Noblesville, IN — Riverview Health (“Riverview”) is providing notice of a recent data security incident that may have affected certain individuals’ protected health information. The incident resulted from a social engineering attack that led to the compromise of a staff member’s electronic mail (“email”) account by an unauthorized individual. On August 23rd, 2024, Riverview discovered that access to one of its staff member’s e-mail accounts had been compromised by an unauthorized individual, leading such individual to have access to the compromised e-mail account as well as certain electronic files. Upon access to the staff member’s account, Riverview’s security mechanisms promptly identified the threat and access was terminated in less than one hour from the start of the intrusion. After further investigation, Riverview confirmed on September 3rd, 2024, that the accessible files contained certain protected health information, which may have included medical record numbers, admission dates, diagnosis and medical information, names, dates of birth, and sex. No social security numbers, financial information or bank account numbers were exposed. Although the access was terminated shortly after it was obtained, Riverview is notifying the patients whose information may have been exposed.
Riverview believes that due to the limited information contained in the exposed files, the risk of compromise or harm to patients is low. However, Riverview is taking this matter very seriously and is identifying internal and external processes to prevent future recurrences. This includes reviewing policies around phishing and social engineering attacks, as well as evaluating methods and procedures around electronic access and controls.
As required by federal law, Riverview is also notifying the U.S. Department of Health and Human Services Office for Civil Rights. Riverview patients impacted by this disclosure are also expected to receive letters in the mail notifying them of this incident within the next few days. As a precautionary measure, please remain vigilant by reviewing suspicious activity related to the use of your protected health information. Patients who have concerns or questions may contact Riverview by phone or mail utilizing the following contact information:
Toll Free Phone Number: (855) 278-0525; Call center representatives are available Monday through Friday from 9:00 a.m. to 9:00 p.m. Eastern Time, excluding major U.S. holidays.
Mailing Address: 395 Westfield Road, Noblesville, Indiana 46060; Attention Privacy Officer.
Riverview truly values our relationship with its patients and looks forward to continuing its service to its patients and the community.