U.S. healthcare provider AspenPointe has notified its patients of a data breach stemming from a September cyberattack that resulted in hackers stealing protected health information (PHI) and personally identifiable information (PII). AspenPointe is a nonprofit organization funded by state, federal and local governments and operates 12 organizations that each serve more than 50,000 individuals and families.
In a notification to its patients, AspenPointe said it discovered that an unknown individual gained unauthorized access to its network between September 12 and 22. In addition, the organization has hired external security to investigate the incident and determine whether and to what extent sensitive patient personal information was compromised.

Following an investigation completed on November 10, it was determined that patient information such as full names, dates of birth, Social Security numbers, Medicaid ID numbers, date of last visit, date of admission, date of discharge, and/or diagnosis code may have been compromised.
Although the nonprofit said there was no evidence that the data stolen during the attack was used “inappropriately” by third parties, patients were urged to protect themselves from potential fraud. Specifically, they were urged to place a security “freeze” or fraud alert on records , as well as to obtain a free credit report to detect any attempts to misuse their information.

Additionally, AspenPointe is providing patients affected by the data breach with 12 months of CyberScan, a $1,000,000 indemnity insurance policy, and services for the affected information.
Following the attack, the organization changed passwords, implemented additional protection , increased monitoring, and firewall. While AspenPointe did not disclose the exact number of patients affected in this incident, the healthcare provider reported the data breach to the U.S. Department of Health and Human Services (HHS) on November 19. According to the report filed with HHS, PHI and PII of 295,617 AspenPointe patients were stolen.
