About 10,000 affected by security breach in Lawrence Memorial Hospital's online bill pay service

Lawrence Memorial Hospital, 325 Maine.

Lawrence Memorial Hospital, 325 Maine.

Financial information of about 10,000 people may have been posted online during a security breach by Lawrence Memorial Hospital’s online patient bill pay services.

LMH reported Friday that information maintained by its vendor Mid Continent Credit Services was inadvertently publicly available on the Internet between Sept. 20 and Oct. 28. This information may have been available:

• Patient name, phone number, email address, health care provider, payment amount and date of payment.

• Credit card information, including the type of card, name and address of the card holder, the account number, the verification number and the expiration date.

• Checking account information, including the check number, the account holder name and address, the checking account number and bank routing number, and the bank name and address.

Janice Early, LMH director of community relations, said the information did not include medical records and was not released by the hospital.

The security breach affects people who used the online bill pay service on the hospital’s website — lmh.org — which asks for either credit card information or bank account information. It does not affect people who paid for bills through their bank, by mail or phone. People use the online bill pay service not only for hospital bills, but to pay physicians groups and health fairs, Early said. The online pill bay service is currently unavailable.

“We are in the process of arranging for a new online payment system with a new vendor. We hope that it can be available within a week,” Early said.

The event occurred as a result of failed security measures on a website hosted by BrickWire LLC, which hosted the online patient bill pay service on behalf of Mid Continent Credit Services. LMH has had a contract with Mid Continent Credit Services since 2005, when it started online services.

Early said the hospital learned about the security breach by a patient on Oct. 28 and it immediately contacted Mid Continent Credit Services.

LMH is notifying patients through letters, which should be received during the next couple of weeks. It is advising people who have made online payments to monitor their account statements and credit reports for suspicious activity. Mid Continent has agreed to offer a free one-year credit monitoring subscription to individuals.

Anyone who has questions about the security breach should call LMH at 505-4945 or send an email to lmhcompliance@lmh.org.

“We take privacy and security of patient information very seriously and we sincerely apologize for the inconvenience caused by this event,” Early said.

Tagged: Lawrence Memorial Hospital

Comments

LadyJ 1 year, 6 months ago

Should be a minimum of 2 years at least. I believe Old Navy offered 2 years when employees social security information was breached. Credit card information is worse. I am willing to bet social security information was also in those records. They need to include the bank and credit card information that was in the records so we don't have to change all our credit card numbers and bank account numbers. Do they really think we should wait until something happens and then try to straighten things out? No thanks, I'll head them off at the pass.

0

riceballs 1 year, 6 months ago

No social security numbers or birth dates were in the records. All individuals affected will be personally notified.

0

toe 1 year, 6 months ago

Must be one of those discount out of town outsource companies that are so popular in Lawrence.

0

Janice Early-Weas 1 year, 6 months ago

No Social Security information or dates of birth were entered into the online bill pay system at any time. To clarify, individuals entered information, which included either bank account information if they were paying by check or credit card information if they were paying by credit card. The letters being sent will state which form of payment was used.

Also, I want to correct the statement in the story that says we were notified on Monday. An individual called the hospital Oct. 28, and the online bill pay site was shut down immediately. -- Janice Early, LMH Director of Community Relations

0

LadyJ 1 year, 6 months ago

Thanks, I was more worried about the social security numbers than anything else. Knew an elderly widow who could not file her income tax return and get her refund because somebody else had filed one under her name and social security number. Still think we should get two years of monitoring, please push for that.

0

Dave Greenbaum 1 year, 6 months ago

I filed a complaint about the online bill pay system provided by midccs.com back in August of 2006. The system sent a receipt for my payment in plain text and include the account number. Using that account information you can retrieve additional information about the account. No password was necessary. It was out there in plain view. I filed a HIPAA complaint when "infolmh infolmh@midccs.com" sent an email containing confidential email about my account.

If this is the same system used back then, the account will also have your doctor info (but not procedure) . I assume that what "health care provider" refers to in the article. Once someone knows your doctor, they possibly know something about your health history or current conditions. For example, if it's an oncologist, that communicates to others you have been most likely treated for cancer. Some may not want the fact they were treated by a mental health professional to be disclosed to the public.

Whom we see should be private and is of much more concern than a credit card number than can easily be cancelled. Linking the health care provider with someone's name and phone number (system didn't ask for address) is of much greater concern.

0

LadyJ 1 year, 6 months ago

Very good points that I had not considered. Thanks. Fortunately ours were of just family physician type. Glad I didn't use cell phone #. Land line number is used mostly to catch spam calls.

0

kbritt 1 year, 6 months ago

Thanks for the clarification. It has been corrected in the story.

0

opinion 1 year, 6 months ago

The article states the website in question is lmh.org. I believe the site listed on statements - lmhbillpay.com - is also one that the vendor used to process payments. I went to pay through there last week and it was no longer available.

0

kernal 1 year, 6 months ago

I wonder if Mid Continent's breach included other medical clients and if so, did they notify those clients?

0

Perses 1 year, 6 months ago

This is rather unusual. How was the information posted online? If the breach was from an outside source (hacker) the info is usually sold to others to exploit the financial accounts. Who had access to this information? The general public? So my question is; Was this an external breach or an internal security lapse that allowed the info to be seen? The recourse of those affected will be different based on the liability of Mid Continent.

0

LadyJ 1 year, 6 months ago

Good questions, let's hope they give us the answers.

0

Janice Early-Weas 1 year, 6 months ago

This was not a breach on LMH systems, nor was the system hacked. This was an internal failure of BrickWire's web security during a system update they completed. BrickWire's database, which was used to manage the online bill pay system, was inadvertently made publicly available on the Internet. -- Janice Early, LMH Director of Community Relations

0

phred 1 year, 6 months ago

Great that they are notifying by mail in a couple weeks (given they do have email addresses). That should give criminals plenty of time to run up charges on the credit card. It looks like I will be canceling a credit card today.

I am not impressed.

0

sherbert 1 year, 6 months ago

Wow, this is bad. And what an embarrassment to LMH. Seems like there should be some type of repercussion for this.

0

lisabeth2002 1 year, 6 months ago

I called on Monday to make a payment by phone (since I usually use the online bill pay but it wasn't available all weekend) and the lady on the phone didn't mention ONE WORD about any of this. I explained that I usually pay online but needed to pay over the phone since "apparently you're site isn't working." "Yeah, it's down right now," she said. Mail out letters within a few weeks?!? LMH needs to pull their head out and handle this like the serious situation that it is.

0

highbanks 1 year, 6 months ago

I think folks should just call the number and find out if their account is part of the breach. Then you'll know if you need to call your bank or credit card company.

0

phred 1 year, 6 months ago

Good idea, tried it and got a recording and voice mail. It doesn't appear the hospital is taking their patient's security very seriously and doesn't really care if people are financially hurt by this. They have already been sitting on the information for a week.

0

highbanks 1 year, 6 months ago

I called yesterday around 4. Spoke with a live person. She answered my questions. Said a letter would be coming, and that I should contact my credit card. Also said that I could get a one year subscription to a credit service paid for by the online company. Same response as when the deal happened at TJMaxx and Bank of America.

0

Oldsoul 1 year, 6 months ago

This comment was removed by the site staff for violation of the usage agreement.

0

Joe Hyde 1 year, 6 months ago

Looking at the bright side, this security breach offers the FBI an opportunity to conduct a high tech 2-prong sting operation that monitors electronic theft from specific private bank accounts, as well as identity thefts.

In today's world the more often cyber-thieves are caught, the happier I get.

0

Gareth 1 year, 6 months ago

Makes me very, very glad that long ago I refused to do any business with Mid-Continent. They have many complaints about their professionalism, their ethics, and violations of the Fair Credit Reporting Act.

0

Sigmund 1 year, 6 months ago

"The UCLA Health System is warning thousands of patients that their personal information was stolen and they are at risk of possible identity theft, officials said in a statement released Friday."

"The stolen patient information included first and last names as well as some birth dates, medical record numbers, addresses and medical information, officials said. It did not include Social Security numbers, credit card or insurance details. The patient information was from 2007 through 2011." "UCLA medical officials say patient information data stolen" LA Times, November 4, 2011. http://latimesblogs.latimes.com/lanow/2011/11/ucla-patient-identification-stolen.html

Management at these companies have a affirmative duty to protect patients information from disclosure under numerous federal and state laws. Victims of computer crimes have been given the legal authority to peruse civil action under federal law. Corporations can be held corporately liable and management can be held personally liable for failure to ensure due care in implanting and complying with recognize standards.

Only when these companies and managers are hauled into court and held accountable for their failures they will begin to take their customers and patients personal information serious. While LMH may have a CIO I doubt he or she has a single certified computer security professional (CISSP or equivalent) on their staff.

0

SarcasmIsALostArt 1 year, 6 months ago

There's quite a bit of info here that we're missing.. 1) Is there any evidence that the database was accessed via an external connection? 2) Did the vendor perform any testing or perform any secure scans post 'maintenance' work? ...ie did the vendor do its due diligence in providing a secure service? 3) Did LMH vet the vendor? 4) Did LMH mandate certain standards in their SLA's requiring x standard to be provided? 5) Did LMH sign a BA in absolving them of liability in these billing transactions?

Prob won't get these answers from a news service...but as a customer I'd be demanding to see the granulars, especially if my data was at risk. Although given it was limited to financial data and minus any PII (SSN's etc etc), the damage at least has the potential to be limited.

0

bc 1 year, 6 months ago

It's clear the vendor was not PCI compliant which I believe is required if you are going to at least process Visa/MasterCard. Storage of card verification codes is prohibited under the standards.

0

Kelsey_Ryan 1 year, 6 months ago

Glad to hear about this.... looks like a new credit card number is in order.

0

Commenting has been disabled for this item.

Relay For Life of Douglas County »

Light up Douglas County with a Birthday Celebration!

May 22, 2013 marks the 100th Birthday of the American Cancer Society (ACS). The ACS has worked relentlessly to save lives and create a world ...

Growing Food, Growing Health »

Growing Food, Growing Health 2013 Crew

We are in constant amazement of the magical, inspirational growth in our gardens. Throughout a season, we watch dozens of species blossom and change, growing ...

Bobcat Marathon Club »

Wait! There's More!

Haley finishes with 26.2!

Two more finishers to end the season! Way to go Bobcats! Now that's a wrap!

Bert Nash Community Mental Health Center »

Easy rider

Bicycling is part of a healthy lifestyle.

May is Bike Month, but every month is bike month for Bert Nash psychiatrist Joe Douglas. He rides his bicycle to work year-round, weather permitting, ...

Fun Runs and Walks »

Run for Kids 5K

The Run for Kids 5K run/walk will take place Sunday, May 19, 2013 starting at 8 am. The race will start behind Johnny's Tavern at ...

Relay For Life of Douglas County »

Relay Idol Competition at Relay For Life of Douglas County

Relay Idol Flyer

Got talent? Prove it! Introducing Relay Idol to Relay For Life of Douglas County Friday, June 7th, 2013 Free State High School Track Lawrence, KS ...

NeuCare Family Medicine »

Creating end-of-life wishes with a free, online service

MyDirectives.com. A free online service to create a personalized Advanced Medical Directive.

As a primary care provider, I ask all new patients if they have end-of-life wishes or formal "Advanced Medical Directives". Advanced directives are often part ...

Bert Nash Community Mental Health Center »

Be our guest

Bert Nash CEO David Johnson hosted a group of visitors from Africa. Each member of the Rotary group study exchange team works in the medical field.

Visitors from Africa — part of a Rotary group study exchange — were guests at the Bert Nash Center on Wednesday and attended a Discover ...

Marcia Epstein's Blog »

Headquarters Counseling Center Receives 2013 Crisis Center Excellence Award

Headquarters Counseling Center was honored with the Crisis Center Excellence Award by the American Association of Suicidology (AAS) at their conference in Austin. The annual ...

LMH working to prepare for 'Obamacare' insurance exchanges, but questions aplenty remain

There are still a lot of details even the top officials at Lawrence Memorial Hospital don’t understand about the new system of buying health insurance under the federal Affordable Care Act. But Joe Pedley, LMH’s chief financial officer, believes one concept for consumers is abundantly clear. “People had better learn how to do math,” Pedley said. By Chad Lawhorn

A Trail a Day »

Summer Love: Tips for hot weather running

In the heat of summer, try to schedule runs early or late in the day and find shade.

As I entered mile five or so of my run this morning, I started thinking time had sped up and it was July because no ...

Bobcat Marathon Club »

NOT TOO HOT TO TROT ... OR FINISH A MARATHON!

Andrew! Nice work!

Aye, aye aye! We had 42 marathon finishers today! As a club, we ran a total of 6,839.8 miles! We had 132 kids finish one ...

Lawrence-Douglas County Health Department »

Lawrence environmental health specialist takes mission trip to remote Alaskan area

Andrew Stull, environmental health specialist for the Lawrence-Douglas County Health Department, stands between the bones of a Bowhead whale near a cemetery in Point Hope, Alaska.

Andrew Stull, environmental health specialist for the Lawrence-Douglas County Health Department, spent two weeks in April in Kotzebue, Alaska, and five nearby villages as part ...

Aging Well »

THE SENIOR CELEBRATION ART SHOW and RECEPTION

SENIOR CELEBRATION ART SHOW &
RECEPTION

THE SENIOR CELEBRATION ART SHOW - June 1st thru 30th 1510 St. Andrews Drive at Drury Place at Alvamar 10:00 am to 5:00 pm daily ...

Linda Cottin's Blog »

Farmers Markets Are the Key Ingredient

With fresh ingredients from your local farmers market it is easy to make even the simplest of meals special.

On Friday, May 10, Micahel Pollan spoke about his new book “Cooked” at the Unity Temple in Kansas City. Several folks from Lawrence were lucky ...

Bert Nash Community Mental Health Center »

Mental Health Month proclamation

Mayor Dever reads a proclamation observing Mental Health Month.

Lawrence Mayor Michael Dever read a proclamation at Tuesday's city commission meeting in observance of Mental Health Month, proclaiming "a commitment to community-based systems of ...

Healthy Body & Mind »

Third graders get moving at Kansas Kids Fitness Day

Jump Rope Relays was one of 10 activity stations for students at Kansas Kids Fitness Day.

Anschutz Sports Pavilion on the University of Kansas campus was bursting with energy last Friday morning as 620 third-graders from Northeast Kansas filled it as ...

Lawrence-Douglas County Health Department »

Debbie Mitchell marks 5 years of service in Health Department's clinic office — 'a busy place'

Debbie Mitchell, clinic office assistant at the Lawrence-Douglas County Health Department, was recognized May 14, 2013, during a staff meeting for five years of service.

Before joining the Lawrence-Douglas County Health Department staff five years ago, Debbie Mitchell admits she had “no clue” about all of the services it provided ...

Independence, Inc. »

Donations Needed Immediately to Build Wheelchair Ramp for Eudora Man

Steve Hall needs to see his doctor, but until a wheelchair ramp can be constructed, he is effectively trapped in his home. Volunteers have agreed ...

Double Take: And next teen co-author is...

We had a record nine applicants for this year’s Double Take contest, with three juniors and six seniors, one from Free State, four from Bishop Seabury Academy and four from Lawrence High.

Doctor finds 'A Healthier Wei' to treat kids

Julie Wei was a pediatric Otolaryngologist, or ear, nose and throat specialist, at the University of Kansas Medical Center for more than ten years when she began to see a trend that she didn’t like: a large number of children with chronic congestion. Wei’s book, “A Healthier Wei” is an explanation of why she believes children are being misdiagnosed and wrongly medicated and her theory, with proven success, on how to fix these problems.

American Cancer Society to host volunteer open house

As a celebration of the 100th birthday of the American Cancer Society, the organization is encouraging people to raise awareness and join the fight against cancer.

Relay For Life of Douglas County »

Celebrate the American Cancer Society's 100th Birthday

May 22, 2013 marks the American Cancer Society's 100th Birthday. As the official sponsor of birthdays, we believe this year provides a unique opportunity for ...

Bobcat Marathon Club »

Record High!

Will just completed his 2nd marathon of the year!

We had a record high of 20 finishers today! Over 100 of our kids at Langston Hughes Elementary have completed 26.2 miles or more over ...

Belinda Rehmer's Blog »

LMH to Hold Stroke Risk Mini-Screening Event

May is Stroke Awareness Month. A stroke or brain attack is currently the fourth leading cause of death in the United States, but according to ...

Lawrence-Douglas County Health Department »

Lawrence-Douglas County Health Department celebrates nurses

Our nurses are, back row from left, Catherine Bird, Kathy Colson, Shirley Grubbs, Kelli Raney and Peggy Gabler; front row from left, Carolyn Ball, Corey Roelofs, Ashley Halton and Kim Ens.

It's National Nurses Week! At the Lawrence-Douglas County Health Department, nurses work in a variety of programs and do a variety of tasks. Those tasks ...

KHI News Service »

Kansas to get new ACA jobs despite snub of health care law

Lawrence call center expected to add positions to handle insurance exchange calls. Four states that have snubbed the federal health law by defaulting to the ...

Bert Nash Community Mental Health Center »

Takin' it to the streets: Bert Nash team reaches out to the Lawrence homeless population

David Tucker is a member of the Bert Nash homeless outreach team. He also works at the Lawrence Community Shelter.

With their long hair and long beards, they look like rock stars. But they don’t act like it. No limos or five-star hotels for this ...

Bobcat Marathon Club »

Aw Caramba!

Braiden brings in a strong finish!

Aw Caramba! We had 13 finishers today! These kids are motivated! Only two more days of marathon club left :-) See ya there!

Bert Nash Community Mental Health Center »

Bert Nash peer support specialist tells her story with goal of giving hope to others

Susan Murphy shares her story to show people that recovery is possible.

My days were dark for 30 plus years. With a degree in secondary education, I was a teacher until I was diagnosed with anorexia. I ...

Log in to your WellCommons account.

You may also use your LJWorld.com, Lawrence.com or KUSports.com account.

Forgotten your password?

Don’t have a WellCommons account? Get one now!

An account lets you join in the conversation, mark your favorites, get your own Blog and more.