A cyberattack in December at St Vincent's Health Australia has left patients in the dark about whether their sensitive medical data has been leaked.
See also: TransForm: Ransomware attack on hospitals affects data of thousands of patients

St Vincent's, Australia's largest not-for-profit hospital, began responding to a cybersecurity incident on December 19, 2023. In a statement issued three days later, the organization revealed that it had identified evidence that cybercriminals had removed "some data" from its network.
Although St Vincent's says the "cybercriminal activities" have not affected its ability to provide services across all of its hospitals, nursing homes, and virtual and home health networks, the hospital provided little information about the data theft.
The company's initial statement did not reveal exactly what data may have been affected, and while an update was issued a week later, St Vincent's has not been able to publicly confirm whether any patient data was stolen during the attack. Patients are still waiting to learn whether information was affected and what type of information may have been leaked.
See also: Alphv/BlackCat ransomware: Did it steal data from Morrison Community Hospital?
Towards the end of December, St Vincent's said it was still working to determine what data had been stolen, but expected it to "take considerable time" due to the "complex and highly technical" nature of its investigations.

“If we discover that sensitive information has been stolen by cybercriminals, we will do everything possible to contact the individuals affected to inform them of this, provide them with information about steps they can take to protect themselves, and support them in this process.“
St Vincent's told Information Age on Monday that it could not provide any information about the data theft or the identity of the individuals behind the incident.
See also: Two New York hospitals face problems after LockBit ransomware attack
A cyberattack on a medical institution can have serious consequences. First, it can cause disruption to medical services, as computing devices and systems used to manage patients may be unavailable.
Second, a cyberattack can lead to the leakage of sensitive patient data, such as medical information, personal details, and medical history. This can have serious implications for patient privacy and can lead to legal implications for the institution
Third, public trust in the medical establishment may be undermined, as patients and their families may be concerned about the security of their personal information.
Finally, a cyberattack can have financial consequences for the medical institution, as restoring systems and data, as well as dealing with legal repercussions, can be very costly.
Source: Information Age
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
