News: 1712187189

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Nearly 1M medical records feared stolen from City of Hope cancer centers

(2024/04/04)


Nearly one million individuals' personal details, financial account information, and medical records may well have been stolen from City of Hope systems in the United States.

Despite the name, City of Hope is a healthcare organization that operates cancer hospitals and outpatient centers in Duarte, California, as well as the Atlanta, Chicago, and Phoenix areas. The biz, which also carries out cancer research, disclosed it suffered an IT security breach on its website on Tuesday.

In a notification [1]submitted to the Maine Attorney General's office this week, City of Hope said 827,149 people have been caught up in yet another case of [2]cyber-thieves targeting hospitals and their patients, which in previously separate cases has at times [3]disrupted critical care.

[4]

According to an April 2 [5]statement by the health org, a miscreant infiltrated "a subset of our systems," had access to the aforementioned personal records, and stole at least some files between September 19 and October 12, 2023. City of Hope says it became aware of "suspicious activity" a day later, and swears it immediately took action to minimize any disruption to its operations.

[6]

[7]

We're told that in December last year the org emailed folks who may have had their info siphoned, and since March 25 has been alerting those it has determined were affected by the intrusion.

"There is no indication of any identity theft or fraud occurring as a result of this incident," The Register was told by a spokesperson today. "City of Hope has safely cared for patients during and after the incident."

[8]

City of Hope stated the "investigation remains ongoing," and warned in its advisory that any stolen data could include: Names, email addresses, phone numbers, dates of birth, Social Security numbers, driver's license or other government identification, financial details such as bank account number and/or credit card details, health insurance information, medical records and information about medical history and/or associated conditions, and/or unique identifiers to associate individuals with City of Hope such as medical record numbers.

Whew.

"Upon discovery of this incident, City of Hope immediately instituted mitigation measures," the Maine notification stated.

[9]

"We then promptly implemented additional and enhanced safeguards and enlisted the support of a leading cybersecurity firm to enhance the security of our network, systems, and data," it continued. "We also launched a comprehensive investigation, identified individuals affected, reported the incident to law enforcement, and notified regulatory bodies."

Affected individuals will receive two years of free identity monitoring services from Kroll.

[10]INC Ransom claims responsibility for attack on NHS Scotland

[11]Uncle Sam intervenes as Change Healthcare ransomware fiasco creates mayhem

[12]Ransomware can mean life or death at hospitals. DEF CON hackers to the rescue?

[13]Ignore Uncle Sam's 'voluntary' cybersecurity goals for hospitals at your peril

The City of Hope disclosure follows several other major data theft and ransomware infections targeting the healthcare industry, in part because criminals have learned that these critical facilities are more likely to pay a ransom to end the pain as it were.

In late March, crime gang INC Ransom [14]claimed to have stolen three terabytes of data from NHS Scotland. The health org said it managed to contain the infection within a regional branch.

Earlier this year, the ALPHV/BlackCat gang took credit for a [15]ransomware attack on Change Healthcare that disrupted pharmacies' abilities to fill prescriptions and hospitals providing patient care for weeks across America in February and March.

The US government has since launched a [16]probe into Change's data protection practices; it's alleged the ALPHV crew stole 6TB of info from that business.

In response to the growing number of attacks on healthcare and other [17]critical infrastructure sectors in America, last week the Feds [18]posted a notice of proposed rulemaking for the Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA).

Meanwhile, the Department of Health and Human Services has [19]indicated its "voluntary" cybersecurity goals for hospitals may soon become less voluntary. ®

Get our [20]Tech Resources



[1] https://apps.web.maine.gov/online/aeviewer/ME/40/1bb296e2-ea79-438c-b357-28ef738a0bf6.shtml

[2] https://www.theregister.com/2024/01/06/ransomware_payment_ban_wrong_idea/

[3] https://www.theregister.com/2024/03/06/us_government_change_ransomware_intervention/

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Zg4l2KJmZXS48Gx63GW8eAAAAAk&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[5] https://www.cityofhope.org/notice-of-data-security-incident

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Zg4l2KJmZXS48Gx63GW8eAAAAAk&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Zg4l2KJmZXS48Gx63GW8eAAAAAk&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Zg4l2KJmZXS48Gx63GW8eAAAAAk&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[9] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Zg4l2KJmZXS48Gx63GW8eAAAAAk&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[10] https://www.theregister.com/2024/03/28/nhs_scotland_cyberattack/

[11] https://www.theregister.com/2024/03/06/us_government_change_ransomware_intervention/

[12] https://www.theregister.com/2024/03/26/aixcc_healthcare/

[13] https://www.theregister.com/2024/02/05/us_voluntary_cybersecurity_goals_hospitals/

[14] https://www.theregister.com/2024/03/28/nhs_scotland_cyberattack/

[15] https://www.theregister.com/2024/02/29/alphv_change_healthcare/

[16] https://www.theregister.com/2024/03/14/change_healthcare_ransomware_investigation/

[17] https://www.theregister.com/2024/03/06/fbi_ransomware_cybercrime_costs/

[18] https://www.theregister.com/2024/03/28/critical_infrastructure_cyberattack_reporting/

[19] https://www.theregister.com/2024/02/05/us_voluntary_cybersecurity_goals_hospitals/

[20] https://whitepapers.theregister.com/



Way

elsergiovolador

It's not how you do it.

You create a company that specialises in processing data, especially medical records.

Build some reputation over the years.

Start lobbying politicians and people responsible for tenders.

Get a contract from department of health or something for processing medical records.

Make sure your lawyers sneak in terms that will allow you to choose subcontractors to process data virtually unrestricted.

Now you got the medical records, they pay you for having them and nobody calls you a thief.

Then instead of advertising on darknet, advertise that you look for subcontractors on the pedestrian web.

Hire them to do processing they want to do while they pay you to your completely unconnected offshore vehicle.

<Endy> taniwha: Have you TESTED this one? :)
<taniwha> Endy: of course not