FMOLHS logo
ServicesFind a Doctor
Locations
Patients & Guests
Research and Education

Notice of Ciox Email Security Incident

March 14, 2022

Our Lady of the Lake Regional Medical Center contracts with Ciox to process requests for medical records. The Lake was informed by Ciox that information, from a limited number of our record requests, was included in their breach. For more information, please read the following release from Ciox.

Ciox Health is working with our customers to notify individuals whose information may have been involved in an incident involving unauthorized access to a Ciox employee’s email account. Ciox is posting this notice on behalf of multiple healthcare providers listed here.

What Happened?
An unauthorized person accessed one Ciox employee’s email account between June 24, 2021, and July 2, 2021, and during that time may have downloaded emails and attachments in the account. Ciox reviewed the account’s contents to determine whether sensitive information was contained in the account. On September 24, 2021, Ciox learned that some emails and attachments in the employee’s email account contained limited patient information related to Ciox billing inquiries and/or other customer service requests. The review was completed on November 2, 2021.

Between November 23, 2021, and December 30, 2021, we began the process of notifying our healthcare provider customers of this incident. Since then, we have worked with the providers to notify the affected individuals whose information was identified by the review.

What Information Was Involved?
The information involved included patient names, provider names, dates of birth, and/or dates of service. In very limited instances, the information involved may have also included Social Security numbers or driver’s license numbers, health insurance information, and/or clinical or treatment information.

It is important to note that the Ciox employee whose email account was involved did not have direct access to any healthcare provider’s or facility’s electronic medical record system.


What Ciox Is Doing

Ciox takes the privacy and confidentiality of the information it maintains very seriously, and we continuously evaluate our security procedures against industry best practices. To help prevent something like this from happening again, we have and will continue to identify opportunities to implement additional procedures to further strengthen our email security, including by providing enhanced cybersecurity training to our employees. We also have been working with our customers to notify individuals whose information was contained in the email account.


What You Can Do

While the investigation did not find any instances of fraud or identity theft that have occurred as a result of this incident, out of an abundance of caution, beginning December 30, 2021, Ciox will be working with our customers to notify patients whose information was reflected in the emails and/or attachments and for whom we had sufficient contact information. We are also providing resources involved individuals can use to help protect their information, including complimentary credit monitoring and identity protection services to the limited number of individuals whose Social Security numbers or driver’s license numbers were involved in this incident.

Ciox believes that the account access occurred for purposes of sending phishing emails to individuals unrelated to Ciox, not to access patient information. However, as a precaution, Ciox recommends individuals review statements received from their healthcare providers and health insurers. If they see charges for services they did not receive, they should contact the provider or insurer immediately.


For More Information

Ciox has also established a dedicated, toll-free call center for questions about this incident. The call center may be reached at (855) 618-3107 Monday through Friday, between 9:00 a.m. and 6:30 p.m., Eastern Time, excluding some major U.S. holidays.




About Our Lady of the Lake Health

Our Lady of the Lake Health is a not-for-profit Catholic healthcare ministry based in Baton Rouge, Louisiana, with more than 7,500 employees committed to serving the Capital Region and building a healthy community through excellence in patient care and education. With an 800-bed Regional Medical Center, a dedicated Children’s Hospital, a 78-bed hospital in Gonzales, Louisiana, two freestanding emergency rooms in outlying parishes, and a 600+ provider Physician Group, Our Lady of the Lake Health provides comprehensive healthcare services for common to complex conditions. Our Lady of the Lake Regional Medical Center is a primary teaching site for graduate medical education programs in partnership with LSU, and is recognized in the areas of heart and vascular, trauma and emergency care, stroke, cancer care, minimally invasive procedures, and more. Our Lady of the Lake is part of the Franciscan Missionaries of Our Lady Health System and is driven by its mission to serve all God’s people, especially those most in need. For more information, visit ololrmc.com.

Media Contact

Chrislyn Maher
Senior Director, Marketing & Communications
Our Lady of the Lake Health

 

Email

Recommended News