HIPAA Blog

[ Thursday, September 17, 2020 ]

 

 Blackbaud is (was?) one of the nation's largest service vendors to charitable institutions, helping them manage their donor lists and fundraising efforts.  They were subject to a ransomware attack that might've hit the mother lode of data, mainly on donors to these charities, but also to some of the beneficiaries and/or customers of the charities.  Obviously, some non-profit healthcare institutions were likely to get caught up in the mess, and the dominoes are starting to fall: Minnesota Children's (160,000 donors/patients) and Allina Health (200,000) have reported that they are victims


Jeff [12:12 PM]

Comments:
As of September 13, I had tabulated 38 Blackbaud clients who had patient data caught up in the breach. For the 14 entities for which I had numbers, that came to 3.6 million patients: https://www.databreaches.net/interim-report-on-the-blackbaud-breach-3-4-million-patients-and-counting/

As of yesterday, my counter was at 63 clients with patient data and another 7 where I couldn't tell for sure and sent inquiries. For the 24 entities I had numbers for, the new running subtotal is more than 4 million. That includes the Minnesota entities you named in your post.
 
Post a Comment
http://www.blogger.com/template-edit.g?blogID=3380636 Blogger: HIPAA Blog - Edit your Template