Email intruder causes N.C. hospital data breach

Approximately 5,600 patients of Carolinas Medical Center-Randolph are impacted by a data breach caused by an unauthorized electronic intruder who obtained incoming and outgoing emails from a provider's account without the provider's or the hospital's knowledge.

The security breach of the Charlotte, N.C. facility was discovered on Oct. 8 following an upgrade in the hospital’s security software. Based on the investigation, the intruder obtained emails from the provider’s account between March 11 and Oct. 8, according to a release. Upon discovery of the breach, Carolinas HealthCare System hired a forensic investigator and notified federal law enforcement of the incident.

Based on information discovered through the investigation, most of the obtained emails did not contain patient information. While only five emails contained Social Security numbers, several contained some medical and other patient information. The emails appear to include one or more of the following: patient names, dates and times of service, provider and facility names, internal hospital medical record and account numbers, dates of birth, and treatment information, such as diagnosis, prognosis, medications, results and referrals. Potentially affected patients have been sent personal letters explaining the type of information involved.

Carolinas HealthCare said it has taken "several measures" to ensure this intrusion is contained and to prevent similar incidents from happening again, including implementing additional security safeguards to prevent unauthorized intrusions and continuing to actively monitor systems for unusual activity, according to the release.

Beth Walsh,

Editor

Editor Beth earned a bachelor’s degree in journalism and master’s in health communication. She has worked in hospital, academic and publishing settings over the past 20 years. Beth joined TriMed in 2005, as editor of CMIO and Clinical Innovation + Technology. When not covering all things related to health IT, she spends time with her husband and three children.

Around the web

The tirzepatide shortage that first began in 2022 has been resolved. Drug companies distributing compounded versions of the popular drug now have two to three more months to distribute their remaining supply.

The 24 members of the House Task Force on AI—12 reps from each party—have posted a 253-page report detailing their bipartisan vision for encouraging innovation while minimizing risks. 

Merck sent Hansoh Pharma, a Chinese biopharmaceutical company, an upfront payment of $112 million to license a new investigational GLP-1 receptor agonist. There could be many more payments to come if certain milestones are met.