Rush reports data breach involving 45,000 patients - Insurance News | InsuranceNewsNet

InsuranceNewsNet — Your Industry. One Source.™

Sign in
  • Subscribe
  • About
  • Advertise
  • Contact
Home Now reading Newswires
Topics
    • Advisor News
    • Annuity Index
    • Annuity News
    • Companies
    • Earnings
    • Fiduciary
    • From the Field: Expert Insights
    • Health/Employee Benefits
    • Insurance & Financial Fraud
    • INN Magazine
    • Insiders Only
    • Life Insurance News
    • Newswires
    • Property and Casualty
    • Regulation News
    • Sponsored Articles
    • Washington Wire
    • Videos
    • ———
    • About
    • Meet our Editorial Staff
    • Advertise
    • Contact
    • Newsletters
  • Exclusives
  • NewsWires
  • Magazine
  • Newsletters
Sign in or register to be an INNsider.
  • AdvisorNews
  • Annuity News
  • Companies
  • Earnings
  • Fiduciary
  • Health/Employee Benefits
  • Insurance & Financial Fraud
  • INN Exclusives
  • INN Magazine
  • Insurtech
  • Life Insurance News
  • Newswires
  • Property and Casualty
  • Regulation News
  • Sponsored Articles
  • Video
  • Washington Wire
  • Life Insurance
  • Annuities
  • Advisor
  • Health/Benefits
  • Property & Casualty
  • Insurtech
  • About
  • Advertise
  • Contact
  • Editorial Staff

Get Social

  • Facebook
  • X
  • LinkedIn
Newswires
Newswires RSS Get our newsletter
Order Prints
March 4, 2019 Newswires
Share
Share
Post
Email

Rush reports data breach involving 45,000 patients

Chicago Tribune (IL)

March 04-- Mar. 4--The personal information of about 45,000 Rush patients may have been compromised in a data breach, the health system revealed in a recent financial filing.

The exposed data may include names, addresses, birthdays, Social Security numbers and health insurance information, according to the filing. The data did not include medical information. Rush said that to its knowledge, none of the information had been misused.

The breach is just the latest in what has been a continuing pattern of data security problems at hospitals across the nation. At Rush, an employee of one of the hospital system's billing processing vendors improperly disclosed a file to "an unauthorized party," likely in May 2018, according to a letter sent to affected patients.

Rush said it discovered the breach Jan. 22. It detailed the breach in a financial filing dated Feb. 12, and it sent letters dated Feb. 25 to affected patients. It took several weeks to send letters to patients because Rush had to review the data and set up a call center to assist patients, among other things, said Deb Song, a spokeswoman for Rush.

"It is a matter that we do take very seriously," she said.

After it discovered the breach, Rush launched an internal investigation and suspended its contract with the vendor. Rush said it also was reviewing its internal procedures and contracting processes.

The health system is offering affected patients a free one-year membership to an identity protection service. It also recommends affected patients check their credit reports and financial accounts for suspicious activity, review their explanations of benefits documents from health insurers, and understand that they have the option of freezing their credit.

Patients may call 833-231-3355 for more information. Rush has three hospitals: Rush University Medical Center in Chicago, Rush Oak Park Hospital and Rush Copley Medical Center in Aurora.

It is at least the second privacy-related incident reported by Rush this year. In February, Rush University Medical Center reported that letters notifying patients of the retirement of a nurse practitioner at the Epilepsy Center were addressed incorrectly. The envelopes were marked with the names of certain patients but sent to different patients' addresses. That incident affected 908 patients, according to the U.S. Department for Health and Human Services Office for Civil Rights.

Across the country, many health systems have been involved in data breaches. At least 57 incidents involving at least 500 patients have been submitted to the U.S. Department of Health and Human Services' Office for Civil Rights so far this year. That office is tasked with investigating such breaches and may levy fines against health systems, depending on a breach's severity, said Rachel Patrizzo, vice president of cyber liability underwriting with TDC Specialty Underwriters, a subsidiary of The Doctors Company, which sells medical malpractice insurance.

Health systems must report breaches of protected health information involving 500 or more individuals to the Office for Civil Rights, which posts reports on a public website, nicknamed the Wall of Shame. Recently, UConn Health in Connecticut reported a breach affecting more than 326,000 individuals.

Though many incidents stem from human error, others are the result of hackers or theft. Health systems can be an attractive target for hackers because they keep so much valuable personal data and because there are so many entry points into them, Patrizzo said.

"Certainly, the malicious attacks are on the rise and they get the most publicity and they scare us the most, but personal errors and human errors are just inevitable," she said.

Some health care systems may not be investing as much in cybersecurity as other industries, said Sean Curran, senior director of cybersecurity at West Monroe Partners, a management consulting firm. Some cash-strapped health systems would rather use the money on patient care than data protection, he said.

Rush is just the latest Illinois health system to deal with an incident related to patient privacy.

In 2016, Advocate Health Care agreed to pay $5.55 million -- a record at the time -- to settle allegations it violated federal patient privacy law after three separate data breaches involving its physician-led medical group subsidiary, Advocate Medical Group.

The breaches involved the electronic health data of 4 million people that were exposed after a handful of laptops were stolen and an unauthorized third party accessed the network of an Advocate business associate. Advocate did not admit any liability as part of that settlement, though it said at the time, "we deeply regret any inconvenience this incident has caused our patients."

In 2017, the personal information of as many as 8,862 individuals was compromised after a breach involving Silver Cross Hospital in New Lenox. Silver Cross discovered that year that some patient information may have leaked onto the Internet after a vendor that managed parts of its website upgraded its software.

The report of the data breach comes as Rush also recently disclosed that it potentially received $10.8 million in overpayments from the federal government over a four-year period related to admissions to Rush University Medical Center's Inpatient Rehabilitation Facility. Rush self-reported that information to the federal government, Song said.

Rush is working with the federal government to determine the exact amount Rush may owe, she said.

In 2017, the U.S. Department of Health and Human Services' Office of Inspector General conducted a review of Rush and found that the system owed it $10.2 million because of overpayments -- which Rush denied. The government has already taken that money back, Song said, though she said Rush is still working with the government to get that number adjusted.

[email protected]

___

(c)2019 the Chicago Tribune

Visit the Chicago Tribune at www.chicagotribune.com

Distributed by Tribune Content Agency, LLC.

Older

At least 23 dead, including numerous children, in Alabama tornado; rescue teams searching for more victims

Newer

Breit Drescher Imprevento & Cantor Stoneburner Ford Grana Buckner Win 10 Top 2018 Settlements in VA

Advisor News

  • What advisors must know about accessible client documents
  • Your client texted. Now what? The compliance rules advisors better know
  • Helping small-business owners build, grow and exit
  • Help women break through their retirement roadblocks
  • Advisors await SEC decision on Vanguard fair fund distribution
More Advisor News

Annuity News

  • Legacy Marketing Group partners with Malibu Life USA for annuity launch
  • Best’s Market Segment Report: Global Life/Annuity Reinsurers Remained Poised for Steady Growth
  • When technology becomes easy to rent, what still separates life and annuity carriers?
  • Legacy Marketing Group® and Malibu Life USA Announce Distribution Partnership for New Fixed Indexed Annuity Platform
  • Empower Annuity Insurance Company of America Trademark Application for “EMPOWER WHAT’S NEXT” Filed: Empower Annuity Insurance Company of America
More Annuity News

Health/Employee Benefits News

  • Where CT Residents Can Get Free Help Navigating Medicare
  • Study Findings on Electromagnetics Are Outlined in Reports from Liaoning University (Research on the Standardization of Legal Regulation of Integrated Medical and Elderly Care Services under the Long-Term Care Insurance System): Magnetics – Electromagnetics
  • Proposed Medicaid Cuts Could Cost Maternal and Children's Health Care Billions
  • Trump administration cuts health care coverage for some transgender youth in California
  • Trump administration cuts health care coverage for some transgender youth in California
Sponsor
More Health/Employee Benefits News

Life Insurance News

  • Venus Williams to headline speaker roster for Finseca 2027 experience
  • How advisors can get clients to act sooner on life insurance
  • AM Best Affirms Credit Ratings of Crum & Forster Insurance Group’s Members and Monitor Life Insurance Company of New York
  • AM Best Affirms Credit Ratings of Life Insurance Company Centras Life JSC
  • AM Best Withdraws Credit Ratings of New Providence Life Insurance Company
More Life Insurance News

- Presented By -

NEWS INSIDE

  • Companies
  • Earnings
  • Economic News
  • INN Magazine
  • Insurtech News
  • Newswires Feed
  • Regulation News
  • Washington Wire
  • Videos

FEATURED OFFERS

Press Releases

  • Classic Car Insurer OpenRoad Insurance Expands to 40 U.S. States in Two Years
  • How Aspire General Turned an Early Technology Bet Into Claims Automation at Scale with Kyber
  • Adjusto launches AI-Native contents claims services powered by its technology platform
  • URL Insurance Group Celebrates 40 Years of Service, Growth, and Industry Leadership
  • MassMutual Ascend Surpasses $2 Billion in Lifetime Advisory Annuity Sales, Reflecting Continued Momentum in RIA Channel
More Press Releases > Add Your Press Release >

How to Write For InsuranceNewsNet

Find out how you can submit content for publishing on our website.
View Guidelines

Topics

  • Advisor News
  • Annuity Index
  • Annuity News
  • Companies
  • Earnings
  • Fiduciary
  • From the Field: Expert Insights
  • Health/Employee Benefits
  • Insurance & Financial Fraud
  • INN Magazine
  • Insiders Only
  • Life Insurance News
  • Newswires
  • Property and Casualty
  • Regulation News
  • Sponsored Articles
  • Washington Wire
  • Videos
  • ———
  • About
  • Meet our Editorial Staff
  • Advertise
  • Contact
  • Newsletters

Top Sections

  • AdvisorNews
  • Annuity News
  • Health/Employee Benefits News
  • InsuranceNewsNet Magazine
  • Life Insurance News
  • Property and Casualty News
  • Washington Wire

Our Company

  • About
  • Advertise
  • Contact
  • Meet our Editorial Staff
  • Magazine Subscription
  • Write for INN

Sign up for our FREE e-Newsletter!

Get breaking news, exclusive stories, and money- making insights straight into your inbox.

select Newsletter Options
Facebook Linkedin Twitter
© 2026 InsuranceNewsNet.com, Inc. All rights reserved.
  • Terms & Conditions
  • Privacy Policy
  • InsuranceNewsNet Magazine

Sign in with your Insider Pro Account

Not registered? Become an Insider Pro.