May 2, 2023
Methodist Family Health (“MFH”) experienced a data breach on March 4, 2023, that was first detected on March 6, 2023. After a thorough investigation, we have determined that a variety of documents a business associate uses to provide pharmacy services containing protected health information (“PHI”) were accessed and copied without authorization. The types of information involved in the breach included, in some instances, full name, date of birth, date of admission or treatment, home address, account number, diagnosis, service charges, or medication information. Through our internal investigation and our consultations with and examinations by outside cybersecurity and privacy specialists, we have determined that soon after the breach was detected, unauthorized access was terminated, and additional measures were taken to strengthen privacy and data security. We continuously review and update our internal processes and procedures and will implement suggested guidance. Our additional cybersecurity measures are specifically designed to ensure the safety and security of patients’ PHI. We take safeguarding our patients’ PHI very seriously and will continue to strive to fully protect all privacy interests of our clientele.
We understand that protecting yourself from any potential harm due to this breach is of vital importance to you, as it is to us. As a precautionary measure, we recommend that you remain vigilant by reviewing your account statements and credit reports closely. If you detect any suspicious activity on an account, you should promptly notify the financial institution or company with which the account is maintained. You also should promptly report any fraudulent activity or any suspected incidence of identity theft to proper law enforcement authorities, your state attorney general, and/or the Federal Trade Commission.
To file a complaint with the FTC, go to www.ftc.gov/idtheft or call 1-877-ID-THEFT (877-438-4338). Complaints filed with the FTC will be added to the FTC’s Identity Theft Data Clearinghouse, which is a database made available to law enforcement agencies.
You may also obtain a free copy of your credit report from each of the three major credit reporting agencies once every 12 months by visiting https://www.annualcreditreport.com, calling toll-free (877) 322-8228, or by completing an Annual Credit Report Request Form and mailing it to Annual Credit Report Request Service, P.O. Box 105281, Atlanta, GA 30348. You can print a copy of the request form at:
https://www.annualcreditreport.com/cra/requestformfinal.pdf.
You can also elect to purchase a copy of your credit report by contacting one of the three national credit reporting agencies. Contact information for the three national credit reporting agencies for the purpose of requesting a copy of your credit report or for general inquiries is provided below:
Equifax
(800) 685-1111
www.equifax.com
P.O. Box 740241
Atlanta, GA 30374
Experian
(888) 397-3742
www.experian.com
535 Anton Blvd., Suite 100
Costa Mesa, CA 92626
TransUnion
(800) 916-8800
www.transunion.com
P.O. Box 6790
Fullerton, CA 92834
Our representatives are available to answer any questions or concerns that may arise. For further information and assistance, we have a toll-free number available: 1-866-813-3388—ask for the Chief Privacy Officer.
Notice of Privacy Practices (NPP) describes uses and disclosures of a patients “Protected Health Information” (PHI) regarding treatment, payment or healthcare operations and for other purposes permitted or required by law and a patient’s right to access and control of PHI including demographics: identity of patient; past, present or future physical or mental health or condition and/or related healthcare services.
Methodist Children’s Home (MCH), Methodist Behavioral Hospital (MBH), Methodist Counseling Clinic (MCC), and Arkansas C.A.R.E.S. will abide by the terms of the NPP and at any time may change the terms of notice that will be effective for all PHI maintained at time of change. A revised NPP will be provided on request by mail or email.
This Notice describes the practices of our programs associated with the Methodist Children’s Home (MCH), the Methodist Behavioral Hospital (MBH), Methodist Counseling Clinic (MCC) and Arkansas C.A.R.E.S may share medical information for treatment, payment or operations as described in this notice. Any healthcare professional associated with the Methodist Family Health system — employees, staff and other personnel authorized to enter information into the patient’s file or record — will follow the terms of the NPP.
Uses and Disclosures of Protected Health Information Based upon Written Consent:
If you believe your privacy rights have been violated, please contact the Methodist Children’s Home, Arkansas C.A.R.E.S., Methodist Counseling Clinic and Methodist Behavioral Hospital and/or the Office for Civil Rights, Region VI (U.S. Department of Health & Human Services):
Office for Civil Rights
U.S. Department of HHS
1301 Young Street, Suite 1169
Dallas, TX 75202
(214) 767-4056; (214) 767-8940
(214) 767-0432 Fax
You may contact our Chief Privacy Officer or Chief Security Officer for further information about the complaint process.
Jennifer Horner, RHIA
Chief Privacy Officer
Methodist Behavioral Hospital
1601 Murphy Drive
Maumelle, AR 72113
(501) 803-3388 Ext. 8129
Toll free 866-813-3388
jhorner@methodistfamily.org
Keven Burress
Chief Security Officer
Methodist Family Health
1600 Aldersgate Road, Suite 200
Little Rock, AR 72205
(501) 661-0720, Ext. 7312
Toll free 800-756-3709
kburress@methodistfamily.org
To receive a full copy of the notice you may request it from Methodist Family Health via paper or electronic version.
This notice was published and effective on April 14, 2003.
Updated March 2012.
Visit Request Medical Records to obtain yours.