Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Monday, 25 September, 2023
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2022
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2022
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

HCA Healthcare Falls Victim to Data Security Incident

Tennessee-based based HCA Healthcare has confirmed a data security incident that sees approximately 11 million patients across 20 states have their data stolen.

by The Gurus
July 11, 2023
in Featured
HCA data breach
Share on FacebookShare on Twitter

One of the largest healthcare providers in the US, HCA confirmed the breach on Monday 10 July. The data was taken from an external storage location exclusively used to automate the formatting of email messages. Taken from its statement, HCA confirmed that the stolen list contains information used for email messages, such as reminders that patients may wish to schedule an appointment and education on healthcare programs and services.

It also confirmed the information taken did not include clinical information, such as treatment, diagnosis, or condition, payment information, such as credit card or account numbers or sensitive information, such as passwords, driver’s licence or social security numbers.

Discussing the breach, Darren James, Senior Product Manager at Specops Software, said: “Once again, we see that globally healthcare organisations are a high-value target for cyber criminals. HCA claims they offer cyber security awareness education to their employees and vendors, but this once again proves that training needs to be reinforced by policy. All organisations can improve their security posture quickly by improving and enforcing their password policy so that it complies with NIST and HIPAA requirements. Implementing 2FA/MFA reduces the risk even further. Allegedly HCA was contacted by the hacker on the 4th July, and the data, including that of 11 million patients, was offered for sale on a forum on the 5th July. It appears that no ransomware was deployed in this breach, or that it may have been contained, as HCA’s operations do not appear to have been affected so this attack seems to be driven purely for financial gain.” 

Looking at how the breach could have happened, Etay Maor, Senior Director of Security Strategy at Cato Networks, commented; “’The breach could have resulted from sophisticated methods like phishing, malware, ransomware, or exploiting vulnerabilities in the healthcare provider’s security. However, without further details, it remains challenging to attribute the breach to a specific source or determine its exact nature,”  

Maor went on to discuss how; “Healthcare organisations must take immediate action to strengthen cybersecurity measures in light of this concerning incident involving a major breach of personal data held by HCA. This serves as a stark reminder of the potential consequences of lax data security, including financial losses, legal liabilities, and reputational damage. To regain and maintain the trust of customers and stakeholders, healthcare entities must prioritise data protection by implementing stringent privacy policies, investing in robust cybersecurity infrastructure, and conducting regular audits to identify vulnerabilities. Proactive measures like employee training, encryption technologies, and continuous system monitoring are essential for safeguarding sensitive data. Collaboration and information sharing among organisations are critical in mitigating risks and combating evolving cyber threats. This serves as a wake-up call for healthcare organisations to prioritise data security not just for regulatory compliance, but also to ensure the trust and confidence of customers in an interconnected and data-driven world.”

Javvad Malik, lead security awareness advocate at KnowBe4 agrees with Maor on the possibly way this breach happened, saying; “When we look at healthcare breaches, the three most common ways that data is breached is through social engineering such as phishing emails, or through employees not taking care of their passwords and credentials. Either by reusing passwords, leaving machines unlocked in public areas, or having passwords written down on post-it notes on monitors. The third way is by exploiting unpatched software. What all of this points to is the lack of an overall culture of security, in which cyber security is embedded throughout the organisation and each department and individual playing their part in ensuring the safety of the information.” 

HCA’s statement also mentioned that its ongoing investigation has not identified evidence of any malicious activity on HCA Healthcare networks or systems related to this incident. The company disabled user access to the storage location as an immediate containment measure and plans to contact any impacted patients to provide additional information and support. 

FacebookTweetLinkedIn
ShareTweet
Previous Post

Cyber Mindfulness Corner Company Spotlight: Exabeam

Next Post

Cato Networks Extends ZTNA to Protect Against Insider Threats

Recent News

Adarma Names James Todd as Chief Technology Officer, Reinforcing Dedication to Security Operations Excellence

Adarma Names James Todd as Chief Technology Officer, Reinforcing Dedication to Security Operations Excellence

September 25, 2023
Nurturing Our Cyber Talent

Nurturing Our Cyber Talent

September 25, 2023
The Journey to Secure Access Service Edge (SASE)

The Journey to Secure Access Service Edge (SASE)

September 22, 2023
WatchGuard

WatchGuard acquires CyGlass for AI-powered network anomaly detection

September 21, 2023

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2019 IT Security Guru - Website Managed by Calm Logic

  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2022
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2019 IT Security Guru - Website Managed by Calm Logic

This site uses functional cookies and external scripts to improve your experience.

Privacy settings

Privacy Settings / PENDING

This site uses functional cookies and external scripts to improve your experience. Which cookies and scripts are used and how they impact your visit is specified on the left. You may change your settings at any time. Your choices will not impact your visit.

NOTE: These settings will only apply to the browser and device you are currently using.

GDPR Compliance

Powered by Cookie Information