A break-in at Self Regional Healthcare resulted in the theft of a laptop and the exposure of sensitive patient information at risk.
The incident occurred on May 25, while the organization's employees learned about it two days later, on May 27.
Two people responsible for the breach, who have already been arrested and confessed to the crime, stated that the computer was destroyed after being thrown into a lake.
The device, which is password-protected but not encrypted, has not been found, leading to speculation that the data could have been accessed by unauthorized individuals. Self Regional is therefore required to notify individuals whose data may have been exposed. According to officials, at least 500 patients may have been affected by the data breach.
The information carried by the computer includes patients' names, social security numbers, driver's license numbers, names of treating physicians, insurance policy numbers, patient account numbers, maintenance dates, diagnostic information/procedure, payment card information, financial information, and, possibly, their addresses.
