A Mercy Iowa hospital employee's computer was compromised by an unauthorized user in the spring, putting the data of more than 60,000 Iowans at risk .

The hospital said in a press release Tuesday that it has no reason to believe the information was used to commit fraud or identity theft, but is taking steps to inform patients and protect their data.
Between May 15 and June 24 of this year, an unauthorized person managed to access email , according to Mercy's press release.
Lawyers for the Polsinelli law firm, which is representing the hospital, wrote in a letter to the Iowa Attorney General's office that the hospital first discovered the incident on June 24, when the account began sending spam. It immediately reinstated the account and then launched an investigation into the incident.
Officials found that the account had access to personal information, from names and Social Security numbers to medical treatments and health insurance information. In total, 60,473 Iowans may have been affected by the breach, according to the letter.

The hospital also sent out notifications on Friday to any patients who may be affected, informing them of the breach and the steps they can take to protect themselves in the future.
Mercy Iowa City offers free theft protection services to people whose Social Security numbers and driver's license numbers may have been compromised.
According to the hospital, additional security measures were also implemented to prevent future breaches.
Mercy Iowa City last reported a potential security breach in 2016, when it discovered that the personal information of 15,625 patients had been leaked.
According to the letter filed with the Attorney General's office, the hospital said it had no evidence that personal information was misused. Of the total, 15,052 belonged to Iowa residents. Any security breach affecting more than 500 Iowa residents must be reported to the Attorney General's Office's Director of Consumer Protection within five business days, according to the law.
