UW Health reports some patient information compromised by cybersecurity incident

Get Our Email Newsletter
The companies, people and issues shaping business in Madison and the Capital Region.

UW Health reported today that some patient information was compromised in a cybersecurity incident that originated with the hacking of an employee’s email account, according to the Wisconsin State Journal. UW Health said there is no indication that any information has been misused but is mailing notification letters to affected individuals for whom it has sufficient contact information as a precaution.

UW Health  determined an unauthorized person gained access to an employee’s email account while investigating an email incident on Jan. 5, prompting it to change the employee’s password and contact a cybersecurity firm for assistance.

The investigation determined that, at various times between Sept. 20 and Dec. 5, the unauthorized person accessed the account and a “limited” number of emails. A review of the emails concluded Feb. 9; it found that they included patient information including names, dates of birth, medical record numbers, and/or clinical information like dates of service, provider names, or diagnoses. The emails did not, however, contain any patients’ Social Security numbers, health insurance ID numbers, or any financial information.

UW Health did not specify how many patients were involved but said the incident affected only those patients whose information was contained in the involved emails. It has established a toll-free call center for those who have questions about the incident at 866-495-2398. The call center is open Monday–Friday from 8 a.m.–5:30 p.m. UW Health is also increasing its email security and providing further workforce training on email best practices.

Digital Partners