News: 1678910706

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Cancer patient sues hospital after ransomware gang leaks her nude medical photos

(2023/03/15)


A cancer patient whose nude medical photos and records were posted online after they were stolen by a ransomware gang, has sued her healthcare provider for allowing the "preventable" and "seriously damaging" leak.

The proposed class-action lawsuit stems from a February [1]intrusion during which malware crew BlackCat (also known as ALPHV) broke into one of the Lehigh Valley Health Network (LVHN) physician's networks in the USA, stole images of patients undergoing radiation oncology treatment along with other sensitive health records belonging to more than 75,000 people, and then demanded a ransom payment to decrypt the files and prevent it from posting the health data online.

The Pennsylvania health care group, one of the largest in the state, oversees 13 hospitals, 28 health centers, and dozens of other physicians' clinics, pharmacies, rehab centers, imaging and lab services. LVHN [2]refused to pay the ransom, and earlier this month BlackCat started leaking patient info, including images of at least two breast cancer patients, naked from the waist up.

[3]

"This unconscionable criminal act takes advantage of patients receiving cancer treatment, and LVHN condemns this despicable behavior," LVHN spokesperson Brian Downs [4]said at the time.

Ms. LaRock offered plaintiff an apology, and with a chuckle, two years of credit monitoring

According to the lawsuit

[5]PDF

filed this week, here's how one of the patients, identified as "Jane Doe" found out about the data breach — and that LVHN had stored nude images of her on its network in the first place.

On March 6, LVHN VP of Compliance Mary Ann LaRock, called Doe and told her that her nude photos had been posted on the hackers' leak site. "Ms. LaRock offered plaintiff an apology, and with a chuckle, two years of credit monitoring," the court documents say.

[6]

[7]

In addition to swiping the very sensitive photos, the crooks also made off with everything needed for identity fraud.

According to the lawsuit, LaRock also told Doe that her physical and email addresses, along with date of birth, social security number, health insurance provider, medical diagnosis and treatment information, and lab results were also likely stolen in the breach.

[8]

"Given that LVHN is and was storing the sensitive information of plaintiff and the class, including nude photographs of plaintiff receiving sensitive cancer treatment, LVHN knew or should have known of the serious risk and harm that could occur from a data breach," the lawsuit says.

It claims LVHN was negligent in its duty to safeguard patients' sensitive information, and seeks class action status for everyone whose data was exposed with monetary damages to be determined.

[9]Ransomware gang threatens 1m-plus medical record leak

[10]Zoll Medical says intruders had 1M+ patient, staff records at their fingertips

[11]FBI: BlackCat ransomware scratched 60-plus orgs

[12]This ransomware gang is a right Royal pain in the AES for healthcare orgs

Pennsylvania attorney Patrick Howard, who is representing Doe and the rest of the plaintiffs in the proposed class action, said he expects the number of patients affected by the breach to be in the "hundreds, if not thousands."

"The hospital invites patients into its facility and takes possession of this data," Howard told The Register . "The hospital must ensure that the data it takes is properly safeguarded, including these highly sensitive photographs. You give the expectation of safety and security, if you act negligently in providing that safety/security, you can be held liable regardless of the conduct of a third party."

LVHN declined to comment on the suit. "We do not comment on active legal matters," Downs told The Register .

[13]

According to the lawyers, this is the second data breach affecting the Pennsylvania health-care group's patients over the last few years. In 2021, LVHN admitted that patients' personal info was stolen from one of its vendors, we're told. ®

Get our [14]Tech Resources



[1] https://www.theregister.com/2022/09/14/ransomware_medical_groups/

[2] https://www.lvhn.org/news/message-brian-nester-do-mba-president-and-ceo-lehigh-valley-health-network

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZBJOEFUHml2c4XFEFnYbZQAAAFU&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[4] https://www.hipaajournal.com/ransomware-gang-ups-the-ante-by-publishing-naked-images-of-patients/

[5] https://regmedia.co.uk/2023/03/15/lvhn_lawsuit_march_2023.pdf

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZBJOEFUHml2c4XFEFnYbZQAAAFU&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZBJOEFUHml2c4XFEFnYbZQAAAFU&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZBJOEFUHml2c4XFEFnYbZQAAAFU&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[9] https://www.theregister.com/2022/09/14/ransomware_medical_groups/

[10] https://www.theregister.com/2023/03/13/zoll_medical_data_intrusion/

[11] https://www.theregister.com/2022/04/25/in_brief_security/

[12] https://www.theregister.com/2022/12/09/royal_ransomware_hhs_warning/

[13] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZBJOEFUHml2c4XFEFnYbZQAAAFU&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[14] https://whitepapers.theregister.com/



Flippin' heck!

Eclectic Man

As if having cancer badly enough to need radiotherapy was not bad enough:

"her physical and email addresses, along with date of birth, social security number, health insurance provider, medical diagnosis and treatment information, and lab results were also likely stolen in the breach."

I though there was some general agreement amongst data thieves and ransomware users that medical facilities were off limits.

Utterly appalling.

Re: Flippin' heck!

J__M__M

>I though there was some general agreement amongst data thieves and ransomware users that medical facilities were off limits.

Where in the hell have you been?

NHS

elsergiovolador

Thankfully our government is keeping our personal data safe under hawkish eye of a certain corporation.

So don't worry, something like this will never happen.

And once we ban encryption and maths, we will be able to see what everyone is up to and we will catch anyone daring to touch our precious data before they do anything.

Anonymous Coward

Until and unless the alternative is an existential threat level of fines/compensation payouts, organisations will continue to fail to properly fund cybersecurity efforts

Doctor Syntax

Or to put it plainer (it needs to be plain enough for directors and investors), until fines and compensation have actually taken a few noticeably big corporations down entirely. The first two or three might get noticed but it mike take more to start the panic that's needed.

The reasonable man adapts himself to the world; the unreasonable one
persists in trying to adapt the world to himself. Therefore all progress
depends on the unreasonable man.
-- George Bernard Shaw