4 min readfrom Washington State University | Washington State University

Third-party data breach impacts users of WSU Pullman pharmacy

Our take

Heads up, Cougs! A recent cybersecurity incident involving Change Healthcare has affected healthcare providers across the country, including our WSU Pullman pharmacy. If you’ve used their services, your personal information might be at risk. It’s a reminder to stay aware and proactive about our data security. For more details on what this means for you and how to protect yourself, check out [WSU’s website](https://www.wsu.edu) for updates. Let’s stay informed and look out for each other!

The recent cybersecurity breach affecting Change Healthcare, a third-party service provider linked to various healthcare systems, is more than just a headline; it’s a stark reminder of the vulnerabilities inherent in our digital world. As reported, the incident has compromised personal information for a significant portion of the American public, including users at Washington State University’s Pullman pharmacy. This incident brings to light critical issues surrounding data security, privacy, and the responsibility institutions have to protect their communities. In a landscape where technology and healthcare are increasingly intertwined, incidents like this can shake the trust that patients place in their providers and institutions.

The implications of this breach are particularly concerning for students and staff at WSU. Many of us are already juggling a multitude of challenges: classes, jobs, and social life. The last thing we need is the anxiety of wondering whether our personal information is secure. This incident emphasizes the need for educational institutions to prioritize cybersecurity measures actively. As we've seen with other recent cases, such as the court ruling that reinstated a professor at Texas State for discussing sensitive topics or the ongoing discussions around student rights in Kentucky, universities must navigate complex social landscapes while also safeguarding their communities' personal data.

This breach also raises important questions about the use of third-party applications in healthcare. While these systems streamline processes like health insurance claims, they can also create single points of failure that put countless individuals at risk. The reliance on such services means that when one entity is compromised, the fallout can be widespread. Students and community members should be aware of how these systems work and advocate for transparency and accountability from their institutions. The situation is reminiscent of the University of Washington researchers' work deciphering beluga calls to enhance conservation efforts; just as understanding complex systems can lead to better outcomes in conservation, so too can awareness and education about data security lead to stronger protections for our personal information.

As we process this news, it’s essential to remain proactive. Students should take the time to review their own privacy settings and understand the protections their institution offers. WSU and similar institutions must bolster their cybersecurity measures, ensuring that students feel secure in their healthcare interactions. It’s a collective responsibility that goes beyond just IT departments; every member of the university community has a role to play.

Looking ahead, we should be asking ourselves: how can we better prepare for future incidents? What steps can we take to ensure that our personal data is safeguarded in an increasingly digital world? As we navigate the complexities of modern education and healthcare, our vigilance and proactive engagement will be critical in creating a secure environment for all Cougs. Let’s remember that while we balance ambition with community, our safety and privacy should always come first.

According to national news media reports, healthcare providers nationwide have been impacted by a cybersecurity incident related to a common application used to submit and process health insurance claims. The third-party service provider, Change Healthcare, has indicated that a substantial portion of the American public could have had their personal information compromised in this attack.

What happened?

On February 21, 2024, Change Healthcare became aware that its computer system had been compromised by a cybercriminal.

On June 20, 2024, Washington State University (WSU) received notification from Change Healthcare that personally identifiable health information for some WSU Pullman students and others who used the Cougar Health Services pharmacy may have been included in the breach. Change Healthcare did not provide names of individuals who may have had their information compromised.

What information has been exposed?

Change Healthcare cannot confirm exactly what data was affected for each impacted individual, but the data that may have been accessed by unauthorized parties included contact information (such as first and last name, address, date of birth, phone number, and email) and one or more of the following:

  • Health insurance information (such as primary, secondary or other health plans/policies, insurance companies, member/group ID numbers, and Medicaid-Medicare-government payor ID numbers),
  • Health information (such as medical record numbers, providers, diagnoses, medicines, test results, images, care and treatment),
  • Billing, claims and payment information (such as claim numbers, account numbers, billing codes, payment cards, financial and banking information, payments made, and balance due), and/or
  • Other personal information such as Social Security numbers, driver’s licenses or state ID numbers, or passport numbers.

What steps can I take to protect myself?

While Change Healthcare is still investigating whose personal information may have been involved, and WSU is waiting to obtain a list of affected individuals from Change Healthcare, there are steps you can take to protect yourself:

  • If you believe your information may have been impacted by this incident, you can enroll in two years of complimentary credit monitoring and identity protection services. Change Healthcare is paying for the cost of these services for two years.
  • Be on the lookout and regularly monitor the explanation of benefits statements received from your health plan and statements from healthcare providers, as well as bank and credit card statements, credit reports, and tax returns, to check for any unfamiliar activity.
  • If you notice any healthcare services you did not receive listed on an explanation of benefits statement, you should contact your health plan or doctor.
  • If you notice any suspicious activity on bank or credit card statements or on tax returns, you should immediately contact your financial institution and/or credit card company or relevant agency.
  • If you believe you are the victim of a crime, you can contact local law enforcement authorities and file a police report.

You may have additional rights available to you depending on the state you live in.

Visit the Change Healthcare Notice of Data Breach website for more information and details on resources the company is making available to impacted individuals.

For more information

If you have questions for the WSU Cougar Health Services Pharmacy regarding this incident, please contact Joseph Santos, Quality Assurance and Compliance Coordinator for Cougar Health Services at incident.notification@wsu.edu or at (833) 401-2121.

The link to the Change Healthcare Notice of Data Breach website above provides contact information for Change Healthcare.

Moving forward

Washington State University will continue to update this webpage as new information becomes available from Change Healthcare.

Read on the original site

Open the publisher's page for the full experience

View original article