$100 Million awarded Since 1994 6,000 Satisfied Clients

Posted On June 20, 2022 Consumer Privacy & Data Breaches

Data Breach Alert: Baptist Health System

NOTICE: If you received a NOTICE OF DATA BREACH letter from Baptist Health System, contact the attorneys at Console & Associates at (866) 778-5500 to discuss your legal options, or submit a confidential Case Evaluation form here.

Data Breach AlertJune 20, 2022 – Recently, Baptist Health System announced a data breach impacting patients of Baptist Medical Center and Resolute Health Hospital. Evidently, the breach occurred after an unauthorized party installed a lone of malicious code on the organization’s website, granting that party access to sensitive patient information. Based on the most recently available information, the Baptist Health System data breach resulted in the following patient data being compromised: full names, dates of birth, addresses, Social Security numbers, health insurance information, medical information and billing information. On June 16, 2022, Baptist Health System filed official notice of the breach with state government entities and began sending data breach notification letters to affected patients. Notice was sent to more than 1.2 patients in the State of Texas alone.

If you received a data breach notification, it is essential you understand what is at risk. The data breach lawyers at Console & Associates, P.C. are actively investigating the Baptist Medical Center data breach on behalf of people whose information was exposed. As a part of this investigation, we are providing free consultations to anyone affected by the breach who is interested in learning more about the risks of identity theft, what they can do to protect themselves, and what their legal options may be to obtain compensation from Baptist Medical Center.

What We Know So Far About the Baptist Health System Breach

According to official notice filed by the company, on April 20, 2022, Baptist Health System discovered that a malicious actor installed a line of code on the back-end of the organization’s website. In response, Baptist Health suspended the affected systems to restrict further access and began working with a cybersecurity firm to investigate the incident. While the investigation is ongoing, so far, Baptist Health has confirmed that an unauthorized third party was able to access certain systems that contained personal information and remove some data from the network between March 31, 2022 and April 24, 2022.

Upon discovering that sensitive consumer data was accessible to an unauthorized party, Baptist Health System then reviewed the affected files to determine exactly what information was compromised. While the breached information varies depending on the individual, it may include your full name, date of birth, address, Social Security number, health insurance information, medical information and billing information.

On June 16, 2022, Baptist Health System sent out data breach letters to all individuals whose information was compromised as a result of the recent data security incident.

More Information About Baptist Health System

Baptist Health System is a health system based in San Antonio, Texas. The Baptist Health System consists of 65 locations, most of which are located in San Antonio and the surrounding areas. Baptist Health provides a wide range of healthcare services, including orthopedic care, neuroscience, cardiovascular care, emergency room care, obstetrics, and physical therapy. Baptist Health System employs more than 6,000 people and generates approximately $880 million in annual revenue.

If You Have Questions About Your Rights Following the Baptist Health System Data Breach, Console & Associates, P.C. Can Help

At Console & Associates, P.C., our consumer privacy lawyers monitor all security and data breaches to help affected consumers pursue their legal remedies. We offer free consultations to victims of data breaches and can explain your rights in clear, understandable terms so you can make an informed decision about how to proceed with your case. If you’ve been affected by the Baptist Medical Center data breach or any other data security incident, Console & Associates, P.C., will investigate your case at no charge and offer you thorough advice about how to most effectively proceed with your case. If you decide to bring a case, we only get paid if you do. If your claim is successful, any legal fees are either paid by the defendant or come out of the funds recovered from the defendant. If your claim doesn’t result in a recovery, you will pay nothing.

To schedule your free consultation, just call (866) 778-5500 today or fill out our secure contact form.

Below is a copy of the initial data breach letter issued by Baptist Health System (the actual notice sent to consumers can be found here):

Dear [Redacted],

This notice provides information about a recent cybersecurity incident that affected Baptist Medical Center and Resolute Health Hospital, from which individuals may have received services at one of our locations in Texas (collectively “we”). We are committed to protecting your information. This commitment includes notifying you if we believe that an incident may have involved your personal information. This notice provides information about the incident and the resources available to you.

What happened?

On April 20, 2022, it was discovered that certain systems within our network may have been infected with malicious code as a result of potentially unauthorized activity. In response to this incident, user access was immediately suspended to impacted information technology applications, extensive cybersecurity protection protocols were executed, and steps were quickly taken to restrict further unauthorized activity. In parallel, an investigation of the incident was immediately launched, and a national forensic firm was engaged to assist with investigation and remediation efforts. Although the investigation is ongoing, it has been determined that an unauthorized third party was able to access certain systems that contained personal information and remove some data from the network between March 31, 2022 and April 24, 2022. As a result of this review, it appears that your personal information may have been involved.

What information may have been involved?

Based on the review, the personal information involved in this incident may have included one or more of the following elements: (1) demographic information to identify and contact you, such as full name, date of birth, and address; (2) Social Security number; (3) health insurance information, such as name of insurer/government payor, policy and/or group number; (4) medical information, such as medical record number, dates of service, provider and facility names, chief complaint or reason for visit, and other visit, procedure and diagnosis information; and (5) billing and claims information, such as account and/or claim status, billing and diagnostic codes, and payor information. Your driver’s license number, credit and debit card information, bank account information and account passwords were not involved in this incident. Please note that not all data elements were involved for all individuals.

What we are doing.

We take the security of personal information seriously. As soon as the incident was discovered, a forensic investigation was immediately launched, law enforcement was contacted, and steps were taken to mitigate and remediate the incident and to help prevent further unauthorized activity. In response to this incident, security and monitoring capabilities are being enhanced and systems are being hardened as appropriate to minimize the risk of similar incidents in the future.

Individuals affected by this incident are being mailed notice letters. Since it is possible there may be insufficient contact information for some individuals, notice is being provided on the Baptist Medical Center and Resolute Health Hospital websites as permitted by HIPAA.

Complimentary credit monitoring and identity protection services are being offered to those whose Social Security number was potentially involved. There is a deadline of September 17, 2022 to activate these services, and instructions on how to activate these services are included in the notice letters sent to affected individuals. For additional information, please call the toll-free number listed below.

What you can do.

In addition to enrolling in the complimentary credit monitoring and identity protection services if you are eligible, the Additional Resources section at the top of this page includes additional information on general steps you can take to monitor and help protect your personal information. Please review the Additional Resources. We also encourage you to carefully review statements sent from healthcare providers and insurance companies to ensure that all of your account activity is valid. Any questionable charges should be promptly reported to the provider or company with which you maintain the account.

For more information

For the next 90 days, if you have any questions about this matter or would like additional information (including which types of your data may have been involved and whether you are eligible for complimentary credit monitoring and identity protection services), please call toll-free 1-833-423-2986. This call center is open from 9 am – 9 pm Eastern Time, Monday through Friday, except holidays. This substitute notice and toll-free number will remain active for at least 90 days.

We deeply regret any concern this incident may cause you and want to assure you that we take this matter seriously.

NOTICE: If you received a NOTICE OF DATA BREACH letter from Baptist Health System, contact the attorneys at Console & Associates at (866) 778-5500 to discuss your legal options, or submit a confidential Case Evaluation form here.