0 comments | Print

Sutter Health sued over theft of computer containing patient data

Published: Wednesday, Nov. 23, 2011 - 12:00 am | Page 6B
Last Modified: Sunday, Nov. 27, 2011 - 2:57 pm

Sutter Health is being sued for negligence and other allegations in the mid-October theft of a computer from Sutter Medical Foundation headquarters that held information on more than 4 million of its patients.

The class-action suit, filed Monday on behalf of plaintiff Karen Pardieck of Folsom in Sacramento Superior Court, alleges that the Sacramento-based health network was negligent in safeguarding its computers and data and then did not notify the millions of patients whose data went missing within the time required by state law. The suit seeks $1,000 for each member of the class and attorneys' fees.

The computer was stolen during a break-in through a smashed window the weekend of Oct. 15. Employees discovered the theft Oct. 17. Sutter patients were being notified last week.

"Sutter should've had that under lock and key, not protected by a pane of glass," attorney Robert Buccola of the Sacramento firm Dreyer Babich Buccola Wood LLP, which filed the suit, said Tuesday. "If there's proprietary information in their files, they have a financial interest to make sure security is of the utmost importance."

Some 3.3 million patients whose providers are supported by Sutter Physician Services were affected.

Their names, addresses, email addresses, dates of birth, telephone numbers and names of patients' health insurance plans dating from 1995 were contained in the computer's database.

The computer contained the same information for 943,000 Sutter Medical Foundation patients. It also included data on foundation patients from January 2005 to January 2011, including descriptions of medical diagnoses or procedures used for business operations.

Sutter Health officials said the data breach is the largest ever at the health network.

The data were stored on a password-equipped but unencrypted desktop computer in the administrative offices of Sutter Medical Foundation in Natomas.

Sutter officials said they were in the process of encrypting patient data stored on its desktop computers, but had not yet protected the stolen computer. Data on its laptop and mobile devices were secure.

Reports of missing or stolen patient information are becoming a more common occurrence.

Over the last two years, health care organizations have reported 364 incidents involving the loss or theft of information ranging from names and addresses to Social Security numbers and medical diagnoses on nearly 18 million patients, according to the Associated Press.

On Tuesday, Sutter spokesman Bill Gleeson defended the time it took the health network to notify patients, saying a team had to first determine what was on the computer. Sutter also put a private investigator on the case.

"It took some time. We began a detailed, complicated process of notifying that number of patients," Gleeson said.

Gleeson also said Sutter "deeply regrets the theft," but would not comment on the lawsuit or on allegations that the health network had no system to back up the millions of pieces of data contained in the stolen computer.

© Copyright The Sacramento Bee. All rights reserved.


Call The Bee's Darrell Smith, (916) 321-1040.

Read more articles by Darrell Smith



About Comments

Reader comments on Sacbee.com are the opinions of the writer, not The Sacramento Bee. If you see an objectionable comment, click the "Report Abuse" link below it. We will delete comments containing inappropriate links, obscenities, hate speech, and personal attacks. Flagrant or repeat violators will be banned. See more about comments here.

What You Should Know About Comments on Sacbee.com

Sacbee.com is happy to provide a forum for reader interaction, discussion, feedback and reaction to our stories. However, we reserve the right to delete inappropriate comments or ban users who can't play nice. (See our full terms of service here.)

Here are some rules of the road:

• Keep your comments civil. Don't insult one another or the subjects of our articles. If you think a comment violates our guidelines click the "Report Abuse" link to notify the moderators. Responding to the comment will only encourage bad behavior.

• Don't use profanities, vulgarities or hate speech. This is a general interest news site. Sometimes, there are children present. Don't say anything in a way you wouldn't want your own child to hear.

• Do not attack other users; focus your comments on issues, not individuals.

• Stay on topic. Only post comments relevant to the article at hand.

• Do not copy and paste outside material into the comment box.

• Don't repeat the same comment over and over. We heard you the first time.

• Do not use the commenting system for advertising. That's spam and it isn't allowed.

• Don't use all capital letters. That's akin to yelling and not appreciated by the audience.

• Don't flag other users' comments just because you don't agree with their point of view. Please only flag comments that violate these guidelines.

You should also know that The Sacramento Bee does not screen comments before they are posted. You are more likely to see inappropriate comments before our staff does, so we ask that you click the "Report Abuse" link to submit those comments for moderator review. You also may notify us via email at feedback@sacbee.com. Note the headline on which the comment is made and tell us the profile name of the user who made the comment. Remember, comment moderation is subjective. You may find some material objectionable that we won't and vice versa.

If you submit a comment, the user name of your account will appear along with it. Users cannot remove their own comments once they have submitted them.

hide comments
Sacramento Bee Job listing powered by Careerbuilder.com
Quick Job Search
Buy
Used Cars
Dealer and private-party ads
Make:

Model:

Price Range:
to
Search within:
miles of ZIP

Advanced Search | 1982 & Older



Find 'n' Save Daily DealGet the Deal!

Local Deals