Loretto Hospital Data Breach Details
On January 17, 2025, Loretto identified suspicious activity within its computer network. Upon discovering the issue, the hospital immediately launched an investigation. The investigation revealed that the network had been accessed by an unknown actor between January 17, 2025, and February 1, 2025, during which time certain files were copied.
Additionally, due to this incident, data entered into the electronic medical record system between the evening of February 2, 2025, and the afternoon of February 3, 2025, was not saved. While Loretto worked diligently to restore and recover as much patient data as possible during this downtime, some records may not have been fully recovered or recreated.
Loretto is offering affected individuals access to free credit monitoring and medical identity protection services.
Personal Information Affected
The specific data involved may differ for each individual, but it could include the following categories:
-
Contact Details: Name, address, phone number, and email
-
Medical/Clinical Information: Date(s) of service, diagnoses, treatment, medical record number, lab results, patient number, provider name, and treatment location
-
Health Insurance Information: Plan name, plan type, insurance company details, and member/group ID numbers
-
Billing, Claims, and Payment Data: Claim numbers, billing details, bank account information (including bank name, account number, and routing number), billing codes, payment card details, and financial information
-
Additional Identifiers: Social Security Number, driver’s license or state ID number, passport number, date of birth, and other government identifiers