185K people's sensitive data in the pits after ransomware raid on Cherry Health
- Reference: 1713448815
- News link: https://www.theregister.co.uk/2024/04/18/ransomware_cherry_health/
- Source link:
Michigan-based Cherry Health reported a data breach to regulators on Wednesday caused by a ransomware attack back in December 2023.
The health center, which operates across six counties within the state, also revealed the scale of the sensitive data stolen by the group. In addition to names, email and home addresses, phone numbers, and dates of birth, data that could be used to increase the perceived legitimacy of a phishing campaign was also gathered:
Health insurance information
Health insurance ID number
Patient ID number
Provider name
Service date
Diagnosis/treatment information
Prescription information
Financial account information and/or social security numbers
All of these data points were mentioned in a template [1]notification letter [PDF] prepared for bulk distribution. However, Cherry Health's [2]report to the Office of the Maine Attorney General suggests that simply listing "financial account information" may have been underplaying the severity here.
The filing in Maine mentioned bank account or credit/debit card numbers were stolen in combination with one of the following: security code, access code, password, or PIN for the account.
[3]MGM says FTC can't possibly probe its ransomware downfall – watchdog chief Lina Khan was a guest at the time
[4]Change Healthcare's ransomware attack costs edge toward $1B so far
[5]Change Healthcare faces second ransomware dilemma weeks after ALPHV attack
[6]Nearly 1M medical records feared stolen from City of Hope cancer centers
The healthcare organization said in the letter: "We take the privacy of information in our care very seriously. At this time, there is no evidence that any of your information has been, or will be, misused. In an abundance of caution, we are providing you information about the incident, our response, and steps you can take to further protect your information should you feel it is necessary to do so.
"On December 21, 2023, Cherry Health experienced a network disruption, that affected our ability to access certain systems. Upon learning of this, we immediately began an investigation with the support of third-party specialists. Through the investigation, we learned that some data we maintain was accessed improperly. We then took steps to determine the types of information that were at risk and the individuals to whom it pertained. On March 25, 2024, this process was completed, and we worked to notify you as soon as possible."
[7]
Individuals caught up in the data breach have been offered the requisite 12 months of credit monitoring, and according to the HTML in the letter template, it seems some may be offered up to 24 months.
[8]
The attack type was listed as ransomware, but no criminal crew has yet stepped forward to claim responsible.
However, in common ransomware scenarios, stolen data is used as leverage to extort a victim. If they pay, the data doesn't get published – it's known as the [9]double extortion method , which has proven quite successful for criminals in recent years.
[10]
The attack comes fresh off the heels of the massively disruptive [11]incident at Change Healthcare , which this week was revealed to have cost parent company UnitedHealth [12]$872 million in remediation costs to date. ®
Get our [13]Tech Resources
[1] https://regmedia.co.uk/2024/04/18/m_cherry_street_services_general_notification_letter_v2.pdf
[2] https://apps.web.maine.gov/online/aeviewer/ME/40/2b5a149e-ee5d-4199-9149-ca4d19ec7515.shtml
[3] https://www.theregister.com/2024/04/16/mgm_ftc_lawsuit/
[4] https://www.theregister.com/2024/04/16/change_healthcares_ransomware_attack_has/
[5] https://www.theregister.com/2024/04/08/change_healthcare_ransomware/
[6] https://www.theregister.com/2024/04/03/city_of_hope_data_theft/
[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZiFDnSDzx9FxbJkKV2BtRgAAAEI&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZiFDnSDzx9FxbJkKV2BtRgAAAEI&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[9] https://www.theregister.com/2023/10/02/feds_ransomware_report/
[10] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZiFDnSDzx9FxbJkKV2BtRgAAAEI&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[11] https://www.theregister.com/2024/02/29/alphv_change_healthcare/
[12] https://www.theregister.com/2024/04/16/change_healthcares_ransomware_attack_has/
[13] https://whitepapers.theregister.com/
There ought to be a rubber stamp for this
' "We take the privacy of information in our care very seriously. At this time, there is no evidence that any of your information has been, or will be, misused. ..."
Why doesn't someone make a million selling a rubber stamp carrying this text? Preferably suitable for printing on toilet paper as this is really just a bum cover.
No evidence of harm is not evidence of no harm. And do they have a crystal ball to see into the future? In any case it's probably impossible to find out as any evidence of a connection between this breach and any subsequent fraud on some individual will be really tenuous.
Re: There ought to be a rubber stamp for this
Any institution uttering that (or similar) phrases should be subject to an immediate multi-million $/£/€ fine!
"In an abundance of caution"
You mean, the abundance you did not put into securing your network and training your people ?
And I see that you have found the boilerplate yada yada for failling to ensure the security of the data in your care. Well done. It sounds just as reliable now as it has the last million times we've already heard it.
You might want to actually put some millions behind your words soon, because it has cost some other health company $800+ million just to clean up.
You have that kind of money ? If so, carry on mouthing your platitudes.