Skip to content

Condition: Post with Page_List

Listen
Search
Please enter at least 3 characters.

Latest Stories

Windsong partner pays for not protecting data

US Radiology will pay $450,000 for failing to protect its patients' personal and health care data

Letitia James
Getty Images

Buffalo, N.Y. (WBEN) - New York State Attorney General Letitia James says there's an agreement with a partner of Windsong Radiology for failing to protect patient data. James says her office's investigation found US Radiology did not prioritize upgrading its hardware, leading to a ransomware attack.

US Radiology partners with and acts as a service provider for facilities throughout the country, including the Windsong Radiology Group, which has six offices across Western New York. James says her office's investigation found US Radiology did not prioritize upgrading its hardware, which left its network exposed to a known vulnerability, leading to a ransomware attack that affected more than 92,000 New Yorkers.


"When patients visit a medical facility, they deserve confidence in knowing that their personal information will not be compromised when they are receiving care," says James. "US Radiology failed to protect New Yorkers' data and was vulnerable to attack because of outdated equipment. In the face of increasing cyberattacks and more sophisticated scams to steal private data, I urge all companies to make necessary upgrades and security fixes to their computer hardware and systems. My office will continue to ensure companies do not neglect their legal responsibilities to protect New Yorkers' private information."

US Radiology is a large private radiology group that provides managed services for many of its partner companies, including the Windsong Radiology Group, which has six facilities across Western New York. US Radiology failed to quickly update its firewall to protect itself and its partner companies' networks from cyber threats. In December 2021, a threat actor gained access to US Radiology's network and stole the personal and health information of 198,260 patients, including the data of 92,540 New Yorkers. The stolen information included names, dates of birth, social security numbers, driver's license numbers, passport numbers, patient IDs, dates of service, provider names, types of radiology exams, diagnoses, and/or health insurance ID numbers.

The OAG's investigation concluded that US Radiology had failed to adopt reasonable data security practices to protect patients' personal information by failing to protect its firewall from a known vulnerability.

As part of today's agreement, US Radiology has agreed to pay $450,000 in penalties and adopt additional data security practices to strengthen its network, including:

- Enhancing and maintaining its existing written information security program that ensures the security, integrity, and confidentiality of patients' personal information.
- Creating and implementing an IT asset management program for identifying, reporting, and prioritizing replacement or updates of IT assets.
- Encrypting patients' personal information that it collects, stores, transmits, and/or maintains.
- Developing and maintaining a penetration testing program that regularly identifies and remediates any and all security vulnerabilities found during testing.
- Implementing policies and procedures that seek to permanently delete their patients' personal data when there is no reasonable business purpose to retain it.

US Radiology will pay $450,000 for failing to protect its patients' personal and health care data