Norton Healthcare has confirmed that a ransomware attack that took place in May ultimately led to a data breach that exposed personal information of patients, employees and others.

Norton Healthcare offers health services to adults and children at more than 40 clinics and hospitals throughout Greater Louisville, Southern Indiana and the Commonwealth of Kentucky.
“On May 9, 2023, Norton Healthcare discovered that it was experiencing a cybersecurity , which was later determined to be a ransomware attack,” said in a press release published Friday.
Norton Healthcare said it notified federal enforcement and began working with third-party cybersecurity experts to investigate and terminate the unauthorized access.
See also: US hospitals urged to protect against Citrix Bleed bug
“Our investigation determined that an unauthorized individual gained access to certain network storage devices between May 7, 2023 and May 9, 2023, but did not access Norton Healthcare’s medical records system or Norton MyChart,” the health organization said.
However, the ransomware attack led to a data breach, as the attackers managed to gain access to information such as name, information , Social Security Number, date of birth, health information, insurance information, and medical ID numbers belonging to Norton Healthcare customers and employees.
The agency says that, for some individuals (likely employees), the exposed data may also include bank account, driver's licenses, or other identification numbers.
Affected individuals will be able to use credit protection services for two years, free of charge, while they will receive additional information about the incident through special notifications.
Is BlackCat/ALPHV ransomware behind the Norton Healthcare attack?
While Norton Healthcare did not link the attack to a specific ransomware group, the ALPHV (BlackCat) claimed responsibility in late May. The hackers listed the organization on their data breach site, saying they stole data (4.7 TB) from the organization’s compromised systems.
See also: Capital Health: IT systems in hospitals outages due to cyberattack
The ransomware gang also leaked dozens of files as proof of the breach, containing patients' social security numbers, bank statements, and more.
Norton Healthcare is just one of several large healthcare organizations in the United States that have fallen victim to ransomware. Since last year, the US government has issued multiple warnings about attacks targeting healthcare institutions across the country.

Consequences of cyberattacks on hospitals
The consequences of an attack on a hospital can be severe and affect both patients and hospital staff. An attack can lead to the loss or theft of sensitive information, such as medical records, personal data, and financial information. This can have negative impacts on patient privacy and security, as well as their trust in the hospital.
Additionally, an attack can cause disruption to critical hospital services, such as access to medical devices and intensive care systems. This can have serious health and safety patient, as well as cause delays in the provision of medical care.
See also: Hospitals in 6 states hit by ransomware attack
In addition, attacks can cause financial losses for the hospital, as restoring systems and dealing with the impact can require significant resources. Then, the hospital's reputation can suffer, as attacks can cause concern and loss of trust from the public.
Finally, an attack on a hospital can have wider implications for the health sector. It can encourage other malicious actors to attack other hospitals and healthcare providers, thereby increasing the risk to the health and safety of the wider population.
Source: www.bleepingcomputer.com
