ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Health data of 4,000 Garrison Women’s Health patients exposed in third-party security incident

New Hampshire-based Garrison Women’s Health has suffered a significant data breach that has compromised the sensitive personal information of more than 4,000 patients.In a recent notice on its website, the healthcare provider said that the data breach was a result of a security incident at Global Network Systems, a third-party technology service provider. GNS manages the IT infrastructure and applications for Garrison Women’s Health, including hosting a server for electronic medical records.According to Garrison, Global suffered a network outage on December 12, 2022. “Through its investigation, Global learned that certain information in the Global-hosted environment regarding patient care services provided at GWH between April 29, 2022, and December 12, 2022, was subject to unauthorised third-party activity that rendered the information inaccessible and for which there was not a backup available,” the notice read.Global took the necessary steps to explore alternative data backup sources and restoration methods. GWH’s access to certain information, such as radiology and ultrasound applications, was eventually restored and completed.“During January 2-9, 2023, the GWH electronic medical record system was restored through backups which included earlier data through April 28, 2022.“Although the review is still ongoing, we are reaching out to individuals who had an appointment or visit at GWH during April 29, 2022-December 12, 2022 to let you know of the unavailability of this information and the resources available to you. As a result of this incident, some of your information regarding services entered into your electronic medical record at GWH during that time period will not be fully restored,” GWH explained.Based on its internal review, GWH confirmed that certain sensitive personal records of 4,158 patients were impacted in the security incident. Compromised information included medical and treatment information like visits, procedures, tests, medical record number, diagnosis, medical history, genetic information, and various types of assessments; imaging and results, coding, claims, insurance, and payment information for services provided at GWH during that timeframe, and scheduling information for upcoming appointments.“The outage occurred on Global’s systems and affected information stored in Global’s environment. The outage did not impact Wentworth-Douglass Hospital’s network or any other Wentworth-Douglass Hospital core clinical system,” GWH added.After being notified about the security incident at Global, GWN launched an internal investigation and took steps to mitigate and remediate the impact of the cyber attack, including reviewing the status of data recovery and enhancing security processes in place to minimise the risk of similar incidents in the future.Garrison Women’s Health has urged all affected individuals to carefully review statements sent by healthcare providers and their insurance companies to make sure that all account activity regarding services provided at GWH from April 29, 2022- December 12, 2022, is complete and accurate.
 

Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543