A data breach affecting Chesapeake in Virginia, USA, resulted in the exposure of sensitive information on approximately 23,000 patients.

The organization, which operates Chesapeake Regional Medical Center, Outer Banks Hospital and several ancillary healthcare facilities, revealed this week that the personal data of 23,058 patients, donors and employees may have been leaked as a result of a data breach against one of its partners.
Among the leaked information are names, email addresses, and demographic information, such as donation dates and amounts.
Chesapeake Regional Healthcare notified patients and those affected by the breach via email.
"Because the cybercriminal did not have access to credit card information, bank account details, social security numbers and other personal identification information, the data breach presents a low risk of identity theft," the organization added in a statement.

Many healthcare organizations were affected
The incident was the result of a security breach that affected donor and fundraising software provider Blackbaud.
“Blackbaud assured Chesapeake Regional that it has implemented several changes to protect data from any similar incidents in the future,” Chesapeake Regional Healthcare said
But Chesapeake Regional Healthcare isn't the only one affected by the attack on Blackbaud in May, in which attackers took control of the vendor's servers and encrypted certain data sets.
In September, separate incidents at two US healthcare organizations exposed the personal data of more than 190,000 patients.
Earlier in August, Mines Advisory Group (MAG), a non-profit company based in Manchester, UK, involved in clearing landmines in war-torn countries , informed donors that they may have also been affected by the data breach
All affected organizations had used Blackbaud services.
