U.S. nonprofit healthcare giant Maternal & Family Health Services has confirmed hackers accessed sensitive patient, financial and medical information months earlier.
In an advisory published on its website on Thursday, MFHS said a “sophisticated ransomware incident” exposed the sensitive information of current and former patients, employees and vendors. This information included names, addresses, dates of birth, Social Security numbers, driver’s license numbers, financial account data and payment card information, usernames and passwords, and medical and health insurance information.
The organization, which serves more than 90,000 individuals across Pennsylvania, said it was made aware of the incident on April 4, 2022 but may have been initially compromised as far back as August 21, 2021, citing an investigation conducted by an unnamed forensic incident response firm.
It then took MFHS a further nine months to publicly disclose the incident.
When reached for comment, Patrick McGloin, a partner at Gaffney Bennett, a public relations firm representing MFHS, declined to answer our questions beyond providing a boilerplate statement. It’s not yet known why MFHS didn’t publicly disclose the cyberattack sooner, who was behind the attack, or whether MFHS paid a ransom demand.
Healthcare organizations are a frequent target for ransomware attacks, and at least 25 healthcare providers operating 290 hospitals were hit by ransomware in 2022, according to recent data from Emsisoft. This includes Chicago-based medical giant CommonSpirit Health, which confirmed that an October ransomware attack exposed the personal data of more than 620,000 patients.
In the past decade, Apple has positioned itself as a privacy-first company. It has butted heads with law enforcement for encrypting people’s phones, messages, and FaceTime calls, and battled Facebook over its creepy ad-tracking practices. But Apple’s business model is also shifting. For years, Cupertino has made its money by selling expensive hardware—iPhones, iPads, and Macs. However, […]
The FBI accused two groups of North Korean government hackers of carrying out last year’s heist of $100 million in crypto stolen from a company that allows users to transfer cryptocurrency from one blockchain to another. On Monday, the FBI announced that the Lazarus Group and APT38 — two groups linked to the North Korean government by both cybersecurity […]
ate on Friday, Twitter announced a new policy that will remove text message two-factor authentication (2FA) from any account that won’t pay for it. In a blog post, Twitter said that it will only allow accounts that subscribe to its premium Twitter Blue feature to use text message-based 2FA. Twitter users that don’t switch to a different […]
Leave a Reply