HomeSecurityUtah Pathology Services: 112,000 patient data exposed

Utah Pathology Services: 112,000 patient data exposed

A hacker attempted to “redirect” money from Utah Pathology Services after an employee’s email was compromised. Patient data appears to have been leaked.

Utah Pathology Services has notified 112,000 patients that their data may have been affected after an employee's email was breached in June.

A hacker attempted to redirect funds to his account after gaining control of an employee's email. Company representatives said the attempt was unsuccessful and that no patient information was compromised.

Utah Pathology patient data

The account was secured and an investigation was launched with the help of an external security firm. The investigation is ongoing, but it was eventually discovered that some patient information was accessible to the hacker.

The data breached varies by patient, but could include names, contact information, insurance information such as ID numbers, medical and health information such as internal file numbers and diagnostic information, as well as some social security.

Utah Pathology is currently implementing additional security and safety measures to enhance the privacy and security of its network and has reported the incident to authorities.

The Maze ransomware threat actors and the REvil hacking group have again released data they claim was stolen from healthcare providers (two separate incidents).

Screenshots shared with HealthITSecurity.com contained “evidence” of data allegedly stolen by Maze hackers from Houston-based United Memorial Medical Center, along with “evidence” of data allegedly stolen by the REvil group from Valley Health System in West Virginia.

Both centers are currently responding to the COVID -19 pandemic . In July, UMMC reported the highest number of deaths due to COVID-19. At the same time, the health center was dealing with the fallout from a ransomware attack.

The evidence published by Maze shows 5% of the data that the hackers claim to have stolen from UMMC. The zip file published by the hacking group contained general company records, but also some information . The extent of the attack and its impact are currently unclear.

For Valley Health System, screenshots of evidence shared with HealthITSecurity.com include detailed information of patients' medical prescriptions.

Valley Health confirmed that its system was indeed hit by ransomware on August 22. Company said emergency procedures were put in place to ensure patient care would not be disrupted.

Valley Health confirmed that the REvil team leaked some patient data. The incident is being investigated by authorities who were immediately notified.

Many hackers, before infecting systems with ransomware, extract data so they can use it for extortion. The double extortion method was first popularized by the Maze hackers and has since been used by the REvil group, also known as Sodinokibi, DoppelPaymer, and Netwalker.

Reports show that approximately one in 10 ransomware attacks results in data theft and that the healthcare sector is a major target of such attacks.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS