Jefferson University Hospitals

Notice to Patients of Vendor Security Incident

07/19/21

cyber-security-news

Jefferson Health is committed to protecting the security and confidentiality of patient information. This notice concerns a recent security incident experienced at one of our vendors, Elekta, Inc., involving some of our patient information. Elekta provides a cloud-based mobile application known as SmartClinic, which allows our clinic providers to access patient information related to cancer treatments.

On May 26, 2021, Elekta informed us that an unauthorized individual gained access to Elekta’s systems between April 2, 2021 and April 20, 2021 and, during that time, acquired a copy of the SmartClinic database that stores some of our patients’ information. The information may have included patient names, dates of birth, medical record numbers, and clinical information related to treatment at Jefferson Health, such as physician name and department, date(s) of service, treatment plan, diagnosis and/or prescription information. For some patients, a Social Security number was also included. Financial account, insurance and payment card information was not involved.

This incident did not involve access to Jefferson Health’s systems, network, or electronic health records. It occurred on Elekta’s systems, which held a database for cancer patients seen at Sidney Kimmel Cancer Center – Jefferson Health. The incident was not targeted at Jefferson Health or its hospitals.

Jefferson Health is mailing letters to patients whose information may have been involved in this incident. Jefferson Health is also providing individuals whose Social Security number was involved with complimentary credit monitoring and identity theft protection services. Patients are encouraged to review statements from their healthcare providers, and to contact them immediately if they see any services they did not receive.

Jefferson Health regrets this incident occurred and is committed to protecting the security and privacy of patient information. To help prevent something like this from happening again, Jefferson Health is re-evaluating its relationship with Elekta. Patients with questions can call the dedicated call center at (866) 281-0520, Monday through Friday from 9:00 a.m. to 11:00 p.m., and Saturday and Sunday from 11:00 a.m. to 8:00 p.m. Eastern Time.