Feeds

'Chinese crims' snatch 4.5 MILLION patient files from US hospitals

Don't worry, says Community Health Systems, we're insured

Secure remote control for conventional and virtual desktops

One of the largest healthcare providers in the US claims Chinese hackers ran riot through its systems between April and June this year – accessing names, addresses and social security numbers of millions of patients.

But Community Health Systems (CHS) insists no medical records nor any financial data were grabbed by the miscreants. The biz oversees 206 hospitals in 29 states across America.

"Unfortunately, we have joined numerous American companies and institutions who have been victimized by highly sophisticated, criminal cyber-attacks originating out of China," CHS spokesperson Tomi Galin told The Register in a statement today.

"We worked quickly to identify and eradicate the intruder and we are also working closely with federal law enforcement authorities as they pursue the criminals responsible. While we did have security measures in place to protect our computer network and electronically stored information, this attacker used very sophisticated methods to bypass security systems.

"Importantly, no patient medical or financial information was transferred as a result of this intrusion. The company carries cyber and privacy liability insurance. We do not believe this incident will have a material adverse effect on our business or financial results."

According to an 8K filing [PDF] to US financial watchdog the Securities and Exchange Commission, the attackers were trying to get hold of medical device and equipment development data, but were prevented from grabbing it by the security systems the Fortune 500 company had in place.

What the hackers did get hold of was 4.5 million records detailing the names, addresses, birth dates, telephone numbers and social security numbers of patients who have used the hospital chain during the past five years. According to the filed paperwork:

The company and its forensic expert, Mandiant (a FireEye Company), believe the attacker was an “Advanced Persistent Threat” group originating from China who used highly sophisticated malware and technology to attack the company’s systems. The attacker was able to bypass the company’s security measures and successfully copy and transfer certain data outside the company.

All affected citizens are now being contacted, the hospital group said, and identity theft protection will be offered to those who are targeted from the data swiped from its servers. Since the hospital is insured against such attacks, the financial effects should be minimal, the 8K filing states, but that hasn't impressed some in the security industry.

"The unfortunate reality is that most (but not all) of the healthcare providers have little concern for nor have they invested in IT security. There is no incentive for them to invest, nor is there any material consequence of their failure to protect their infrastructure," said Philip Lieberman, president of password and identity management biz Lieberman Software.

"The funny postscript to this article is that Community Health's stock was up 48 cents at $51.48 in late-morning trading on the New York Stock Exchange, which could be translated to say that a data breach is good for the shareholders. That is how sick IT security is at health care providers."

Last year the Office of National Counterintelligence warned Congress that Chinese hackers and other miscreants are targeting American healthcare companies to get intellectual property pertaining to new drugs and medical equipment. It now appears those warnings were more accurate than first thought. ®

Remote control for virtualized desktops

More from The Register

next story
UK smart meters arrive in 2020. Hackers have ALREADY found a flaw
Energy summit bods warned of free energy bonanza
DRUPAL-OPCALYPSE! Devs say best assume your CMS is owned
SQLi hole was hit hard, fast, and before most admins knew it needed patching
Knock Knock tool makes a joke of Mac AV
Yes, we know Macs 'don't get viruses', but when they do this code'll spot 'em
Feds seek potential 'second Snowden' gov doc leaker – report
Hang on, Ed wasn't here when we compiled THIS document
Mozilla releases geolocating WiFi sniffer for Android
As if the civilians who never change access point passwords will ever opt out of this one
Why weasel words might not work for Whisper
CEO suspends editor but privacy questions remain
prev story

Whitepapers

Why and how to choose the right cloud vendor
The benefits of cloud-based storage in your processes. Eliminate onsite, disk-based backup and archiving in favor of cloud-based data protection.
A strategic approach to identity relationship management
ForgeRock commissioned Forrester to evaluate companies’ IAM practices and requirements when it comes to customer-facing scenarios versus employee-facing ones.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.
New hybrid storage solutions
Tackling data challenges through emerging hybrid storage solutions that enable optimum database performance whilst managing costs and increasingly large data stores.
The Heartbleed Bug: how to protect your business with Symantec
What happens when the next Heartbleed (or worse) comes along, and what can you do to weather another chapter in an all-too-familiar string of debilitating attacks?