HomeSecurityLos Angeles - Department of Public Health: Data breach affects 200,000 people

Los Angeles – Department of Public Health: Data breach affects 200,000 people

The Los Angeles Department of Public Health (DPH) has disclosed a data breach affecting more than 200,000 people.

Department of Public Health Los Angeles Data Breach

The stolen data includes personal, medical and financial information. The breach occurred between February 19 and 20, 2024, and was caused by the theft and use of credentials of 53 employees (via phishing).

See also: New phishing toolkit uses PWA to steal login credentials

The Department of Public Health, which serves about 10 million residents of County , said the data breach may affect the following customer/employee/other:

  • First name, last name and date of birth
  • Diagnosis and prescription information
  • Medical record number/patient ID
  • Medicare/Med-Cal number
  • Health insurance information
  • Social Security Number and other financial information

However, it does not mean that all of this information has been compromised for all of the affected individuals. Each individual may be affected differently.

The government agency is notifying all individuals who may be affected by the data breach by mail. For those who do not have a mailing address available, the agency is posting a notice on its website.

The Los Angeles Department of Public Health said: "While it cannot be confirmed whether information has been accessed or misused, individuals are encouraged to review the content and accuracy of the information in their medical records with their physician."

See also: Phishing emails promote malicious scripts via Windows search protocol

Affected individuals are also offered a free identity monitoring service from Kroll for one year.

Law enforcement has investigated the incident and the U.S. Department of Health and Human Services and other agencies are being notified as required by law and/or contract.

It all started with phishing emails and stolen credentials

The Department of Public Health said it has implemented "many improvements" to prevent similar phishing attacks in the future.

Upon discovering the attack, the department disabled the affected email accounts and reset users' devices. Additionally, all websites identified as part of the phishing campaign were blocked and all suspicious incoming emails were quarantined.

The service added that it has contacted all staff and sent out notifications to remind them to be careful when opening emails, especially those that include links or attachments.

Phishing protection

Users should be cautious and suspicious of emails they receive without expecting it. They should always be aware of the latest phishing techniques and learn how to recognize suspicious emails or message scams  . It is advisable to avoid clicking on links and attachments that look suspicious. Also, personal and financial information should not be given to third parties.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Los Angeles - Department of Public Health: Data breach affects 200,000 people
Los Angeles – Department of Public Health: Data breach affects 200,000 people

Using reliable security software that provides protection against malware and viruses is also helpful. This can help detect and avoid phishing attacks.

See also: Phishing attacks: Significant increase in the US and Europe

Next, users should be careful about the apps they download and install on their devices. They should only download apps from trusted sources and avoid apps that look suspicious or don't have good reviews.

Finally, it is essential to use different passwords for different accounts. Don't forget two-factor authentication where available, for an extra layer of security for your accounts.

Source: www.infosecurity-magazine.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS