A Dallas-area women’s health practice has told Texas regulators that an intruder reached the records of 16,876 patients.
The Vernon & Waldrep OB-Gyn Associates filing said the exposed information includes names, addresses, medical information, health insurance information and dates of birth. Impacted individuals are being notified by mail.
The practice had not, at the time of the filing, detailed how the intruder gained access or how long the exposure lasted.
Attorneys are reviewing the incident for a possible class action.
For a specialty clinic, the data set is exactly what makes medical-record theft persistent: a combination of identity details and gynaecological or obstetric history creates a trail that is difficult to change, unlike a compromised password.
Small and mid-sized practices remain a soft target because they often rely on a single IT vendor and lack round-the-clock monitoring. Basic controls, including multi-factor authentication on remote access, least-privilege accounts and logging of bulk record queries, would blunt many of these incidents.
Patients should review insurer statements for services they never received and consider a credit freeze.