• About Us
    • Our Services
      • Careers
        • For Patients, Visitors & Vendors
          • Contact Us
            • Call Today Call Today
            • Email Us
            • Our Map
            • Menu
              Home
              About Us
              Coronavirus COVID-19
              Our Services
              Careers
              For Patients, Visitors & Vendors
              For Physicians
              Virtual Tours
              Foundation
              Chinese Home
              News
              Events
              Video Center
              Club 300
              Find a Physician
              Contact Us
              Privacy Policy
              Site Map
              EDAP
            • Awards & Recognition
            • Board of Directors
            • Calendar of Events
            • Community Outreach
            • Community Reports
            • Compliance & Ethics
            • Directions
            • Executive Team
            • Foundation
            • History
            • News & Press Releases
            • Patient Testimonials
            • Spiritual Care
            • Virtual Tours
            • Video Gallery
            • Volunteer Opportunities
            • Cancer Care
            • Cardiology
            • Diagnostic Imaging
            • Emergency Services
            • Institute for Women's Services
            • Institute for Surgical Specialties
            • Interventional Radiology
            • Maternity Services
            • Neurosciences
            • Orthopedics
            • Rehabilitation
            • Stroke Care
            • Surgical Services
            • Weight Loss Surgery
            • Wound Healing Center & Hyperbaric Oxygen Center
            • Pay Bill Online
            • Understanding Your Bill
            • Pricing Estimates
            • Financial Assistance for Patients
            • 340B Program
            • Accepted Insurance Plans
            • Translation Services / Interpreters
            • Notice of Privacy Practices
            • Patient Rights
            • Non-Discrimination Statement
            • Vendor Diversity Policy
            • Daisy Awards
            • Spiritual Care
            • Visitor Information
            • How to Access Electronic Health Records (EHR)
            • Follow My Health - Patient Portal
            • Electronic Health Records (EHR) for Mobile Devices
            • Hospital Price Transparency
            Methodist Hospital of Southern California
            訪問我們的中文網站 Find a Doctor
            Free Physician Referral888.388.2838
            Search Close
            News 2020 November Notice of Vendor Data Security Incident to Our Patients and Donors

            Notice of Vendor Data Security Incident to Our Patients and Donors

            11/18/2020

            At Methodist Hospital of Southern California (“MHSC”), we take our responsibility to maintain the privacy and security of our patients’ personal information very seriously. Regrettably, we have learned that MHSC is one of hundreds of hospitals, healthcare systems, and other nonprofit organizations, including several in California, to be affected by a security event at Blackbaud Inc., a well-respected provider of cloud and data services for charitable organizations.

            What Happened?

            The Methodist Hospital Foundation (the “Foundation”) is a nonprofit corporation that is organized to fund charitable funds for the benefit of MHSC. In accordance with our policies and procedures, and as described in our Notice of Privacy Practices provided to our patients (found on our website at: https://www.methodisthospital.org/For-Patients-Visitors/Notice-of-Privacy-Practices.aspx), MHSC provides limited information about our patients to our Foundation, which contracts with Blackbaud to host the Foundation’s fundraising databases.

            On September 9, 2020, we were notified by the Foundation that Blackbaud discovered and stopped a ransomware attack that included our Foundation’s donor database, as well as those of many other nonprofit organizations. The ransomware attack occurred between February and May 2020, but Blackbaud and the Foundation took time to determine which organizations were impacted before we were notified of the attack.

            In its investigation, Blackbaud stated that its cybersecurity team — together with independent forensics experts and law enforcement — successfully prevented the cybercriminal from blocking Blackbaud’s system access. Blackbaud ultimately expelled the cybercriminal from its system. Prior to locking the cybercriminal out, however, the cybercriminal removed a copy of a backup file containing some information about our patients. Blackbaud stated that they paid the ransom and received confirmation that the cybercriminal had destroyed the copy of the data removed from the system.

            What Information Was Involved?

            The information we had provided to the Foundation, which was copied and, presumably, destroyed by the cybercriminal may have included patients’:

            • full name;
            • contact information, such as telephone numbers, email address, and mailing address;
            • demographic information, such as date of birth and sex; and
            • Medical record number and possibly admission date.

            We had not provided any other health information, such as insurance information or Social Security number, to the Foundation.

            Based on the nature of the incident, Blackbaud’s research, and third-party (including law enforcement) investigation, Blackbaud has assured us that it has no reason to believe that any data went beyond this cybercriminal or was disseminated or otherwise made available publicly. Blackbaud further stated that they have taken additional steps to ensure that the backup file was permanently deleted.

            What We Are Doing

            Blackbaud has taken several steps in response to this incident. As part of its ongoing efforts to help avoid an event like this from happening in the future, Blackbaud has informed us that it has implemented changes to help protect its system from any future incidents. Since learning of the issue, Blackbaud identified the vulnerability associated with this incident, including the tactics used by the cybercriminal, and has taken actions to fix it. Additionally, Blackbaud is accelerating its efforts to further improve its systems through enhancements to access management, network segmentation, and other network-based platforms. As an additional safety measure, Blackbaud has indicated that it has hired a third-party team of experts to monitor the dark web for any further misuse of the data.

            In response to Blackbaud’s notification, MHSC initiated a full investigation once the incident was identified and has taken the necessary steps to prevent a similar event from occurring again, including reviewing and minimizing the sensitive data elements that are provided to the Foundation and/or Blackbaud. In addition, we have reported this incident to the California Department of Public Health.

            What Our Patients Can Do

            We want to emphasize again that Blackbaud has assured us that noSocial Security numbers, credit cards, bank accounts or other information of that nature were compromised. However, we recommend our patients remain attentive by reviewing their account statements and credit reports closely and reporting any suspicious activities.

            Our Commitment to Our Patients

            While data security incidents and ransomware attacks are unfortunately becoming more common, this is not something MHSC ever wants to happen to our valued patients. Your privacy is of utmost importance to us. We very much regret the inconvenience that this incident may have caused. Please be assured that we take data protection very seriously and are grateful for the continued support of our vital mission to deliver world-class care to our patients.

            If you have any other questions, please contact us via one of the methods below:

            • Telephone: 626-574-3528
            • Email: patientsafetycompliance@methodisthospital.org
            • Web site: www.methodisthospital.org/News.aspx

            Categories: News & Press Releases


            Previous Post  |  Next Post

            Recent Posts

            • New Study Shows Men Prone to Anxiety Can Develop More Risk Factors for Heart Disease
            • Methodist Hospital Hosts RN Open House March 10 - Qualified RNs May Be Eligible for a $30,000 Bonus at Sign-On!
            • Methodist Hospital of Southern California and Keck Medicine of USC take next steps toward affiliation
            • Grateful Patient and Healthcare Hero, Akira Sawada, CNA
            • Crystal Ball Fund Raiser Nets $780,000 for New Technologies at Methodist Hospital
            • Newsweek Magazine Honors Methodist Hospital Acute Rehabilitation As One of Nation's Best Programs
            • Methodist Hospital's Crystal Ball Fundraiser Returns to the Pasadena Convention Center on Oct. 9
            • When family history plays a role, life can be at risk in an instant

            Categories

            • Employee News (2)
            • Foundation (1)
            • News & Press Releases (55)
            • Orthopedics (1)

            Archives

            • 2022 (2)
            • February (2)
            • 2021 (11)
            • November (2)
            • October (2)
            • September (1)
            • June (2)
            • May (1)
            • April (1)
            • March (1)
            • January (1)
            • 2020 (11)
            • December (1)
            • November (1)
            • September (1)
            • May (1)
            • April (2)
            • March (3)
            • February (1)
            • January (1)
            • 2019 (16)
            • December (3)
            • November (1)
            • October (2)
            • September (4)
            • August (3)
            • March (1)
            • February (2)
            • 2018 (7)
            • November (1)
            • September (1)
            • August (1)
            • April (1)
            • February (1)
            • January (2)
            • 2017 (9)
            • December (1)
            • November (2)
            • October (2)
            • July (2)
            • May (1)
            • March (1)
            • 2016 (1)
            • February (1)

            Video Gallery

            View Our Full Video Gallery

            Events Calendar

            Choose a topic below or view our full calendar to learn about many of
            the exciting classes and events happening at Methodist Hospital.

            • Maternity & Baby Classes

            • Community Outreach Events

            • Prevention & Screenings

            • Diabetes Education Classes

            • Foundation Events

            View Our Full Calendar

            Recent News & Press Releases

            You can also follow us on Facebook, Twitter, YouTube, Pinterest, and LinkedIn.

            • New Study Shows Men Prone to Anxiety Can Develop ...

              Keep Reading

            • Methodist Hospital Hosts RN Open House March 10 - ...

              Keep Reading

            • Methodist Hospital of Southern California and Keck ...

              Keep Reading

            View All Posts
            • For Employees
            • Home
            • Site Map
            • Privacy Policy
            • Contact Us
            • For Physicians
            Methodist Hospital of Southern California
            Methodist Hospital of Southern California
            www.methodisthospital.org
            300 W. Huntington Drive
            Arcadia, CA 91007

            Main Operator:
            (626) 898-8000
            2017 © All Rights Reserved Scorpion Healthcare