Fred Hutchinson Cancer Center

Your Personal Info Could Be

Exposed Online After

This Hospital Breach

Breach Description

The Fred Hutchinson Cancer Center in Washington experienced a significant data breach, which was first detected on November 19, 2023. This cybersecurity incident involved unauthorized access to the center’s clinical network, leading to the acquisition of patient information by an unauthorized third party. The breach potentially affects approximately 1 million individuals, with the compromised information varying by individual but may include sensitive data such as names, addresses, phone numbers, email addresses, dates of birth, Social Security numbers, health insurance information, medical record numbers, patient account numbers, dates of service, and certain clinical information like treatment/diagnosis information, lab results, or provider names[1][3].

In response to the breach, Fred Hutchinson Cancer Center has taken several steps to address the situation and mitigate its impact. These measures include notifying federal law enforcement, conducting an investigation with the assistance of a third-party forensic security firm, and implementing additional defensive tools and increased monitoring to protect personal information. The center began mailing notification letters to affected individuals on December 20, 2023, and is offering complimentary credit monitoring and identity protection services to those whose Social Security numbers may have been involved[1][3].

The breach has led to a series of class-action lawsuits against Fred Hutchinson Cancer Center, with plaintiffs alleging negligence and breach of contract among other claims. These lawsuits argue that the center failed to implement adequate cybersecurity measures and did not promptly notify those whose data might have been compromised[5][9]. The center has also faced criticism for its handling of the situation, including the timing and manner of its communication with affected individuals[5][9].

The incident has had a profound impact on patients and employees, with some receiving spam threats and blackmail attempts following the breach. These threats have added to the distress of individuals already dealing with the challenges of cancer treatment and care[5][7]. The breach has also raised concerns about the security of patient information within the healthcare sector, highlighting the need for robust cybersecurity measures to protect sensitive data[11].

Fred Hutchinson Cancer Center has expressed its commitment to safeguarding personal information and continuously updating and enhancing its systems to prevent future breaches. The center has also established a dedicated call center to support patients affected by the incident[1][3].

Citations:

  1. https://www.fredhutch.org/en/about/about-the-hutch/accountability-impact/notice-to-our-patients-of-data-security-incident.html
  2. https://www.fredhutch.org/en.html
  3. https://www.fredhutch.org/en/news/releases/2023/12/fred-hutchinson-cancer-center-notifies-patients-of-data-security.html
  4. https://www.uwmedicine.org/jobs
  5. https://www.seattletimes.com/seattle-news/health/barrage-of-lawsuits-against-fred-hutch-arrive-after-recent-data-leak/
  6. https://www.nature.com/articles/d41586-024-00392-2
  7. https://www.kiro7.com/news/local/cancer-patients-continue-face-blackmail-threats-weeks-after-fred-hutch-hack/B3PCXEYMXFE45NAEUOWVURJOCU/
  8. https://www.independent.co.uk/news/world/americas/crime/swatting-nikki-haley-trump-fbi-stalkers-b2494097.html
  9. https://www.hipaajournal.com/fred-hutchinson-cancer-center-data-breach-lawsuits/
  10. https://www.biorxiv.org
  11. https://www.healthcareitnews.com/news/fred-hutch-cancer-center-clinical-network-breached
  12. https://news.theregistryps.com/fred-hutchinson-cancer-centers-proposal-for-500000-sqft-research-building-in-seattle-approved-by-west-design-review-board/
  13. https://www.jdsupra.com/legalnews/fred-hutchinson-cancer-center-files-8808983/
  14. https://www.bizjournals.com/seattle/news/2024/02/13/fred-hutch-sloan-oncology-project-advances-seattle.html
  15. https://www.kiro7.com/news/local/seattle-cancer-patients-face-blackmail-threats-after-recent-fred-hutch-data-breach/BCLXFK66DRAEDMRPMVBCUVOUDI/
  16. https://www.fredhutch.org/en/news.related.Wydwcm92aWRlcjpoL2FuZHJldy1oc2llaCdd.html
Breach Submission Date Dec 26, 2023
Converted Entity Name Fred Hutchinson Cancer Center
Converted Entity Type Healthcare Provider
State WA
Individuals Affected 544
Breach Type Loss

Breach Information Location Laptop

Business Associate Present Yes