Sanford Health, the largest rural health system in the United States, has notified more than 21,000 patients that their personal and medical information may have been exposed in a data security incident at one of its imaging vendors. The incident did not occur inside Sanford Health systems. It happened at DMS Health Technologies, the company that supplies and operates the mobile heart screen trucks Sanford Health patients use for cardiac screening.
Patients who trust a health system with their medical histories rarely know how many outside companies handle that same information along the way. When a hospital or clinic shares patient data with a vendor, the obligation to keep that information secure travels with it, and both the provider and the vendor are responsible for protecting it.
Sanford Health’s Data Breach Investigation
The investigation centers on DMS Health Technologies, a West Fargo, North Dakota company that provides mobile imaging services to hospitals and health systems across the region. DMS owns and operates fleets of mobile MRI, CT, PET/CT and nuclear medicine units, and Sanford Health contracts with the company for the mobile heart screen trucks it sends into rural communities. Because DMS handles patient information in order to perform those screenings, records belonging to Sanford Health patients were stored on the DMS network at the time of the incident.
According to information released by DMS, the company became aware of suspicious activity affecting certain computer systems on April 23, 2023. DMS launched an investigation with the assistance of third-party forensic specialists and determined that an unauthorized party had access to its network between March 27 and April 24, 2023. During that window, the intruder had the ability to access information stored on the network. DMS then conducted a review of the files at risk to determine whose information was involved, a process that took several months to complete before individual notifications went out.
Sanford Health publicly disclosed its share of the incident on September 15, 2023, confirming that 21,211 of its patients would be notified. The affected patients are spread across the health system’s rural footprint: 10,334 in North Dakota, 4,967 in Minnesota, 2,685 in South Dakota, 1,058 in Iowa, and smaller numbers across 36 additional states. Sanford Health serves more than one million patients across roughly 250,000 square miles, operating 46 medical centers and employing about 2,800 physicians and advanced practice providers.
Sanford Health was not the only health system affected. DMS contracts with multiple providers, and at least two others disclosed related breaches in the same period. Avera reported roughly 1,500 affected patients and Monument Health reported roughly 2,500, with all three systems headquartered in South Dakota. DMS, rather than the individual health systems, took responsibility for mailing notification letters to affected patients and for offering identity monitoring services through Kroll to some of them, depending on the specific information exposed in each case.
Incidents like this one illustrate why third-party vendors have become such a significant source of risk in healthcare. A single imaging contractor, billing company or records vendor can hold data belonging to patients of many unrelated hospitals, which means one intrusion can cascade into breach notifications across several states and several health systems at once. Rural health systems are particularly dependent on shared mobile and contracted services, because the patient volume in any single community rarely justifies permanently installed imaging equipment.
The categories of information involved here are less immediately dangerous than a Social Security number or a financial account number, but they are far from harmless. Names paired with dates of birth are durable identifiers that do not change and cannot be reissued after a breach the way a payment card can. Combined with a date of service, a physician name and an exam type, they also reveal that a specific person sought a specific kind of medical care on a specific date, which is sensitive on its own terms and can be used to make fraudulent contact appear credible.
That last point is the practical risk for most people affected. Someone holding this combination of details can call or email a patient, correctly reference the screening they had and the physician who ordered it, and use that accuracy to request a Social Security number, an insurance policy number or a payment. Health systems and their vendors do not typically ask for that information by unsolicited phone call or email, and patients who receive such a request after a breach notification should treat it with suspicion regardless of how well informed the caller seems.
Breach notification timelines are also worth understanding. Federal and state laws generally require notice within a set number of days after a breach is discovered, but the clock and the practical reality often diverge, because determining exactly whose records were in an affected system can take months of file review. That gap between the intrusion and the letter is normal in the sense that it is common, but it also means affected patients may be exposed for a considerable period before they learn anything happened.
When Did This Breach Occur?
The unauthorized access to the DMS Health Technologies network took place between March 27 and April 24, 2023. DMS became aware of suspicious activity on its systems on April 23, 2023, near the end of that window, and moved to secure the network.
DMS published its public notice of the data event on June 16, 2023, while it was still working to identify the individuals whose information was involved. Sanford Health announced its own patient impact on September 15, 2023, nearly five months after the intrusion ended. Avera disclosed on September 6, 2023, and Monument Health disclosed on the same day as Sanford Health.
The staggered dates reflect a sequence common to vendor breaches. The vendor detects and investigates first, then determines which client organizations had data on the affected systems, and only then can each health system tell its own patients how many were involved.
What Information Was Breached?
The information potentially involved varies by individual, but according to the notice it was generally limited to names, dates of birth, dates of service, physician names and exam types.
DMS has stated that the exposure typically did not extend beyond those categories. Where the specific information involved warranted it, DMS offered complimentary identity monitoring services through Kroll, with the details included in each individual notification letter. That approach indicates the company assessed the risk as varying from person to person rather than being uniform across everyone affected.
Notice of the incident was also provided to federal law enforcement and to the U.S. Department of Health and Human Services, the standard path for an incident involving protected health information.
What You Can Do
If you received a notification letter from DMS Health Technologies about this incident, or you were a Sanford Health mobile heart screen patient during the relevant period, there are several steps worth taking.
- Read the notification letter closely to see which categories of your information were involved and whether identity monitoring through Kroll was offered to you.
- Enroll in any monitoring service offered, since there is no cost to you and enrollment deadlines apply.
- Review explanation of benefits statements from your health plan for services you did not receive, which can be a sign of medical identity theft.
- Request your free annual credit reports from the three major bureaus and check for accounts you did not open.
- Consider placing a fraud alert or a security freeze on your credit file, both of which are free.
- Be skeptical of unsolicited calls, texts or emails referencing your medical care, even when the caller knows accurate details about your exam or your physician.
You can also contact DMS directly at 866-373-7164 to ask whether your information was affected by this incident.
File a Data Breach Lawsuit Against Sanford Health
Patients whose protected health information is exposed through a vendor relationship they never chose, and may not have known existed, have grounds to ask how that data was protected and whether reasonable safeguards were in place. Legal claims arising from breaches of this kind commonly examine the security measures a company had implemented, how quickly an intrusion was detected, and how long affected individuals waited before they were told.
Speaking with an attorney costs nothing and does not obligate you to file anything. It is simply a way to understand what options exist, particularly if you have already seen suspicious activity following the notice.
Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.