Experience. Creativity. Legal Muscle.

Southern Orthopaedic Associates/Orthopaedic Institute of Western Kentucky Data Breach Investigation

by | Dec 22, 2021 | Firm News

The law firm Markovits, Stock & DeMarco is investigating claims on behalf of victims of a data breach involving Southern Orthopaedic Associates d/b/a Orthopaedic Institute of Western Kentucky (“SOA/OIWKY”).

WHAT HAPPENED?

According to a recent press release issued by SOA/OIWKY, on or about July 7, 2021, SOA/OIWKY “became aware of suspicious activity relating to an employee email account.”[1] Its investigation later determined that an “unauthorized individual accessed several employee email accounts between June 24, 2021 and July 8, 2021,” and that these email accounts contained the sensitive personal information of its patients.[2] In a separate notification provided to the Maine Attorney General, SOA/OIWKY disclosed that the data breach exposed the sensitive data of 106,910 people.[3]

According to a sample notice letter provided to the Maine Attorney General, SOA/OIWKY did not begin notifying victims of the data breach until December 20, 2021.[4] Neither the letter provided to the Maine Attorney General nor the press release explain how the “unauthorized individual” gained access to “several” of its employee email accounts or why it did not detect this sooner.[5]

WHAT INFORMATION WAS EXPOSED IN THE DATA BREACH?

In its press release, SOA/OIWKY states the following data of its patients may have been exposed:

  • Names and dates of birth,
  • Social Security numbers,
  • driver’s license numbers and passport numbers,
  • financial account numbers and/or routing numbers,
  • credit/debit card numbers and security codes (CVV),
  • online account usernames and passwords, PINs or account logins,
  • medical billing/claims information,
  • diagnoses and health information,
  • medical record numbers,
  • Medicare/Medicaid identifications,
  • health insurance information, and
  • patient account numbers.[6]

WHAT SHOULD I DO IF I RECEIVED NOTIFICATION OF THE SOUTHERN ORTHOPAEDIC ASSOCIATES D/B/A ORTHOPAEDIC INSTITUTE OF WESTERN KENTUCKY DATA BREACH?

If you would like to have a free, confidential consultation with an attorney to learn more about your rights and potential legal remedies in response to the Orthopaedic Institute of Western Kentucky data breach, please contact Markovits, Stock & DeMarco attorney Terry Coates at (513) 651-3700, email us at [email protected], or submit a Case Evaluation request through the form below.

[1] https://www.prnewswire.com/news-releases/orthopaedic-institute-of-western-kentucky-provides-notice-of-data-privacy-event-301448413.html (last visited December 22, 2021).

[2] Id.

[3] See https://apps.web.maine.gov/online/aeviewer/ME/40/468e1668-f597-44bb-8f82-2f005d8c954a.shtml (last visited December 22, 2021).

[4] A copy of the sample notice letter provided to the Maine Attorney General can be located at https://apps.web.maine.gov/online/aeviewer/ME/40/468e1668-f597-44bb-8f82-2f005d8c954a.shtml (last visited December 22, 2021).

[5] See supra, n.1, 4.

[6] https://www.prnewswire.com/news-releases/orthopaedic-institute-of-western-kentucky-provides-notice-of-data-privacy-event-301448413.html (last visited December 22, 2021).