Wentworth Health Partners Garrison Women's Health Data Breach
Wentworth Health Partners EMR Breach Affects 4,158 Patients
What happened in the Wentworth Health Partners Garrison Women's Health data breach?
The Wentworth Health Partners Garrison Women's Health data breach was reported on February 10, 2023 and affected 4,158 individuals. The breach type was Hacking/IT Incident involving Electronic Medical Record. This breach occurred in New Hampshire. Under HIPAA, affected patients must be notified within 60 days and may be entitled to credit monitoring services.
Wentworth Health Partners Garrison Women's Health Breach Details
On February 10, 2023, Wentworth Health Partners Garrison Women's Health, a healthcare provider based in New Hampshire, reported a significant data breach involving unauthorized access to its Electronic Medical Record (EMR) system. The breach, classified as a hacking or IT incident, compromised the protected health information (PHI) of approximately 4,158 individuals. The incident represents a serious breach of patient privacy and security, requiring notification to affected patients and regulatory authorities under HIPAA Breach Notification Rule requirements.
Company Response
Upon discovery of the unauthorized access to their EMR system, Wentworth Health Partners Garrison Women's Health initiated a comprehensive investigation to determine the scope and nature of the breach. The organization worked to identify all affected individuals and began the process of notifying patients of the incident. As a covered entity under HIPAA, the organization was required to notify affected individuals without unreasonable delay and no later than 60 calendar days after discovery of the breach. The submission date of February 10, 2023, indicates the organization reported the breach to the Department of Health and Human Services (HHS) Office for Civil Rights (OCR) within the required timeframe. The organization also likely engaged with their business associates to understand the full scope of the incident, as a business associate was involved in the breach.
Specific Details
The breach occurred within the organization's Electronic Medical Record system, which typically contains comprehensive patient health information including medical histories, diagnoses, treatment plans, medications, and clinical notes. Hacking or IT incidents involving EMR systems often result from vulnerabilities such as unpatched software, weak authentication mechanisms, compromised credentials, or exploitation of network security weaknesses. The involvement of a business associate suggests that the breach may have occurred through a third-party vendor's systems or through a connection between the covered entity and its business associate. Business associates—entities that handle PHI on behalf of covered entities—are common vectors for healthcare data breaches, as they may have different security standards or become targets for threat actors seeking to access healthcare data through less-protected entry points.
Organizational Context
Wentworth Health Partners Garrison Women's Health is a healthcare provider specializing in women's health services, operating in New Hampshire. The organization provides obstetric, gynecological, and related women's health services to patients throughout the state. As a covered entity under HIPAA, the organization is subject to comprehensive privacy and security regulations designed to protect patient health information. The breach of 4,158 individuals represents a significant portion of the organization's patient population, suggesting either a widespread compromise of the EMR system or access to a database containing a substantial patient cohort. The involvement of a business associate in the breach indicates that the organization relies on third-party vendors for certain aspects of its operations, whether for IT services, billing, records management, or other healthcare-related functions.
Patient Impact and Notifications
Approximately 4,158 patients of Wentworth Health Partners Garrison Women's Health were affected by this breach. These individuals may have had their protected health information accessed without authorization, potentially including names, dates of birth, medical record numbers, Social Security numbers, insurance information, medical histories, diagnoses, treatment information, and other sensitive health data. The specific types of information exposed depend on what data elements were stored in the compromised EMR system and what access the threat actor obtained. Patients were notified of the breach through written notification letters, which are required under HIPAA regulations. The notification letters typically included information about the breach, the types of information that may have been accessed, steps the organization is taking to address the incident, and recommended actions patients should take to protect themselves from potential identity theft or fraud.
Industry Context and HIPAA Implications
This breach represents one of many healthcare data breaches occurring annually in the United States. According to HHS OCR data, healthcare organizations experience thousands of breaches each year, with hacking and IT incidents being among the most common causes. The HIPAA Breach Notification Rule requires covered entities and business associates to notify affected individuals, the media (if more than 500 residents of a state are affected), and HHS OCR of breaches of unsecured PHI. The rule defines a breach as the unauthorized acquisition, access, use, or disclosure of PHI that compromises the security or privacy of the information. Wentworth Health Partners' breach, affecting over 4,000 individuals, likely triggered media notification requirements in New Hampshire. The involvement of a business associate underscores the importance of Business Associate Agreements (BAAs) and vendor management in healthcare security. Covered entities are responsible for ensuring that their business associates implement appropriate safeguards to protect PHI, and breaches involving business associates can result in regulatory action against both the covered entity and the business associate. This incident serves as a reminder of the ongoing threat landscape facing healthcare organizations and the critical importance of strong cybersecurity measures, including network segmentation, access controls, encryption, vulnerability management, and employee security awareness training.
What Data Was Exposed
Risks to Patients
What to Do If You Were Affected by the Wentworth Health Partners Garrison Women's Health Breach
Monitor credit reports from all three major credit bureaus (Equifax, Experian, TransUnion) for suspicious activity and consider placing a fraud alert or credit freeze to prevent unauthorized credit applications
Review medical records and explanation of benefits (EOB) statements for unauthorized services or charges, and contact healthcare providers immediately if you identify suspicious activity
Change passwords for any online healthcare portals and accounts associated with Wentworth Health Partners or related services, using strong, unique passwords
Consider enrolling in credit monitoring and identity theft protection services, which may be offered by the organization at no cost; remain vigilant for phishing emails or calls claiming to be from healthcare providers or financial institutions
Monitor Your Medical Records
Request copies to check for unauthorized changes
Check More New Hampshire Breaches
Search all breaches reported in New Hampshire