News: 1657746410

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

1.9m patient records exposed in healthcare debt collector ransomware attack

(2022/07/13)


Professional Finance Company, a Colorado-based debt collector whose customers include hundreds of US hospitals, medical clinics, and dental groups, recently disclosed that more than 1.9 million people's private data – including names, addresses, social security numbers and health records – was exposed during a ransomware infection.

In a notice

[1]PDF

posted on its website, PFC said it "detected and stopped a sophisticated ransomware attack" on February 26 this year, during which criminals accessed files containing data from more than 650 healthcare providers

[2]PDF

. The company said it notified the affected medical centers around May 5, and is mailing letters to individuals whose data may have been stolen during the intrusion.

According to the US Department of Health and Human Services, more than 1.9 million individuals were affected in the [3]security breach , which could make it one of — if not the — biggest American medical info data breaches of the year.

[4]

For comparison: in a 2019 [5]breach of American Medical Collection Agency, which provided similar debt collection services to PFC, crooks stole more than 20 million patient records including several hundred thousand payment card details. Shortly after, the agency [6]declared bankruptcy .

[7]

[8]

And in 2017 health insurer Anthem agreed to pay $115 million to settle a class-action suit brought on by its 2015 cyber-theft of 78.8 million records.

Here's an excerpt from PFC's ransomware notice:

PFC found no evidence that personal information has been specifically misused; however, it is possible that the following information could have been accessed by an unauthorized third party: first and last name, address, accounts receivable balance and information regarding payments made to accounts, and, in some cases, date of birth, Social Security number, and health insurance and medical treatment information.

The company will also offer free credit monitoring and identity theft protection services through Cyberscout for affected individuals.

After detecting the attack, the debt collection firm said it "immediately" hired third-party forensic specialists to secure its network and notified federal law enforcement. As stated, PFC claims it found no evidence of personal information being misused – well, other than it being stolen – and maintains that data security is one of its "highest priorities."

[9]

"Since the incident, PFC wiped and rebuilt affected systems and has taken steps to bolster its network security," the ransomware notice said. PFC also noted that it updated its security and data storage policies.

[10]Here today, gone to Maui: That's your data captured by North Korean ransomware

[11]Billion-record stolen Chinese database for sale on breach forum

[12]Cyberattack shuts down unemployment, labor websites across the US

[13]'Prolific' NetWalker extortionist pleads guilty to ransomware charges

The company did not answer any of The Register 's questions about the ransomware infection — including how much money the crooks demanded, whether PFC paid the ransom, why it took so long to notify affected medical centers and patients, and if the stolen files were encrypted prior to the attack.

Instead, PFC's General Counsel Nicholas Prola emailed a canned statement that repeated much of the company's breach alert posted on its website. Prola did, however, include additional information about what steps the debt collection firm took to improve its security posture after the attack.

This includes "adding AI threat protection and contracting with two leading cybersecurity firms," Prola wrote. "Additionally, since the incident, our network environment has been under 24/7 monitoring by cybersecurity experts to mitigate the chance of a future incident."

Meanwhile, in other ransomware news…

The news about the PFC ransomware attack comes as the Institute for Security and Technology's Ransomware Task Force released [14]data documenting more than 4,000 attacks last year targeting organizations across all industries in 109 countries.

The criminals include more than 60 ransomware "families," according to the public-private task force, and almost half of the victims were US-based organizations.

A year ago the group [15]published an 81-page report presenting policy makers with 48 recommendations to disrupt the ransomware business and mitigate the effect of such attacks. ®

Get our [16]Tech Resources



[1] https://s3.documentcloud.org/documents/22084965/pfc-notice-of-ransomware-attack.pdf

[2] https://s3.documentcloud.org/documents/22084964/entities-notified-by-pfc.pdf

[3] https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Ys9AhRlYOJ3C-nk4l5zhJAAAAMs&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[5] https://www.theregister.com/2019/06/05/labcorp_amca_hacked/

[6] https://www.theregister.com/2019/06/18/hacked_amca_bankruptcy_protection/

[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Ys9AhRlYOJ3C-nk4l5zhJAAAAMs&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Ys9AhRlYOJ3C-nk4l5zhJAAAAMs&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[9] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Ys9AhRlYOJ3C-nk4l5zhJAAAAMs&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[10] https://www.theregister.com/2022/07/06/here_today_gone_to_maui/

[11] https://www.theregister.com/2022/07/05/shanghai_police_database_for_sell/

[12] https://www.theregister.com/2022/07/01/gsi-cyberattack-state-unemployment/

[13] https://www.theregister.com/2022/06/29/netwalker_extortionist_pleaded_guilty/

[14] https://securityandtechnology.org/blog/rtf-year-two-new-map-new-data-same-mission/

[15] https://www.theregister.com/2021/04/29/ransomware_task_force_offers_48/

[16] https://whitepapers.theregister.com/



Criminals hack criminals

ecofeco

While it sucks that personal records were stolen, I have no love for the company either.

Much like when Equifax was hacked.

Rules for Writers:
Avoid run-on sentences they are hard to read. Don't use no double
negatives. Use the semicolon properly, always use it where it is appropriate;
and never where it isn't. Reserve the apostrophe for it's proper use and
omit it when its not needed. No sentence fragments. Avoid commas, that are
unnecessary. Eschew dialect, irregardless. And don't start a sentence with
a conjunction. Hyphenate between sy-llables and avoid un-necessary hyphens.
Write all adverbial forms correct. Don't use contractions in formal writing.
Writing carefully, dangling participles must be avoided. It is incumbent on
us to avoid archaisms. Steer clear of incorrect forms of verbs that have
snuck in the language. Never, ever use repetitive redundancies. If I've
told you once, I've told you a thousand times, resist hyperbole. Also,
avoid awkward or affected alliteration. Don't string too many prepositional
phrases together unless you are walking through the valley of the shadow of
death. "Avoid overuse of 'quotation "marks."'"