HomeSecurityTimberline Billing Service LLC: Data stolen in ransomware attack

Timberline Billing Service LLC: Data stolen in ransomware attack

A medical billing company in Iowa, USA, is beefing up its cybersecurity after being hit by ransomware. A hacker, whose identity remains unknown, infected Timberline Billing Service LLC with malware between February 12 and March 4, 2020. After gaining access to the company’s network, the attacker encrypted files and stole data and information.

Timberline said it cannot currently determine exactly what data was stolen. However, after reviewing files that the attacker could have accessed, the company determined that current and former students at schools it serves may have been affected by the ransomware attack.

Timberline Billing Service LLC: Data stolen in ransomware attack

Timberline, based in Des Moines, serves about 190 schools in Iowa. The security incident was reported to the Department of Health and Human Services’ Office of Civil Rights as a data breach that affected about 120,000 people.
The data accessed by the attacker may have included student names, dates of birth, Social Security numbers, Medicaid identification numbers and billing information.

Iowa school district leaders said the ransomware attack did not involve the attacker accessing the district's internal systems or student records. Timberline began contacting students in Iowa on Oct. 20 to notify them of a " privacy incident " that may have exposed some of their personal information.

Timberline Billing Service LLC: Data stolen in ransomware attack

While the company said it has not yet discovered any misuse of student data, it is providing all students affected by the incident with free credit monitoring and identity protection services. In addition, the company has set up a toll-free call center to provide support to students and their parents.

Company representatives said they have taken the necessary steps to improve their security systems to prevent a similar attack in the future. These measures include firewall and server, migrating school and student data to a cloud service, resetting all user passwords, and frequently changing passwords.

As Infosecurity Magazine reports, other Iowa healthcare organizations have been affected by malware this year, including UnityPoint Health and the Iowa State Foundation, which suffered a data breach as a result of the Blackbaud in May that affected numerous organizations around the world.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS