Notice of Data Security Incident
Summit Medical Group, PLLC ("Summit") is committed to protecting the privacy and security of our patients' information. We recently responded to and addressed a data security incident that involved patient information. On January 12, 2024, we began mailing letters about the incident to the patients whose information may have been involved.
On November 29, 2023, we learned that some patient information was involved in an email phishing incident targeting one of our employees. The incident occurred on November 29, 2023, when our employee was tricked into believing they were responding to a request for information from another employee, but they were conversing with an unknown individual. In response, we took immediate steps to prevent further disclosure and initiated an investigation of the incident.
Through our investigation, we determined that a spreadsheet containing information related to patient billing was inadvertently disclosed to the unauthorized individual via email. Our analysis of the spreadsheet determined that it contained certain patient information. The information varies by patient but may include some or all of the following: patient names, provider names, patient identification numbers, dates of birth, facilities of treatment, dates of service, cost of services and/or insurance carrier names.
We deeply regret any inconvenience or concern this may cause and take this matter seriously. We encourage patients whose information may have been involved to review the statements they receive from their providers and health insurers. If the statements identify services that were not received, the patient should contact the insurer that issued the statement immediately.
To help prevent something like this from happening again, we have implemented additional safeguards and technical security measures to further protect and monitor our email system and administered additional training to the employee involved in the incident.
We have established a dedicated toll-free call center for individuals with questions about the incident. The call center can be reached at (866) 992-0887. Monday to Friday, between 8:00 a.m. - 5:30 p.m., Central Time, except for major U.S. holidays.