Rochester medical center suffers third breach
The University of Rochester Medical Center (URMC) suffered its third significant data breach after officials announced that one of its physicians misplaced an unencrypted USB drive containing the protected health information of 537 patients.
URMC officials said they have notified the former orthopedic patients who were included on the drive, which contained patients’ names, genders, ages, dates of birth, telephone numbers, medical record numbers, orthopedic physician’s name, dates of service, diagnoses, diagnostic studies, procedures and complications, if any. No address, Social Security number or insurance information of any patient was compromised, according to a statement.
The flash drive is believed to have been lost at the URMC Outpatient Surgery Center. After an unsuccessful search, hospital officials suspected the drive was destroyed in the laundry. A search of the laundry service, however, also failed to locate the drive.
According to URMC's updated policies regarding portable devices, the resident physician was in violation of company policy. Apparently, he used his own personal device rather than an encrypted drive supplied and required by the hospital.
URMC's two previous data breaches compromised the protected health information of nearly 3,500 patients and both occurred in 2010.