Community Psychiatry Management, LLC, dba Mindpath Health Announces Data Breach

Console and Associates, P.C.
Contact

On January 10, 2023, Community Psychiatry Management, LLC, which does business under the name Mindpath Health, filed notice of a data breach with the Massachusetts Attorney General after discovering that an unauthorized party was able to gain access to two employee email accounts containing confidential patient information. Based on the company’s official filing, the incident resulted in an unauthorized party gaining access to consumers’ names, addresses, Social Security numbers, dates of birth, medical diagnosis and treatment information, health insurance information, and prescription information. After confirming that consumer data was leaked, Mindpath began sending out data breach notification letters to all individuals who were impacted by the recent data security incident.

If you are a current or former patient of Mindpath, the company required you to provide your personal information prior to attending your first appointment. Of course, you had no reason to doubt the company’s ability to keep that information safe. Why would you? However, in the wake of the Mindpath data breach, it is possible that the company failed to implement the necessary protections to keep patient data secure. As we’ve discussed in previous posts, healthcare providers are frequently the target of cyberattacks, primarily because they possess very sensitive information that hackers can easily use to commit fraud and identity theft. However, there are steps you can take to reduce the risks that come along with a data breach. And, if the ongoing investigation into the breach reveals that Mindpath was negligent in how it stored your information, you may be able to pursue a data breach lawsuit against the company.

What We Know So Far About the Mindpath Health Breach

The available information regarding the Mindpath Health breach comes from the company’s filing with the Massachusetts Office of Consumer Affairs and Business Regulation. Mindpath also posted a “Notification of Data Security Incident” on its website.

According to these sources, on July 5, 2022, Mindpath was conducting a regular audit of its email system when the company discovered suspicious activity relating to several email accounts. In response, Mindpath secured its email system and began working with a third-party data security firm to investigate the incident and determine what, if any, patient information was compromised.

The Mindpath investigation confirmed that two employee email accounts were subject to unauthorized access on different dates. One of the accounts was accessed in March 2022, and the other in June 2022. The investigation also revealed that the compromised email accounts contained information belonging to certain Mindpath patients.

Upon discovering that sensitive patient data was available to an unauthorized party, Mindpath Health began to review the affected files to determine what information was compromised and which consumers were impacted. While the breached information varies depending on the individual, it may include your name, address, Social Security number, date of birth, medical diagnosis and treatment information, health insurance information, and prescription information.

On January 10, 2023, Mindpath Health sent out data breach letters to all individuals whose information was compromised as a result of the recent data security incident.

More Information About Mindpath Health

Mindpath Health is a behavioral health provider based in San Rafael, California. Mindpath offers both psychology and psychiatry services, as well as related services, including Transcranial Magnetic Stimulation (TMS). The company offers same-day telehealth appointments for individuals in California and North Carolina and traditional appointments for residents of Arizona, Florida, Minnesota, Ohio, South Carolina and Texas. Mindpath is the business name of Community Psychiatry Management, LLC. Mindpath Health employs more than 500 people and generates approximately $73 million in annual revenue.

DISCLAIMER: Because of the generality of this update, the information provided herein may not be applicable in all situations and should not be acted upon without specific legal advice based on particular situations.

© Console and Associates, P.C. | Attorney Advertising

Written by:

Console and Associates, P.C.
Contact
more
less

PUBLISH YOUR CONTENT ON JD SUPRA NOW

  • Increased visibility
  • Actionable analytics
  • Ongoing guidance

Console and Associates, P.C. on:

Reporters on Deadline

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
Custom Email Digest
- hide
- hide