British healthcare provider HCRG Care Group has confirmed it is investigating a cyberattack, following claims by the Medusa ransomware gang that the company's systems were compromised.

HCRG Care Group is one of the largest independent providers of community health and care services in the UK. The organisation works with National Health Service trusts and local authorities across the country to deliver healthcare services to adults and children.
The Medusa ransomware group added HCRG to its data leak website and claimed to have stolen more than two terabytes of data.
See also: Hackers target organizations with NailaoLocker ransomware
Samples of the allegedly stolen data include personal employee information, sensitive medical records, financial records, and identity documents such as passports and birth certificates.
HCRG did not say what data was compromised, but did not dispute the Medusa ransomware group’s claims. The company also declined to say how many people were affected. According to its website, HCRG has more than 5,000 employees and provides healthcare to half a million patients across the UK.
“Our team has not observed any suspicious activity since implementing the security measures and we are working with external cybersecurity experts to investigate the incident,” the company spokeswoman said.
HCRG said it had notified the UK Information Commissioner's Office and other regulators .
"Our services continue to operate and we are safely seeing patients. Those who have appointments or need access to our services should continue to do so," the company said.
See also: Ghost ransomware has breached organizations in 70 countries
The Medusa ransomware group is threatening to publish the allegedly stolen data if HCRG does not pay a $2 million ransom.
HCRG did not say how it was breached, but Medusa typically exploits vulnerabilities in remote desktop software.

Healthcare: Effective protection strategies
One of the most effective protection strategies is training staff. Staff who are informed about the techniques used by attackers can recognize and, to some extent, avoid cyberattacks.
Implementing up-to-date security protocols is another important strategy. This includes regularly updating software and systems, installing the latest security patches , and implementing procedures that protect data.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Using advanced security tools, such as systems prevention intrusion and cyberattack detection and prevention tools, can help address threats before they cause damage.
See also: Lee Enterprises: Recent cyberattack was ransomware
Additionally, healthcare organizations must implement access policies to control who has access to patient data. This can include the use of credentials, such as usernames and passwords ,as well as implementing policies that require staff to change their passwords regularly.
They can also use external security services to monitor their networks for potential attacks. These services can include monitoring network traffic, detecting “anomalies” and responding to potential threats.
Finally, creating a breach response plan can be crucial. This plan should include threat analysis , attack identification, isolation of the compromised system, and restoration of systems to a secure state.
Source: techcrunch.com
