The biggest health care data breaches you should know about in Alabama

Published 2:30 pm Thursday, August 3, 2023

The biggest health care data breaches you should know about in Alabama

It starts with an often-paralyzing attack on computer systems. Doctors scramble to notify patients awaiting surgery that their procedures have been delayed due to a ransomware attack.

Sometimes a single cyberattack can impact hospitals across multiple states, as was the case when hackers targeted CommonSpirit Health in October 2022. Just one reported case of ransomware has allegedly led to the death of a patient. More often, patients’ sensitive information is served up to a market of seedy individuals around the world ready to cash in on someone else’s identity.

Health care institutions are among the most targeted businesses in the world, chiefly because they hold such sensitive information about the patients they serve. Hospitals, home health agencies, and other institutions store patients’ phone numbers, Social Security numbers, addresses, and other things that would allow any would-be criminal to pose as a patient and open new credit cards or bank accounts in their name.

Drata analyzed Department of Health and Human Services data to determine which health care data breaches reported in 2022 affected the most residents in Alabama. Breaches that did not include locations were not included in this analysis.

Read on to see which institutions reported data breaches to the federal government in your state and explore the largest across the nation here.

1. Norwood Clinic electronic medical record, network server breach
– Type of breach: Hacking/IT Incident
– Individuals affected: 228,000
– Date reported: 02/25/2022

2. Henderson & Walton Women’s Center, P.C. email breach
– Type of breach: Hacking/IT Incident
– Individuals affected: 34,306
– Date reported: 08/23/2022

3. Legacy Operating Company d/b/a Legacy Hospice email breach
– Type of breach: Hacking/IT Incident
– Individuals affected: 21,202
– Date reported: 12/22/2022

4. Aesto, LLC d/b/a Aesto Health network server breach
– Type of breach: Hacking/IT Incident
– Individuals affected: 17,400
– Date reported: 05/20/2022

5. Grandview Medical Center paper/films breach
– Type of breach: Theft
– Individuals affected: 1,126
– Date reported: 06/06/2022