You've been pwned, how much will each stolen customer SSN cost you? How about $7.5k?
- Reference: 1679148133
- News link: https://www.theregister.co.uk/2023/03/18/orlando_family_physicians_settlement/
- Source link:
Under the settlement
[1]PDF
, Orlando Family Physicians, which operates 10 clinics in central Florida, will reimburse affected patients who [2]submit a claim by July 1, and provide them with two years of free credit monitoring. Depending on what type of private data the crooks stole, patients may receive up to $225 or, for those whose SSNs were swiped, up to $7,500.Also under the settlement the physicians group doesn't admit any culpability following the data heist.
[3]
The theft occurred in April 2021 after criminals gained access to four employees' email accounts via a phishing scam, according to court documents
[4]PDF
.[5]
[6]
Orlando Family Physicians [7]said it "immediately" took steps to contain the intrusion and hired a "leading" security shop to determine the scope of the intrusion.
A few months later, the health group posted a notice on its website and sent letters to individuals whose personal information was exposed.
[8]
This included names; demographic information; health information, including diagnoses, providers and prescriptions; health insurance information, including legacy Medicare beneficiary number derived from the individual's Social Security number or other subscriber identification number; medical record numbers; patient account numbers; and passport numbers.
"However, the available forensic evidence indicates that the unauthorized person's purpose was to commit financial fraud against OFP and not to obtain personal information about the affected individuals," the physicians group said at the time.
OFP also [9]reported the crime to the US Department of Health and Human Services, and said it potentially affected 447,426 individuals.
[10]
The group declined to comment to The Register about the settlement.
Is your PII worth $250? Or $75k?
And now, those hundreds of thousands of individuals whose personal information likely ended up for sale on a hacking forum are eligible for a payout, after the attorneys take their cut, natch. The total amount of the settlement remains undisclosed.
There are two levels of class members who may benefit financially. The first, those who had to pay out-of-pocket expense because of the theft, can submit a claim for up to $225 for documented expenses. This includes costs related to freezing or unfreezing credit reports and paying for credit monitoring services, or anything related to communicating with banks about the incident: notary, fax, postage, copying, mileage, and long-distance telephone charges.
These individuals can also submit a claim for up to three hours of time lost due to the security breach at a rate of $25 per hour.
The second group are those whose Social Security numbers were stolen. These individuals can submit a claim for up to $7,500 for documented cases of identity theft, falsified tax returns, or other types of fraud that can be traced to the original hack.
They can also claim up to eight hours of lost time at $25 per hour.
[11]Cancer patient sues hospital after ransomware gang leaks her nude medical photos
[12]Ransomware crooks steal 3m+ patients' medical records, personal info
[13]Zoll Medical says intruders had 1M+ patient, staff records at their fingertips
[14]Ransomware gang threatens 1m-plus medical record leak
The settlement comes as cybercriminals — especially ransomware gangs — [15]step up their attacks against hospitals and healthcare companies, and the attorneys have followed with multiple class-action lawsuits.
Last month, California's Regal Medical Group sent notification letters to more than [16]three million patients alerting them that crooks may have stolen a ton of their sensitive health and personal information during a ransomware infection in December.
At least four [17]class-action lawsuits have since been filed against that medical conglomerate.
Earlier this week, a cancer patient whose nude medical photos and her personal records were posted online after they were stolen by a ransomware gang, [18]sued her healthcare provider for allowing the "preventable" and "seriously damaging" leak.
The proposed class-action lawsuit stems from a February [19]intrusion during which malware crew BlackCat broke into one of the Lehigh Valley Health Network physician's networks, stole images of patients undergoing radiation oncology treatment along with other sensitive health records belonging to more than 75,000 people, and then demanded a ransom payment to decrypt the files and prevent it from posting the health data online. ®
Get our [20]Tech Resources
[1] https://angeion-public.s3.amazonaws.com/www.OrlandoFPSettlement.com/docs/Settlement%20Agreement%20(Fully%20Executed).pdf
[2] https://www.orlandofpsettlement.com/
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZBXuM89fP-f7LhXaXUQPlgAAAFU&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[4] https://angeion-public.s3.amazonaws.com/www.OrlandoFPSettlement.com/docs/Complaint.pdf
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZBXuM89fP-f7LhXaXUQPlgAAAFU&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZBXuM89fP-f7LhXaXUQPlgAAAFU&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[7] https://orlandofamilyphysicians.com/notice/#
[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZBXuM89fP-f7LhXaXUQPlgAAAFU&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[9] https://healthitsecurity.com/news/florida-doctors-group-target-of-cyberattack-phi-exposed
[10] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZBXuM89fP-f7LhXaXUQPlgAAAFU&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[11] https://www.theregister.com/2023/03/15/cancer_lvhn_sues_hospital/
[12] https://www.theregister.com/2023/02/11/ransomware_regal_medical_group/
[13] https://www.theregister.com/2023/03/13/zoll_medical_data_intrusion/
[14] https://www.theregister.com/2022/09/14/ransomware_medical_groups/
[15] https://www.theregister.com/2023/03/13/zoll_medical_data_intrusion/
[16] https://www.theregister.com/2023/02/11/ransomware_regal_medical_group/
[17] https://www.hipaajournal.com/multiple-lawsuits-regal-medical-group-ransomware/
[18] https://www.theregister.com/2023/03/15/cancer_lvhn_sues_hospital/
[19] https://www.theregister.com/2022/09/14/ransomware_medical_groups/
[20] https://whitepapers.theregister.com/
Re: SSN theft
Yes, the SSN system is wholly abused by every facet of life in America. At a lot of employers, it was my employee number. I'm not sure how Social Security and the IRS are connected, but the SSN is also your TIN...Taxpayer Identification Number?
I don't see any problems there /s
Re: SSN theft
What's even better is one of the Oracle DBs I admin uses SSNs as a primary key all over the place. The original developers are far out of horse-whipping reach.
And if you look at a Social Security card, it says in bold type: "Not to be used for identification purposes"
I suppose there isn't an actual law behind that, or I'd be suing the IRS and every man Jack for breaking it.
Re: SSN theft
When I got an American SSN four decades ago, (I had to have one to be paid for my on-campus job) the card had Big Red Letters on it stating that it was NOT FOR USE FOR PERSONAL IDENTIFICATION. A replacement card, obtained less than a decade ago, after the original card pretty much died in action, lacked that notification. There is still a notification on the stuff that comes with the card that you really shouldn’t walk around with your card.
Note that my roommate on campus was Navy ROTC. The USN issued him with a ‘seabag’ (officer’s version) which had his SSN printed on it. He said that enlisted men got similar seabags, and might have the SSN on the backs of various uniform items, and lockers, and so on, as the US military (not just the Navy) used the SSN as their military ID number. (Officers didn’t have their SSN printed on their uniforms.)
And, oh, the uni gave me a new uni ID card, with the SSN. All students who had SSNs, a.k.a. all American students, and non-American students who had on-campus jobs, had their SSNs as the student ID number. Grades were posted on the professors’ doors, listed by student ID. A.k.a SSN. It was trivially easy to obtain someone else’s SSN.
$25/hour in recompense for time spent by individuals trying to clean up this mess?
And how much are the doctors and lawyers paid per hour?
When I was gainfully employed my rate was 3 to 5 times that paltry $25.
SSN theft
> This included names; demographic information; health information, including diagnoses, providers and prescriptions; health insurance information, including legacy Medicare beneficiary number derived from the individual's Social Security number or other subscriber identification number; medical record numbers; patient account numbers; and passport numbers.
I've been a US citizen for decades and I've never understood the whole SSN thing. A single number, which you can't change, which gives people who find out about it the ability to see all sorts of personal info, apply for loans, access various government websites, ...
At least my passport number rotates every time I get a new passport.
I already assume that my (name, SSN, some current or previous address, birthday) tuple is leaked out there already. I'd be significantly more livid to know that my medical info got leaked: there's some things about my health I'd rather keep between me and my family. But that's not what gets the big bucks in compensation, I guess.