Fallon Ambulance Services (“Fallon”) is issuing a notice about a security incident and the steps Fallon has taken to address it. This notice is drafted in accordance with HIPAA disclosure requirements.
Who We Are: Fallon was a medical transportation company that, in part, responded to patient emergencies in the greater Boston area and provided administrative services for affiliated medical transportation companies. Fallon ceased operations in December 2022 but, to comply with legal obligations, has maintained an archived copy of data previously stored on its computer systems.
What Happened: Fallon ceased operations in December 2022 but, to comply with its legal obligations, maintained an archived copy of data previously stored on its computer systems. On or around April 21, 2023, Fallon detected suspicious activity within its data storage archive. Fallon promptly took steps to secure the archive and initiated a comprehensive investigation into the matter with the assistance of third-party specialists. After an extensive review of the event, Fallon identified that the activity appeared to have occurred from February 17, 2023 through April 22, 2023 and that files were obtained by an unauthorized party that may have contained PHI. Fallon then conducted a comprehensive evaluation of the potentially impacted files to determine the nature of any PHI contained therein and to identify the current mailing address for potentially impacted individuals. This process was completed on or around December 27, 2023.
What Information Was Involved: The information that may have been disclosed as a result of this incident varies depending on the types of information provided to Fallon. In general, disclosed information may have included: name, address, Social Security number, medical information, including COVID-19 testing or vaccination information, and information provided to Fallon in connection with employment or application for employment. At this time, Fallon has no evidence of identity theft or fraud related to any PHI as a result of this incident.
How We Have Responded: While Fallon is no longer operational, it has taken steps to secure the data that may be stored in its archives for compliance with Fallon’s legal obligations. Additionally, to help further protect PHI, Fallon is providing affected individuals with identity protection services, including free credit monitoring services. Fallon has provided identified individuals with instructions on how to take advantage of these services as well as additional guidance on how affected individuals can help protect their information. Finally, Fallon has consulted with federal law enforcement in support of its investigation and response to this matter.
What Affected Individuals Can Do: At this time, Fallon has no evidence of identity theft or fraud related to any of the PHI involved in this matter. If any individual believes that they may have been impacted by this incident, there are steps they can take to help protect their information, including enrolling in Fallon’s complementary identity protection service. As a best practice, Fallon encourages individuals to remain vigilant for suspicious activity and to regularly review their financial statements and credit reports. Fallon mailed notification letters to affected individuals on December 27, 2023. If any individual did not receive a notification letter, but believes they were affected by this incident, that individual may contact us at the phone number provided in the “For More Information” section below. Please note the deadline to enroll in Fallon’s complementary identity protection services is March 27, 2024.
For More Information: Fallon takes its responsibility to safeguard PHI seriously and apologies for any inconvenience or concern this incident may have caused. For further questions, please contact us at 1-888-317-9491. Representatives are available Monday through Friday from 9 am - 9 pm Eastern Time.