McLaren Port Huron was notified by one of our former vendors and business associates, MCG Health, LLC, of a cybersecurity event its company experienced that may have exposed some of our patients’ protected health information. Numerous health care providers and health plans across the United States have been impacted by this event, including McLaren Port Huron.
According to its website, MCG provides patient care guidelines to the majority of health plans and nearly 2,600 hospitals across the United States. McLaren Port Huron terminated its use of MCG’s services in 2019.
On June 9, 2022, we received written notice from MCG that it had determined on March 25, 2022, that an unauthorized party had obtained personal information that matched data stored on MCG’s systems and that some of our patients’ data may have been involved in the cybersecurity event. This data included some or all of the following data elements: names, Social Security numbers, medical codes, postal addresses, phone numbers, email addresses, dates of birth and gender. MCG asserts that it has taken steps to investigate the nature and scope of the event, including hiring a cybersecurity forensic investigation firm. Additionally, MCG states that it has notified and is coordinating its efforts with the FBI.
Due to the delay in McLaren Port Huron receiving notice of this event, we have not conducted our own investigation to determine the probability of an actual compromise of our patients’ data arising from this event. We are therefore issuing this notice on the presumption that a breach, as defined under HIPAA, has actually occurred.
McLaren Port Huron takes the privacy of its patients and their information very seriously. To this end, we are directing MCG to notify any of our patients who may have been affected so they can take steps to help protect their information. This notification, along with instructions about what to do, will be sent via US mail to each affected patient’s last known address.
MCG is offering identity protection and credit monitoring services for two years at no cost to any impacted patients. They are also managing a call center to answer questions related to the event. The call center may be reached at 1-866-475-7221, Monday – Friday, 9:00AM – 11:00PM; Saturday – Sunday, 11:00AM – 8:00PM (EST). Additional information is available on MCG’s website here: MCG-Website-Notice_90273447_1-6.8.22481312.4-004.pdf
In addition to the free, 2-year identity protection and credit monitoring services being offered by MCG, affected patients are entitled by law to one free credit report annually from each of the three nationwide consumer reporting agencies. Visit www.annualcreditreport.com or call toll-free at 1-877-322-8228. We encourage our patients to remain vigilant by reviewing account statements and monitoring free credit reports.
We apologize that this occurred at one of our former vendors and regret any concern that this issue may have caused. Please contact the MCG call center with any questions regarding this event.