We use cookies, including third-party cookies from Google to serve personalized ads through AdSense, to operate this site and understand how it is used. By continuing to browse, you accept this use. See our Privacy Policy and Terms of Use for details, including how to opt out of personalized advertising.
Accept
Health Works CollectiveHealth Works CollectiveHealth Works Collective
  • Health
    • Mental Health
  • Policy and Law
    • Global Healthcare
    • Medical Ethics
  • Medical Innovations
  • News
  • Wellness
  • Tech
Search
© 2023 HealthWorks Collective. All Rights Reserved.
Reading: Sutter Health HIPAA Breach: Lessons Learned
Share
Notification Show More
Font ResizerAa
Health Works CollectiveHealth Works Collective
Font ResizerAa
Search
Follow US
  • About
  • Contact
  • Privacy
© 2023 HealthWorks Collective. All Rights Reserved.
Health Works Collective > eHealth > Medical Records > Sutter Health HIPAA Breach: Lessons Learned
Medical RecordsTechnology

Sutter Health HIPAA Breach: Lessons Learned

onlinetech
onlinetech
Share
3 Min Read
SHARE

The Sutter Health HIPAA breach of 3.3 million patient demographic data from 1995 to January 2011 was recently reported – and an additional 943,000 patients from the Sutter Medical Foundation were also affected (both demographic and medical diagnosis data). Twenty-one total healthcare providers were also affected.

The Sutter Health HIPAA breach of 3.3 million patient demographic data from 1995 to January 2011 was recently reported – and an additional 943,000 patients from the Sutter Medical Foundation were also affected (both demographic and medical diagnosis data). Twenty-one total healthcare providers were also affected. Sutter Health is a not-for-profit network of doctors, hospitals and care providers.

A couple key points and lessons learned are noted:

Encryption: the breach was a result of physical theft at the Sutter Medical Foundation’s administrative offices. A rock used to break the window allowed a thief to make off with an unencrypted desktop computer housing a patient database of information (although the company was in the process of encrypting their data at the time of theft, starting primarily with hand-held devices). Encryption is viewed as a common and recommended best practice in cases of sensitive data storage, and is a must for HIPAA covered entities.

More Read

Medical Robotics Could Help Treat Arrhythmia, Keep Patients Mobile
Doximity Mobile and Web Secure Network for Doctors To Communicate
Three Central Questions About Medical Technologies
6 Technologies Changing Healthcare for Mobility-Constrained Seniors
Del Mar Pharmaceuticals Is Fighting Cancer One Molecule At A Time

Data Storage: Keeping a large amount of protected health information (PHI) unencrypted and easily accessible on a desktop computer is not considered the most secure form of data storage. As I blogged about in early August (see 2011 HIPAA Violations infographic), HHS.gov records show the most common type of HIPAA violations by number of instances is due to physical theft (49 percent). Cloud computing, whether the private cloud or the managed cloud, can offer increased security with the use of firewalls, Intrusion Detection and Protection Systems (IDS/IPS), access authentication and more.

Patient notification: Although the data theft was stolen over the weekend of October 15, the patients and the public were not notifieduntil a month later (last Wednesday). In addition, according to ModernHealthCare.com, a Sutter Health spokeswoman is not planning to notify the 3.3 million affected patients directly, and some patients might not receive notice by mail until early next month.

Earlier this year, the TRICARE/SAIC HIPAA breach affected a record 4.9 million military patients of the San Antonio area – the stolen military backup tapes were also unencrypted.

HIPAA compliance is a result of a combination of technology, policies and procedures – if you’re uncertain about what HIPAA hosting for your protected health information (PHI) should entail, see our HIPAA FAQ for more answers.

Sutter Health: Stolen Computer Contained Info on 4.2 Million
Medical Record Theft at Sutter Health Part of Wider Problem

TAGGED:2011 HIPAA breachesHIPAA breachhipaa violationsutter health hipaa breach
Share This Article
Facebook Copy Link Print
Share

Stay Connected

1.5KFollowersLike
4.5KFollowersFollow
2.8KFollowersPin
136KSubscribersSubscribe

Latest News

Workers Comp Claim Denied – Now What?  -- AI-generated illustration
Workers Comp Claim Denied – Now What? 
Policy & Law
October 9, 2026
The Case for Proactive Nutrient Support and Where IV Therapy Fits In -- AI-generated illustration
The Case for Proactive Nutrient Support and Where IV Therapy Fits In
Health Therapies
October 5, 2026
Biofeedback Technology in Addiction Treatment: What the Evidence Shows So Far -- AI-generated illustration
Biofeedback Technology in Addiction Treatment: What the Evidence Shows So Far
Addiction Addiction Recovery
September 28, 2026
Charity Care Is Written Into Hospital Policy. It Rarely Makes It Onto the Bill. -- AI-generated illustration
Charity Care Is Written Into Hospital Policy. It Rarely Makes It Onto the Bill.
Business Hospital Administration
September 25, 2026

You Might also Like

NCQA Encourages Health IT Use Among Medical Specialists

August 4, 2012
images
Medical Records

Infographic:Making Sense of Meaningful Use

March 29, 2012
mobisante ultrasound device
BusinesseHealthMedical DevicesMedical InnovationsTechnology

Interview with Sailesh Chutani, CEO of Mobisante

January 27, 2015
eHealthTechnology

Chatbots – The New Healthcare Frontier

July 13, 2018
Subscribe
Subscribe to our newsletter to get our newest articles instantly!
Follow US
© 2008-2026 HealthWorks Collective. All Rights Reserved.
  • About
  • Contact
  • Privacy
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?