Notice of Data Security Incident
Posted July 24, 2020
The University of Maryland Faculty Physicians, Inc. ("FPI") and the University of Maryland Medical Center ("UMMC") are committed to maintaining the privacy and security of information. FPI is the faculty practice plan for the physician practice groups affiliated with the University of Maryland School of Medicine, which supports certain physicians and staff who provide services at UMMC locations.
FPI and UMMC have notified a limited number of patients about the recently discovered unauthorized access of an FPI email account. Upon learning that there may have been unauthorized access to the FPI email account that contained both FPI and UMMC patient information, FPI secured the account and a prompt and thorough investigation was commenced.
After an extensive forensic investigation and comprehensive manual document review, it was determined on May 26, 2020 that the email account that was accessed between February 6, 2020 and February 11, 2020 contained identifiable personal and/or protected health information.
The accessed FPI email account contained the personal and/or protected health information of certain patients, including name, date of birth, medical record number (used for internal purposes only), and clinical information about care received from a UMMC location or from an FPI-affiliated physician. A limited number of individuals' Social Security numbers were also contained in the accessed email account. This incident does not affect all patients of FPI and UMMC and not all of these identifiers were included for each notified individual.
At this time, FPI and UMMC have no evidence that any information has been acquired or misused. However, out of an abundance of caution, FPI and UMMC have notified individuals whose information may have been contained in the accessed account.
To help prevent something like this from happening again, FPI and UMMC are reviewing their email policies and procedures and working to further enhance email security. It is recommended that patients review the statements they receive from their healthcare providers. If patients see services they do not recognize, they should contact their provider immediately.
For further questions or additional information regarding this incident, or to determine if you may be impacted by this incident, a dedicated toll-free response line has been set up at 1-855-917-3590. The response line is available Monday through Friday, 9:00 a.m. to 9:00 p.m. Eastern Time.