Accessibility links
  • Skip to main content
News Icon NEWS FILTER
All News Security Education Videos Scams & Phishing Your Security Mobile Security Identity Theft Corporate Security
Search Icon SEARCH
 

Email Icon SUBSCRIBE TO WEEKLY NEWSLETTER
One Third of US Might Be Impacted By Massive Healthcare Breach
Facebook   X   LinkedIn   Email

One Third of US Might Be Impacted By Massive Healthcare Breach

June 3, 2024

It’s called PHI, or protected health information, and a recent ransomware attack put that very valuable data at high risk of public exposure. Change Healthcare, a subsidiary of insurance titan UnitedHealth Group, was the target of such an attack. The company provides its services to a massive number of hospitals, doctors, and pharmacies across the U.S., involving untold amounts of PHI belonging to roughly half of all Americans.

The Big Deal Steal

The company performs billing and insurance processing for a huge swath of healthcare-related services across the U.S. for an estimated 100+ million Americans. The company reports losing $827 million due to the attack so far, estimating the total damage at more than $1 billion by the time all is accounted for.

Although the company was not quick to inform customers as to exactly what was compromised, there are common elements collected as part of patient PHI. Those valuable nuggets of data include patient name; insurance ID number; physical, email and IP address; birthdate; Social Security number; driver’s license info; payment data; full-face photo; history of physical and/or mental health conditions and treatment.

Although paying a ransom is not advised, a UnitedHealth spokesperson said they paid the ransom demand to a new threat group called RansomHub “to protect patient data from disclosure.” However, they wouldn’t confirm the amount. Rumors are swirling about the price tag being $22 million in bitcoin.

Staying Ransom-Safer

In this case, RansomHub tipped-off Change Healthcare about the attack by posting a smattering of patient PHI and a few of the company’s internal files on the dark web. Keeping systems and software patched and up to date can prevent an unknown flaw like this one from being exploited. Doing regular system backups separate from the system lessens the threat from ransomware and can restore a business back to working order with minimum downtime.

Cyber-educating employees is a big part of staying out of ransomware’s way. In particular, email phishing is a hacker favorite and also the way 91% of all cyberattacks begin. A cyber-smart employee can stop an attack before it starts.

There are numerous organizations that can provide employee education these days. If you’re in charge of your organization’s data, take the time to determine the best option for you. It might be to hire someone to provide it within the organization, but it may also mean finding a company to provide it for you. Just remember to do it on a regular basis, which means more than annually. As we’ve come to know, threats continue to change all the time. One and done just isn’t healthy.

Although Change Healthcare experienced this attack and paid a hefty ransom, by now we know those whose PHI was stolen pay the ultimate price. It’s hard to put a price tag on their valuable PHI being in the hands of ruthless criminals. Yes, the ransom was paid with the hope to get their data back. However, can criminals be trusted? That’s the question and it’s likely the answer is “No.”


From Mega Breach To Main Street — IBM's Cost Of A Data Breach Report 2023

Corporate Security

From Mega Breach To Main Street — IBM's Cost Of A Data Breach Report 2023

Every year, "IBM's Cost of a Data Breach Report", takes an in-depth look at corporate data breaches and the costs incurred when one strikes. Done in partnership with Ponemon Institute, this year's report highlights the stunning financial cost of breaches and other key findings from 2023. The report paints a realistic picture of the security of corporate America, for better or worse, and how AI (artificial intelligence) can help going forward. READ FULL STORY

Carbanak Is Back! Ransomware Group Reinvents Itself

Corporate Security

Carbanak Is Back! Ransomware Group Reinvents Itself

Since the arrest of Carbanak's leader five years ago, the notorious ransomware group is back with a vengeance. The Carbanak ransomware syndicate gained notoriety as a highly effective cybercrime ring targeting financial and banking institutions worldwide. And now, the group has reinvented its method of attacks to reemerge as yet another force to be reckoned with. The group recently shifted their ransomware attacks from financial targets to posing as business software like HubSpot and Xero on compromised websites. READ FULL STORY

Chicago Kids Stricken By Hospital Cyberattack

Corporate Security

Chicago Kids Stricken By Hospital Cyberattack

Yet another hospital felt the pain of a cyberattack affecting patient services. This time, those in the crosshairs are children, the patients at Lurie Children’s Hospital in Chicago. If you're wondering who would attack a children’s hospital, you're not alone. Lurie and the FBI are working to answer that question, and in the meantime, the hospital is struggling to maintain disrupted patient services. On their website, Lurie Children’s Hospital called what they experienced a "cybersecurity matter" without further detail. READ FULL STORY

A PHI Security Epidemic! Healthcare Ransomware Attacks Threat To Patients

Corporate Security

A PHI Security Epidemic! Healthcare Ransomware Attacks Threat To Patients

It’s no secret that in the U.S., cybercriminals placed a bullseye on healthcare systems and the sensitive patient data they hold. A recent study from the Journal of the American Medical Association (JAMA) shows over a five-year period, nearly 42 million patients had their PHI (Protected Health Information) compromised by ransomware attacks. This previously unprecedented number of victims makes PHI security more important now than ever before. READ FULL STORY

2024 HIPAA Rules Promote Data Privacy, Cyber Awareness Training

Identity Theft

2024 HIPAA Rules Promote Data Privacy, Cyber Awareness Training

The 2024 HIPAA requirements for healthcare organizations include a focus on patient data privacy and cyber incident preparedness. It's a welcome change with new compliance that all Americans can be happy about, especially when their PHI (protected health information) is better guarded from cybercrime. Here's a quick summary of a few that may affect you and the organization you work for including bolstering employee awareness, incident response, and more data privacy. READ FULL STORY








Close
Fraud News & Alerts!

Keep up with the latest cyber security news through our weekly Fraud News & Alerts updates. Each week you will receive an email containing the latest cyber security news, tips and breach notifications.



You're all set!

You will receive your first official security update email within the next week.

A welcome email has also just been sent to you. If you do not receive this email within the next few minutes, please check your Junk box or spam filter to confirm our emails are not being blocked.


 
Help  
Enter any word or words you like.        

The email newsletter will arrive from news@stickleyonsecurity.com


Loading
Please wait...