Previous All Posts Next

University Exposes Patient Data for Two Years

Posted: July 20, 2017 to Cybersecurity.

Tags: Data Breach, HIPAA, Malware

In another major breach involving healthcare providers’ patient data being exposed on an unsecured site for nearly two years, University of Iowa Health Care reports that in April of this year, they discovered that over 5000 patients’ sensitive information had been posted online, unencrypted, since May 2015, on a site that develops applications. On April 29, the UI received a tip from someone who inadvertently discovered the unsecure data.  The University deleted the files on May 1, after learning of the mistake. While it does not appear that any of the data, which includes names, dates of admission and medical record numbers, was misused, this type of breach is becoming more and more common.  While this type of mistake should be easy to avoid, the problem with this and many other issues is that not all employees are properly educated. This was a case of employee error.  UI was quick to investigate the matter, and a spokesman for the University state that "an employee used this open source programming tool as part of an application development for UI Health Care operations. The files were not made private and were left on the site after the work was completed." Fortunately, it does not appear that any of the data was misused, so while the University is not offering any free credit monitoring, the incident has been recorded with the Department of Health and Human Services, and UI is taking steps to bulk up their cyber security by:
  • More in depth training for staff and students.
  • Stricter processes for developing and managing databases.
  • Developing more rigorous protocols and testing before going live.

Protect Your Business Today

Petronella Technology Group has provided cybersecurity, compliance, and managed IT services from Raleigh, NC for over 23 years. Contact us today for a free consultation and technology assessment.

Need help implementing these strategies? Our cybersecurity experts can assess your environment and build a tailored plan.
Get Free Assessment

About the Author

Craig Petronella, CEO and Founder of Petronella Technology Group
CEO, Founder & AI Architect, Petronella Technology Group

Craig Petronella founded Petronella Technology Group in 2002 and has spent more than 30 years working at the intersection of cybersecurity, AI, compliance, and digital forensics. He holds the CMMC Registered Practitioner credential (RP-1372) issued by the Cyber AB, is an NC Licensed Digital Forensics Examiner (License #604180-DFE), and completed MIT Professional Education programs in AI, Blockchain, and Cybersecurity. Craig also holds CompTIA Security+, CCNA, and Hyperledger certifications.

He is an Amazon #1 Best-Selling Author of 15+ books on cybersecurity and compliance, host of the Encrypted Ambition podcast (95+ episodes on Apple Podcasts, Spotify, and Amazon), and a cybersecurity keynote speaker with 200+ engagements at conferences, law firms, and corporate boardrooms. Craig serves as Contributing Editor for Cybersecurity at NC Triangle Attorney at Law Magazine and is a guest lecturer at NCCU School of Law. He has served as a digital forensics expert witness in federal and state court cases involving cybercrime, cryptocurrency fraud, SIM-swap attacks, and data breaches.

Under his leadership, Petronella Technology Group has served 2,500+ clients, maintained a zero-breach record among compliant clients, earned a BBB A+ rating every year since 2003, and been featured as a cybersecurity authority on CBS, ABC, NBC, FOX, and WRAL. The company leverages SOC 2 Type II certified platforms and specializes in AI implementation, managed cybersecurity, CMMC/HIPAA/SOC 2 compliance, and digital forensics for businesses across the United States.

CMMC-RP NC Licensed DFE MIT Certified CompTIA Security+ Expert Witness 15+ Books
Related Service
Protect Your Business with Our Cybersecurity Services

Our proprietary 39-layer ZeroHack cybersecurity stack defends your organization 24/7.

Explore Cybersecurity Services
Previous All Posts Next
Free cybersecurity consultation available Schedule Now