That sketchy letter from your hospital might be real

Rochester patients got a real breach notice with the wrong hospital name on it. Many threw it away.

Share
A woman sits cross-legged on a couch, reading through paper statements with a laptop open on her lap.

In June, about 18,600 patients of Rochester Regional Health in New York got letters saying their health information had been exposed in a data breach. The letters came from a company most of them had never heard of. They named a hospital that does not exist, "Rochester Regional Medical Center." Plenty of people looked at all that and did what we've all been trained to do. They threw it in the trash.

The letters were real.

The breach happened at a company called Xsolis, an AI vendor hospitals use behind the scenes for insurance and care paperwork. In January, someone phished their way into Xsolis systems and got files on about 1.4 million patients across the country. Mayo Clinic, UW Medicine, and Legacy Health patients are all on the list. The stolen data included names, birth dates, Social Security numbers, insurance details, and medical treatment information.

Rochester Regional stopped working with Xsolis back in 2021. The company was still holding five-year-old patient records when it got breached.

You never picked Xsolis. Hospitals are allowed to hand patient data to vendors like this without asking you, and the vendor never has to tell you it has your file. You usually find out the way Rochester patients did: a letter, after something goes wrong.

For the people who tossed that letter, the reality is they were not being careless. Wrong hospital name, unfamiliar sender, an alarming claim about your data. That's the scam checklist, and they ran it correctly. It's the same checklist that catches phishing emails.

The instinct is good. It just has a blind spot. Real companies produce letters this sketchy all the time, because they outsource breach notifications to vendors you've never heard of, and sometimes those vendors can't even get the hospital's name right.

So when one of these shows up, don't trust the letter, and don't trash it. Check it yourself.

A few steps you can take:

  • Find the number on your own. Look up the hospital or company on its official website, or grab it off a bill you already have. Call and ask if the letter is real. A scammer can fake a letter, but they can't make your real hospital vouch for it.
  • Ignore every phone number and link printed on the letter. If the letter is fake, that number rings the scammer. Verify first. Once you know it's real, the letter's contact info is safe to use.
  • If it's real, take the free help. Breach letters usually include free credit or identity monitoring with an activation code. Use it.
  • If your Social Security number was in the pile, freeze your credit. It's free, and it's a lock instead of an alarm. We have a guide.

One bit of caution. This does not mean investigating every strange letter that hits your mailbox. A prize notice from a sweepstakes you didn't enter is still garbage. The verification check is for mail that claims to be from a place you actually deal with: your hospital, your bank, your insurer. If it's really them, they won't have any problem confirming they sent it.

Sources

[ Free every Tuesday, plus the Cache ]
Tech news without having to be tech savvy.
Subscribe ×