Notice of Data Security Incident
Piedmont Cancer Institute, P.C.
Notice Regarding Data Security Incident
At Piedmont Cancer Institute, P.C. (“PCI”), protecting the privacy of personal and protected health information we maintain is of the utmost importance. Beginning on September 15, 2020, PCI began notifying certain individuals that their protected health information may have been accessed by an unauthorized party.
Specifically, PCI recently learned that an unauthorized individual may have obtained access to a PCI employee email account between April 5, 2020 and May 8, 2020. PCI immediately launched an investigation in consultation with outside cybersecurity professionals who regularly investigate and analyze these types of situations to analyze the extent of any compromise of the email account and the security of the emails and attachments contained within it. PCI devoted considerable time and effort to determine what information was contained in the affected email account. On August 10, 2020, PCI’s comprehensive investigation and document review concluded, at which point PCI discovered that the compromised email account contained a limited amount of personal and/or protected health information, including certain patients’ full names and one or more of the following: dates of birth, financial account information, credit or debit card information, and/or medical information (treatment/diagnosis information). Not all of PCI’s patients were affected by this incident.
PCI has no evidence that that any information was or will be used for any unintended purposes. PCI is committed to maintaining the privacy of personal and protected health information in its possession and has taken many precautions to safeguard it. PCI continually evaluates and modifies its practices and internal controls to enhance the security and privacy of personal and protected health information. PCI is in the process of implementing multi-factor authentication across its email environment and has conducted additional security awareness training since the date of this incident.
For further questions or additional information regarding this incident, or to determine if you may be impacted by it, a dedicated toll-free response line has been set up at 833.909.2914. This response line is available Monday through Friday, 9 a.m. to 9 p.m. ET.