Phoenix-based Banner Health disclosed in August 2016 a cyberattack that exposed the electronic protected health information of approximately 2.81 million patients, members, employees, and providers, described by HIPAA Journal as the largest healthcare breach of 2016. Attackers first gained access on June 17, 2016 by compromising payment-card processing systems on the cafeteria point-of-sale network at certain Banner Health facilities, then pivoted laterally into servers holding clinical data; the intrusion was discovered on July 7, 2016 and contained on July 13, 2016. Exposed information included patient names, dates of birth, addresses, physicians' names, dates of service, claims information, possible health insurance information and Social Security numbers, along with payment-card data from cafeteria transactions. On February 2, 2023 Banner Health agreed to pay $1.25 million to the HHS Office for Civil Rights and adopt a two-year corrective action plan to resolve potential HIPAA Security Rule violations, with OCR citing deficiencies in enterprise risk analysis, system activity review, authentication procedures, and audit controls for hardware and software handling ePHI. A consolidated consumer class action was separately settled in 2020.
Blog
Insights on AI security and development
Learn how to protect your code, understand AI risks, and build secure workflows with expert insights.

