McLaren Health Care (McLaren) is informing nearly 2.2 million people of a data breach that occurred from July to August of this year, exposing sensitive personal information.
See also: Kyocera AVX (KAVX): Ransomware attack led to data breach

McLaren is a nonprofit healthcare organization with annual revenues of $6.6 billion. It includes an extensive network throughout Michigan, which includes 14 hospitals with a total capacity of 2,624 beds and is supported by a team of 490 physicians. The organization has a significant workforce, with 28,000 full-time employees. In addition, it maintains contractual relationships with 113,000 providers, extending its influence into Indiana.
McLaren posted a statement on its website about the breach and also notified the “U.S.” authorities . The organization also notified individuals affected by the incident. Based on the information provided, McLaren Health Care identified a security breach on August 22, 2023. Investigations conducted with the assistance of external cybersecurity experts subsequently revealed that the breach had compromised its systems since July 28, 2023.
Evidence shows that on August 31, an unauthorized malicious actor accessed data , and the following types of data were confirmed to be exposed by October 10:
- Full name
- Social Security Number (SSN)
- Health insurance coverage information
- Date of birth
- Billing or claim information
- Diagnosis
- Doctor Information
- Medical file number
- Medicare/Medicaid Information
- Information about prescription drugs
- Diagnostic results and treatment information.
See also: Sumo Logic: Announces breach – Recommends API key resets
The specific types of data disclosed will vary for each individual, depending on the information shared with the organization and the services they received. All affected individuals will receive a notification at the email they provided to McLaren with instructions to sign up for identity protection services for 12 months.

McLaren says it currently has no evidence that cybercriminals misused the data, but encourages affected individuals to be cautious of unexpected communications and to carefully monitor their bank account activity.
Although the organization is not revealing many details about the cyberattack, it is worth mentioning that the ALPHV/BlackCat ransomware group claimed responsibility for an attack on McLaren's network on October 4th.
The threat actors published samples of the data they allegedly stole from McLaren and threatened to auction off the entire set of data they claim affects 2.5 million people.
See also: Marina Bay Sands: Data breach affected 665,000 customers
Affected customers face several potential risks due to the data breach. One of the risks is potential identity theft. breaches include personal information, such as names, addresses, social security numbers, and ID numbers, which can be used to commit fraud or malicious activities.
Another potential risk is loss of privacy. Scammers can use personal information to invade people's privacy, threaten them, or blackmail them.
Additionally, those affected may face risks related to the security of their financial information. If data leaks include credit card or bank account information, hackers can use it to steal money or commit fraud.
Finally, those affected may face cybersecurity risks. Data breaches can lead to the exploitation of vulnerabilities in McLaren Health Care’s systems and applications, resulting in further damage or data breaches.
Source: bleepingcomputer
