athenahealth Data Incident Exposes Sensitive Patient Data

William C. Gendron
Editor in Chief
Published
November 19, 2024
Updated
February 12, 2025
athenahealth Data Incident Exposes Sensitive Patient Data
athenahealth
Types of INFORMATION affected
  • Names
    Names
  • Social security numbers
    Social Security Numbers
  • Dates of birth
    Dates of Birth
  • Addresses
    Addresses
  • Government IDs
    Government IDs
  • Medical Information
    Medical Info
  • Financial Info
    Financial Info

Affected by the

athenahealth

data breach?

Join the Lawsuit

It's free to join. 

Banner advertisement for ExpressVPN to take control of your online security

Claim Depot may receieve a commission from links on this page

On September 16, 2024, athenahealth, Inc., a well-known electronic health record and revenue cycle management vendor, experienced a data breach that potentially affected a significant number of individuals.

The breach was discovered when an insurance provider notified athenahealth that certain patient insurance eligibility queries and responses—collectively known as Eligibility Transaction Files—were inadvertently made publicly accessible on the internet.

This exposure was due to a one-time, manual error in configuring the repository where these files were stored. The files were believed to have been uploaded on or after April 3, 2024.

The information exposed in this incident included:

  • Social security numbers
  • Medical records

athenahealth's Response

Upon learning of the breach, athenahealth took immediate action to remove the exposed files from the public repository. The company launched an investigation to understand how the breach occurred and identified the root cause as a configuration error. In response, athenahealth is evaluating additional safeguards, workflows, and process requirements to prevent similar incidents in the future.

They are also providing training and education to the individual responsible for the error.

To support affected individuals, athenahealth is offering complimentary access to Experian IdentityWorks for 12 to 24 months, depending on the individual's circumstances. This service includes identity restoration support and fraud detection tools.

Steps for Affected Individuals

If you believe you may have been affected by this data breach, there are several steps you can take to protect yourself:

  1. Enroll in Identity Protection: Take advantage of the complimentary Experian IdentityWorks membership offered by athenahealth. This service provides credit monitoring, internet surveillance, and identity restoration support.
  2. Monitor Your Accounts: Regularly check your credit reports and financial statements for any unauthorized activity. You are entitled to one free credit report annually from each of the three major credit reporting agencies.
  3. Consider a Fraud Alert or Credit Freeze: You may place a fraud alert on your credit file, which instructs creditors to take extra steps to verify your identity before opening new accounts. Alternatively, a credit freeze can prevent new credit from being opened in your name without your consent.
  4. Stay Informed: Keep an eye on any communications from athenahealth regarding updates or further protective measures.

For more detailed information, you can view the disclosure on the Massachusetts Attorney General's website.

Protect Your Data

A breach notice means your personal details could be circulating far beyond the organization involved. One practical step is continuous monitoring: services such as Identity Defender (included with an ExpressVPN subscription) can automatically check dark-web markets, flag new credit-file activity, and request removal of your information from data-broker sites.

This kind of “early-warning system” can’t undo a breach, but it can help you spot misuse quickly and limit further exposure. ExpressVPN is offering 61% off, risk-free for 30 days, with ID Theft Insurance included and no extra cost for those who sign up for one or two years.

Notice Letter

This browser does not support inline PDFs. Please download the PDF to view it: Download PDF

CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image