One Brooklyn Health System

Your Personal Info Could Be

Exposed Online After

This Hospital Breach

Breach Description

One Brooklyn Health System Data Breach

One Brooklyn Health System in New York experienced a significant data breach that was first discovered on November 19, 2022. The breach affected over 235,000 individuals, including patients, employees, and their spouses, dependents, and beneficiaries[1][3][6][10]. The compromised data included names, Social Security numbers, driver’s license numbers, state ID numbers, dates of birth, financial account information, medical treatment and diagnosis information, health insurance information, and prescription information[1][2][3][9][10][11][12][13].

Timeline and Impact

  • The unauthorized access occurred intermittently between July 9, 2022, and November 19, 2022[1][3][10][11][12][13].

  • The breach caused a disruption to the hospital’s computer systems, affecting patient care and forcing medical staff to revert to pen and paper for record-keeping[1][5].

  • The affected facilities include Brookdale Hospital Medical Center, Interfaith Medical Center, and Kingsbrook Jewish Medical Center, as well as several nursing homes and health clinics[3][6][10][11].

Legal and Regulatory Response

  • A class-action lawsuit has been filed against One Brooklyn Health System, alleging negligence in failing to protect sensitive information and delayed notification to affected individuals[1][3][4][6][10].

  • The lawsuit seeks monetary damages, restitution, and injunctive relief, including improvements to data security practices[3][4][6][10].

  • One Brooklyn Health System has communicated with law enforcement and healthcare authorities regarding the incident[3][6][13].

Measures Taken by One Brooklyn Health System

  • One Brooklyn Health System has reviewed and updated its data protection policies and training protocols[3][6][13].

  • Enhanced security measures and additional monitoring tools have been implemented to reduce the risk associated with the incident and to prevent similar incidents in the future[3][6][13].

  • Notification letters were sent to affected individuals on April 20, 2023[2][10][11][12].

Recommendations for Affected Individuals

  • One Brooklyn Health System encourages individuals to remain vigilant against identity theft and fraud by reviewing account statements and credit reports for unexpected activity or errors over the next 12 to 24 months[13].

  • Any suspicious activity should be reported to the associated insurance company, healthcare provider, or financial institution immediately[13].

  • A dedicated toll-free number (1-833-570-3025) and email address (incident@obhny.org) have been established for individuals seeking additional information about the incident[1][13].

As of now, One Brooklyn Health System reports being unaware of any actual or attempted misuse of the affected information as a result of this incident[1][3][13]. However, the situation remains under investigation, and affected individuals are advised to take precautions to protect their personal information.

Citations:

  1. https://www.thecity.nyc/2023/04/27/one-brooklyn-health-data-breach-cyber-attack/
  2. https://www.myinjuryattorney.com/one-brooklyn-health-data-breach/
  3. https://www.bankinfosecurity.com/one-brooklyn-reports-breach-faces-lawsuit-post-cyberattack-a-21907
  4. https://nypost.com/2023/04/27/patient-sues-one-brooklyn-health-for-personal-data-breach/
  5. https://www.cbsnews.com/newyork/news/one-brooklyn-health-battling-cyber-attack-that-forced-some-critical-services-offline/
  6. https://thehipaaetool.com/one-brooklyn-health-faces-class-action-lawsuit-over-breach/
  7. https://www.scmagazine.com/analysis/breach-notice-confirms-one-brooklyn-health-cyberattack-outage-in-november
  8. https://www.nytimes.com/2022/12/12/nyregion/brooklyn-hospital-cyberattack.html
  9. https://www.beckershospitalreview.com/cybersecurity/one-brooklyn-health-says-patient-social-security-numbers-were-breached-in-cyberattack.html
  10. https://www.hipaajournal.com/one-brooklyn-health-sued-over-235k-record-data-breach/
  11. https://www.jdsupra.com/legalnews/one-brooklyn-health-reports-leaked-3756261/
  12. https://www.hipaajournal.com/one-brooklyn-health-notifies-patients-about-november-2022-cyberattack/
  13. https://onebrooklynhealth.org/media/p4abqfwk/obh-website-notice.pdf
Breach Submission Date Jan 18, 2023
Converted Entity Name One Brooklyn Health System
Converted Entity Type Healthcare Provider
State NY
Individuals Affected 500
Breach Type Hacking/IT Incident

Breach Information Location Network Server

Business Associate Present Yes