1 min read

Lexington Diagnostic Center data breach exposes nearly 30K

digital face surrounded by code

On December 24, 2024, Lexington Diagnostic Center (LDC) filed a data breach notice with the U.S. Department of Health and Human Services Office for Civil Rights (OCR). The breach, caused by unauthorized access to the company’s computer system, exposed sensitive consumer information, including Social Security numbers and medical details.  

 

What happened  

On March 16, 2024, Lexington Diagnostic Center identified suspicious activity on its computer network. Following the discovery, LDC secured their network, and cybersecurity experts launched an investigation. 

The investigation revealed that an unauthorized party accessed archived files between February 26 and March 16, 2024. The compromised data varied by individual but could include names, addresses, phone numbers, dates of birth, Social Security numbers, and medical information. 

After identifying affected individuals, LDC sent notification letters on December 24, 2024, outlining the specific data compromised.  

 

What was said

The LDC public notice assures, “We have no evidence that any of your information has been used for identity theft or financial fraud as a result of this incident.”

It also stated its commitment to improving cybersecurity measures, saying, “LDC is committed to maintaining the privacy of personal information in its possession and has taken many precautions to safeguard it. LDC continually evaluates and modifies its practices to enhance the security and privacy of the personal information it maintains.”  

 

Why it matters  

Healthcare data breaches are increasingly common, affecting millions annually. These breaches compromise personal data, like protected health information (PHI), with long-term implications, including identity theft, financial fraud, and unauthorized use of medical identities. Healthcare organizations, like LDC, must invest in comprehensive cybersecurity measures to protect patient trust and data integrity.

Learn more: How HIPAA compliance improves patient trust

 

FAQs

What is a data breach?

A breach occurs when an unauthorized party gains access, uses or discloses protected health information (PHI) without permission. Breaches include hacking, losing a device containing PHI, or sharing information with unauthorized individuals.

See also: How to respond to a data breach

 

What should individuals do if their data has been compromised?

If individuals suspect their data has been compromised, they must monitor their accounts for suspicious activity and report any unauthorized transactions immediately.

 

Are there any costs associated with placing a fraud alert or credit freeze?

No, under U.S. law, consumers are entitled to a free credit report annually from each of the three major credit reporting bureaus, Equifax, Experian, and TransUnion. So, placing a fraud alert or credit freeze does not incur any costs.

Digital security shield with keyhole on blue hexagonal network background

Accendo Insurance reports major data breach from business associate

Ascendo Insurance recently announced a breach impacting over 16,000.

Read More
Red warning triangle icon on keyboard

411,000 patients affected by Specialty Networks data breach

Specialty Networks, Inc. experienced a data breach in December 2023, compromising the protected health information of 411,037 patients.

Read More
3D fingerprint pattern on a circuit board with electronic components

Email account breaches reported by 4 HIPAA-covered entities

Four healthcare organizations have recently reported email account breaches, leading to unauthorized access to sensitive patient data. The impacted...

Read More