On January 29, 2018, we learned that the security setting on a Middletown Medical radiology interface may have permitted users to see a patient listing and, in a limited number of cases, may have allowed unauthorized users to access limited electronic patient information. Middletown Medical, the very next day, modified the interface and terminated any potential unauthorized access to the patient listing and electronic patient information. The interface, patient listing, and electronic patient information remain secure.
Limited patient information may have been exposed prior to January 30, 2018, including patient names, birthdates, client identification numbers, an indication that patients received radiology services, and the date(s) when they received those services, and, in a limited number of cases, patient radiology report(s), radiology image(s) and diagnosis. The information did not include Social Security numbers or any other electronic medical records.
Out of an abundance of caution, Middletown Medical is offering identity theft recovery services through ID Experts®, the data breach and recovery services expert, at no cost to the individual. ID Experts fully managed recovery services will provide twelve (12) months of complete access to their fraud resolution representatives. With this protection, ID Experts will help resolve issues if the individual’s identity is compromised.
Although there is no evidence that any of this information has been misused, as an added precaution, we recommend that potentially affected individuals carefully review accounts statements and the explanation of benefits statements that they receive to check for any unfamiliar health care services. If potentially affected individuals notice any suspicious activity, they should contact their health plan immediately at the number listed on the back of their Member ID card. If potentially affected individuals do not regularly receive explanation of benefits statements, they should consider requesting that their plans send them.
In addition, although Social Security number and credit card information were not accessible by this incident, in the event potentially affected individuals notice any suspicious activity, they may wish to order copies of their credit reports from each of the three national credit reporting agencies to check for any inaccurate information, particularly medical services or medical bills that are not recognizable. Potentially affected individuals may obtain their free annual credit report from each of the national credit reporting agencies by visiting www.annualcreditreport.com, by calling 1-877-322-8228 or by mailing their request to Annual Credit Report Request Service, P.O. Box 105281, Atlanta, GA 30348-5281.
Middletown Medical is taking steps to stop a similar event from occurring in the future. This includes making modifications to interfaces to secure all information, implementing additional safeguards to secure documents, and providing additional training about the proper way to secure information systems.
We sincerely regret any inconvenience or concern that this matter may cause you, and remain dedicated to protecting your information. Individuals who may have been affected by this incident can visit https://ide.myidcare.com/middletownprotect or call the toll-free number at
(866) 397-0986 Monday through Friday, between the hours of 8:00 am to 8:00 pm (EDT).