Penn. data breach caused by hacking of third-party vendor

A physician at Penn Highlights Brookville, a healthcare service, informed patients of a breach after an intruder accessed personal data stored on the server of a Ohio-based third-party vendor.

In mid-August, Penn Highlands Brookville discovered that a computer server containing patient information of Barry J. Snyder, MD, was compromised when a third-party intruder potentially had access to information contained on the server, according to the provider.

Data at risk include patient names, addresses, dates of birth, driver’s license numbers, Social Security numbers, phone numbers, insurance information, medical information and gender.

“Our forensics experts cannot verify with 100 percent certainty that the data security event occurred, but Penn Highlands Brookville is providing notice to affected patients so that they may take steps to protect their identity if they feel it is necessary,” according to a notice.

Highlands Brookville has hired national security and computer forensics experts to investigate, and has taken efforts to have the third-party vendor remove and destroy the data contained on the affected server. Likewise, affected patients are receiving free identity monitoring and protection services.
 

Around the web

Compensation for heart specialists continues to climb. What does this say about cardiology as a whole? Could private equity's rising influence bring about change? We spoke to MedAxiom CEO Jerry Blackwell, MD, MBA, a veteran cardiologist himself, to learn more.

The American College of Cardiology has shared its perspective on new CMS payment policies, highlighting revenue concerns while providing key details for cardiologists and other cardiology professionals. 

As debate simmers over how best to regulate AI, experts continue to offer guidance on where to start, how to proceed and what to emphasize. A new resource models its recommendations on what its authors call the “SETO Loop.”