<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:g-custom="http://base.google.com/cns/1.0" version="2.0">
  <channel>
    <title>700137582</title>
    <link>http://www.downriverpediatrics.com</link>
    <description />
    <atom:link href="http://www.downriverpediatrics.com/feed/rss2" type="application/rss+xml" rel="self" />
    <item>
      <title>Notice of Data Security Incident</title>
      <link>http://www.downriverpediatrics.com/notice-of-data-security-incident</link>
      <description />
      <content:encoded>&lt;div data-rss-type="text"&gt;&#xD;
  &lt;h3&gt;&#xD;
    &lt;span&gt;&#xD;
      
          Notice of Data Security Incident
         &#xD;
    &lt;/span&gt;&#xD;
  &lt;/h3&gt;&#xD;
&lt;/div&gt;&#xD;
&lt;div data-rss-type="text"&gt;&#xD;
  &lt;p&gt;&#xD;
    &lt;span&gt;&#xD;
      &lt;span&gt;&#xD;
        
           On October 8, 2026, Downriver Pediatric Associates PC (“Downriver”) began mailing notification letters to certain patients whose information was involved in a data security incident at Technical Solutions Group LLC (“TSG”), a company that was previously used by Downriver to host its electronic health records (“EHR”) system.
          &#xD;
      &lt;/span&gt;&#xD;
    &lt;/span&gt;&#xD;
  &lt;/p&gt;&#xD;
  &lt;p&gt;&#xD;
    &lt;span&gt;&#xD;
      
           
         &#xD;
    &lt;/span&gt;&#xD;
  &lt;/p&gt;&#xD;
  &lt;p&gt;&#xD;
    &lt;span&gt;&#xD;
      &lt;span&gt;&#xD;
        
           According to TSG, in June 2026, it experienced a cyberattack that impacted information related to many of its customers, including Downriver. During this cyberattack, the bad actors encrypted information on TSG’s systems and left a note claiming to have exfiltrated data held by TSG. TSG notified Downriver about the incident and explained that they initiated an investigation to determine the nature and scope of the incident.
          &#xD;
      &lt;/span&gt;&#xD;
    &lt;/span&gt;&#xD;
  &lt;/p&gt;&#xD;
  &lt;p&gt;&#xD;
    &lt;span&gt;&#xD;
      
           
         &#xD;
    &lt;/span&gt;&#xD;
  &lt;/p&gt;&#xD;
  &lt;p&gt;&#xD;
    &lt;span&gt;&#xD;
      &lt;span&gt;&#xD;
        
           On September 16, 2026, TSG notified Downriver that they were unable to recover the encrypted data that it hosted on behalf of Downriver. Additionally, TSG was unable to determine what Downriver information, if any, was accessed or taken by the bad actors. Although we do not know for certain if patients’ information was accessed or taken by a bad actor, out of an abundance of caution, Downriver is notifying all patients whose information was maintained in the EHR system hosted by TSG. Additionally, due to TSG’s incident and the inability of TSG to recover the encrypted data, records maintained regarding patients’ treatment that were created between June 2025 and June 2026 may no longer be available to review or access.
          &#xD;
      &lt;/span&gt;&#xD;
    &lt;/span&gt;&#xD;
  &lt;/p&gt;&#xD;
  &lt;p&gt;&#xD;
    &lt;span&gt;&#xD;
      
           
         &#xD;
    &lt;/span&gt;&#xD;
  &lt;/p&gt;&#xD;
  &lt;p&gt;&#xD;
    &lt;span&gt;&#xD;
      
          It is important to note that the incident involved TSG’s systems, not Downriver’s owned or managed systems. In other words, this incident did not involve access to, or a compromise of, any Downriver owned, operated or administered systems. 
         &#xD;
    &lt;/span&gt;&#xD;
  &lt;/p&gt;&#xD;
  &lt;p&gt;&#xD;
    &lt;strong&gt;&#xD;
      
           
         &#xD;
    &lt;/strong&gt;&#xD;
  &lt;/p&gt;&#xD;
  &lt;p&gt;&#xD;
    &lt;span&gt;&#xD;
      
          The potentially involved files contained information that varied by patient but could have included patients’ names and one or more of the following: Social Security numbers, driver’s license numbers, dates of birth, treating physician, dates of service, medication information, insurance information and treatment and/or diagnostic information.
         &#xD;
    &lt;/span&gt;&#xD;
  &lt;/p&gt;&#xD;
  &lt;p&gt;&#xD;
    &lt;span&gt;&#xD;
      
           
         &#xD;
    &lt;/span&gt;&#xD;
  &lt;/p&gt;&#xD;
  &lt;p&gt;&#xD;
    &lt;span&gt;&#xD;
      
          We recommend that patients review the statements they receive from their healthcare providers and health insurance plan. If they see any services that were not received, patients should contact their provider or health plan immediately.
         &#xD;
    &lt;/span&gt;&#xD;
  &lt;/p&gt;&#xD;
  &lt;p&gt;&#xD;
    &lt;span&gt;&#xD;
      
           
         &#xD;
    &lt;/span&gt;&#xD;
  &lt;/p&gt;&#xD;
  &lt;p&gt;&#xD;
    &lt;span&gt;&#xD;
      &lt;span&gt;&#xD;
        
           While the incident did not impact Downriver’s own network, we are notifying patients of this incident and sharing the steps that we are taking in response. We are no longer using TSG to host our EHR. We remain committed to upholding high standards of custodianship of information held by our third-party vendors.
          &#xD;
      &lt;/span&gt;&#xD;
    &lt;/span&gt;&#xD;
  &lt;/p&gt;&#xD;
  &lt;p&gt;&#xD;
    &lt;span&gt;&#xD;
      
           
         &#xD;
    &lt;/span&gt;&#xD;
  &lt;/p&gt;&#xD;
  &lt;p&gt;&#xD;
    &lt;span&gt;&#xD;
      
          We have set up a dedicated incident response line to answer patient questions. Patients can call 833-918-9468 Monday – Friday, 9 am – 9 pm Eastern Time, except for major U.S. holidays. 
         &#xD;
    &lt;/span&gt;&#xD;
  &lt;/p&gt;&#xD;
&lt;/div&gt;</content:encoded>
      <pubDate>Thu, 08 Oct 2026 19:17:02 GMT</pubDate>
      <guid>http://www.downriverpediatrics.com/notice-of-data-security-incident</guid>
      <g-custom:tags type="string" />
    </item>
  </channel>
</rss>
