Eskenazi Health Announced One Of The Largest Hack That Leaked Patients' Information

Eskenazi Health is part of the Health and Hospital Corp. of Marion County, Florida, U.S..

It includes the Marion County Public Health Department itself, as well as Indianapolis Emergency Medical Services, and the Sidney & Lois Eskenazi Hospital.

And this time, Eskenazi Health said that it has experienced a massive cyberattack that resulted in the personal information of patients and employees to show up on the dark web.

Eskenazi Health said that the data that has been leaked, include medical, financial, and demographic information of certain individuals.

The information impacted may include name, date of birth, age, address, telephone number, email addresses, medical record number, patient account number, diagnosis, clinical information, physician name, insurance information, prescriptions, date(s) of service, driver’s license number, passport number, face photos, Social Security number, and credit card information.

And in the case of deceased patients, this information also may include cause of death and date of death.

Sidney & Lois Eskenazi Hospital, a hospital that is part of Eskenazi Health
Sidney & Lois Eskenazi Hospital, a hospital that is part of Eskenazi Health.

Eskenazi said that it is informing all impacted individuals through a letter, detailing which specific types of their information were involved in the incident.

“Despite Eskenazi Health’s efforts, data was stolen from its network by the cyber criminals and they released some of the data on a portion of the internet known as the dark web. This data included certain personal and health information of some patients and employees of HHC [..] ."

"Eskenazi Health is constantly evaluating its security systems and will continue to make improvements as necessary to protect the privacy and security of information on an ongoing basis."

"Eskenazi Health has been proactive in its efforts to implement policies, procedures, and safeguards to prevent data compromises from occurring in the future and has worked with its forensic team to identify any areas for improvement."

The attack itself happened way back around May 19th. But the health care provided only learned of the breach around August 4th.

After realizing this, Eskenazi took its network offline "to protect its information and maintain the safety and integrity of patient care," said a news release from Eskenazi Health.

Eskenazi also assembled an independent forensic team to investigate and contain the incident and to protect against further criminal activity.

[block:block=87]

The team conducted an extensive investigation and assisted Eskenazi Health with mitigation steps to ensure the cyber criminals were no longer on its network.

Eskenazi Health also notified the FBI and enabled additional security measures to further enhance its network security.

Initially, Eskenazi Health said that there was no evidence the attack resulted in bank or credit card fraud.

Later, the health care provider took precaution by suggesting people to check with credit reporting agencies and get free credit monitoring and identity theft protection.

Reports said that the attack on Eskenazi Health is among the largest target of a cyberattack that left patient and employees personal information compromised.