Top US health provider tells 882,000 patients they were hit in August 2023 breach

healthcare
(Image credit: Shutterstock)

  • Hospital Sisters Health System files new report with the Maine Attorney General
  • It confirmed more than 800,000 affected in an August 2023 breach
  • Compromised people are getting a year's worth of free identity theft monitoring

Hospital Sisters Health System (HSHS), a nonprofit, Catholic healthcare system, suffered a cyberattack one and a half years ago, which resulted in the theft of sensitive patient data.

The firm has now filed a report with the Maine Office of the Attorney General, in which it detailed the attack, noting it discovered an “unauthorized third party” gaining temporary access to its network, on August 27, 2023.

“Upon learning of the situation, we immediately took steps to contain and remediate the incident and launched an internal investigation,” HSHS said in the filing.

Stealing sensitive data

The investigation determined that the unnamed attackers dwelled on HSHS’ network between August 16 and August 27, and during that time exfiltrated sensitive information belonging to exactly 882,782 people.

“We have since been reviewing those files and notifying individuals whose information was found in the files on a rolling basis as our review has continued,” the organization said.

While the type of information stolen varied from person to person, in general it included full names, postal addresses, birth dates, medical record numbers, limited treatment information, health insurance information, Social Security numbers (SSN), and driver’s license numbers.

This is more than enough to engage in highly personalized phishing, identity theft, or even wire fraud. However, HSHS says that at this time it has “no reason to believe” the data has been misused.

Healthcare information is highly sought on the black market because it contains sensitive personal, financial, and medical data that can be exploited for various types of fraud and cybercrimes. Unlike credit card data, which can be quickly canceled, stolen medical records provide long-term value as they include Social Security numbers, insurance details, and medical histories that can be used for identity theft, fraudulent billing, prescription fraud, and even blackmail. Additionally, the resale price of medical records is significantly higher than financial data due to their completeness and difficulty in detection.

That being said, even though there is no evidence of misuse, “out of an abundance of caution”, HSHS offered affected individuals a year’s worth of credit and identity theft monitoring through Equifax.

Via BleepingComputer

You might also like

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

You must confirm your public display name before commenting

Please logout and then login again, you will then be prompted to enter your display name.

Read more
ID theft
Over a million patients potentially hit after another US healthcare provider hit by cyberattack
An abstract image of padlocks overlaying a digital background.
US healthcare giant Ascension says ransomware attack affected nearly six million customers
Lock on Laptop Screen
United Healthcare data breach may have affected 190 million Americans
Data breach
Top medical billing firm says data breach hit 360,000 users
ransomware avast
The biggest addiction treatment provider in the US says it was hit by data breach
A person's fingers type at a keyboard, with a digital security screen with a lock on it overlaid.
Blood donation firm reveals donor personal data stolen in cyberattack
Latest in Security
Representational image of a cybercriminal
Criminals are spreading malware disguised as DeepSeek AI
healthcare
Software bug meant NHS information was potentially “vulnerable to hackers”
A hacker wearing a hoodie sitting at a computer, his face hidden.
Experts warn this critical PHP vulnerability could be set to become a global problem
botnet
YouTubers targeted by blackmail campaign to promote malware on their channels
A close-up of a phone screen showing the Telegram, Signal and WhatsApp apps
Agentic AI has “profound” issues with security and privacy, Signal President says
botnet
Another top security camera maker is seeing devices hijacked into botnet
Latest in News
Nintendo Switch 2
A Nintendo Switch 2 FCC filing confirms Wi-Fi 6 and NFC support for the upcoming console
Google Pixel 8 review Pixel 8 Pro cameras
Is your Google Pixel 9 screen flickering or are the haptics a lot more intense? You aren't alone, and thankfully there's a fix
Matt Murdock holding a phone to his right ear in a prison in Daredevil: Born Again episode 2
What time is Daredevil: Born Again episode 3 going to be released on Disney+?
Representational image of a cybercriminal
Criminals are spreading malware disguised as DeepSeek AI
The logo of the social media app Bluesky is seen on the screen of a mobile phone
Bluesky gets a massive video upgrade to tempt X fans who are frustrated by its cyberattack outages
Acer Aspire 14 AI laptop display showing the Windows 11 login screen
Shock, horror – I’m not going to argue with Microsoft’s latest bit of nagging in Windows 11, as this pop-up is justified