Shields Health Care Group data breach affects 2 million patients
By Bill Toulas, Bleeping Computer
Shields Health Care Group (Shields) suffered a data breach that exposed the data of approximately 2,000,000 people in the United States after hackers breached their network and stole data.
Shields is a Massachusetts-based medical services provider specializing in MRI and PET/CT diagnostic imaging, radiation oncology, and ambulatory surgical services.
According to a data breach notification published on the company's site, Shield became aware of the cyberattack on March 28, 2022, and hired cybersecurity specialists to determine the scope of the incident.
The examination of log files showed that the hackers had access to Shields’ systems from March 7, 2022, to March 21, 2022, allowing them to potentially access data containing the following patient information:
- Full name
- Social Security number
- Date of birth
- Home address
- Provider information
- Diagnosis
- Billing information
- Insurance number and information
- Medical record number
- Patient ID
- Other medical or treatment information
The above information can be used for social engineering, phishing, scamming, and even extortion, depending on the case, and is generally considered extremely sensitive information.
Shields says it has seen no evidence that any stolen information has been misused or disseminated on illegal channels. However, it might be too early for that data to be circulated publicly.
Typically, stolen information of this kind is bartered privately and used in small-scale, targeted attacks before it is resold to lower-tier threat actors who engage in bulk exploitation.
Comments
Post a Comment