drj logo
  • This field is for validation purposes and should be left unchanged.

Already have an account? Log in

drj logo

Welcome to DRJ

Already registered user? Please login here

Login Form

Register
Forgot password? Click here to reset

Create new account
(it's completely free). Subscribe

Skip to content
Disaster Recovery Journal
  • EN ESPAÑOL
  • SIGN IN
  • SUBSCRIBE
  • THE JOURNAL
    • Digital Edition
    • Article Submission
    • DRJ Annual Resource Directories
    • Article Archives
    • Career Spotlight
  • EVENTS
    • DRJ Spring 2023
    • DRJ Fall 2023
    • Other Industry Events
    • Schedule & Archive
  • WEBINARS
    • Upcoming Webinars
    • On Demand
  • MENTOR PROGRAM
  • DRJ ACADEMY
    • DRJ Academy
    • Beginner’s Guide to BC
  • RESOURCES
    • New to Business Continuity?
    • White Papers
    • DR Rules and Regs
    • Planning Groups
    • Business Directory
    • Business Resilience Decoded
    • DRJ Glossary of Business Continuity Terms
    • Careers
  • ABOUT
    • Advertise with DRJ
    • DE&I
    • Board and Committees
      • Executive Council Members
      • Editorial Advisory Board
      • Career Development Committee
      • Glossary Committee
      • Rules and Regulations Committee
  • Podcast

Breach of Healthcare Debt Collection Firm Exposes 1.9M Patients; Cyber Experts Weigh in

by Jon Seals | July 14, 2022 | | 0 comments

More than 1.9 million patients have been exposed to a ransomware infection after a Colorado-based debt collection firm serving hundreds of medical facilities and hospitals across America was breached. 

The Professional Finance Company, PFC, suffered a ransomware attack on February 26 and on July 1 confirmed that over 650 healthcare providers were affected by the breach. According to a notice from PFC, attackers stole confidential patient information including patient names, addresses, and outstanding account balances. PFC said in some cases, SSNs and information about health insurance and medical treatment were also stolen. 

This attack was a result of an unauthorized third party using sophisticated ransomware to gain access and disable internal computer systems to retrieve personal data. PFC said that after the attack, they immediately hired third-party forensic specialists and alerted federal law enforcement. PFC also said they found no substantial evidence that personal information has been misused, however, it is possible the data can be used to launch future attacks. 

As ransomware attacks continue to affect all types of organizations, it’s important to learn from the mistakes of other companies and protect your information. We’ve spoken with several cybersecurity experts to hear their insights about this breach.

Arti Raman (She/Her), CEO and Founder, Titaniam

“In the recent data breach confirmed by PFC, an unauthorized third party accessed and disabled some of PFC’s computer systems. While the company’s statement said that none of the personal data had been misused, the data is now in the hands of cybercriminals. As hacks and extortion become more and more frequent, to truly minimize the risk of potential extortion and lost clear text data, a data security platform, specifically data-in-use encryption, also referred to as encryption-in-use, is the only option for complete protection and peace of mind.

In the last 18 months, companies have been misled into believing that investing in backup and recovery solutions is the answer to their ransomware woes. However, the State of Data Exfiltration & Extortion Report 2022 recently revealed that traditionally used tools are ineffective 60% of the time.

If companies want to stand up to data-related extortion then data-in-use encryption is the technology of choice for unmatched immunity. Should adversaries gain access to data, by any means, data-in-use encryption keeps the sensitive data encrypted and protected even when it is being actively utilized. This helps neutralize all possible data-related leverage and limits the need for breach disclosure.”

Neil Jones, director of cybersecurity evangelism, Egnyte

“The recent data breach at Professional Finance Company is especially concerning because healthcare debt collection information inherently includes PII (Personally Identifiable Information) and PHI (Protected Health Information), which are treasure troves for cyber-attackers. 

In this case, the breach involved the sensitive data of nearly 2 million patients. Although there’s no current evidence that the breached information has been used maliciously, it is not uncommon for attackers to wait for just the right moment to post their breached data to the Web. 

There are several key lessons that can be learned from this incident: 1) Organizations need to combine ransomware detection solutions with effective data recovery programs. 2) Companies need to have incident response plans in place, to effectively notify their customers, employees, business partners and the news media of potential breaches. 3) During these dynamic times, routine technological audits need to occur on a more frequent basis than they did before, to prevent vulnerabilities from being exploited.”

Aaron Sandeen, CEO and co-founder, Cyber Security Works 

As ransomware attacks continue to devastate the healthcare industry, leaders must increase their cybersecurity visibility of known and unknown assets. To fully safeguard their firm from potential assaults, cybersecurity professionals must enhance the frequency with which they validate and seek early warning capabilities.

Patching the vulnerabilities that threat groups and attackers exploit is one of the actions that businesses can take to avoid disaster. Especially as new ransomware organizations develop, knowing how exposed you are to ransomware attacks and monitoring your security posture through ongoing vulnerability management and proactive penetration testing is vital to bolster your defenses. Security and executives in the healthcare field must invest in the protection of their assets.

Tim Prendergrast, CEO, strongDM

“The PFC incident highlights how crucial strong access management and infrastructure are to maintain strong security. Right now, attackers are increasingly looking for improperly stored or secured valid credentials because they’re essentially VIP passes into databases, and servers – everything companies don’t want to be leaked publicly. Once attackers get those valid credentials, they can wreak havoc internally. As a result, we’re now seeing maybe one of the worst healthcare security breaches in 2022 that’s impacting over one million people and whole hospitals, and it’s because of a third-party access breach. Rather than point fingers, because in truth this could have happened to anyone, it is important for CISOs to re-evaluate the visibility and control of access across both applications and infrastructure.”

Related Content

  1. Disaster Recovery Journal
    Forecast for Healthcare: Prepare for Data Breach Spike
  2. Disaster Recovery Journal
    How Digital Cloud Fax Technology Can Eliminate Potential PHI Breach Pitfalls
  3. Disaster Recovery Journal
    DRJ Fall 2018 Q&A

Recent Posts

Kudelski IoT Launches Matter Certificate Authority and Broad Security Portfolio for Manufacturers

February 7, 2023

Lumenore Enters into Strategic Partnership with iQ Innovation Hub LLP

February 7, 2023

Kahuna Solidifies its Place in the Skills Tech Market with Operational Skilling

February 7, 2023

Archer Announces Acquisition of Atlas to Expand Policy Management Capabilities

February 7, 2023

Daon Expands Senior Leadership Team to Scale Its Business into New Markets

February 7, 2023

Pacific Office Automation Announced 2022 Revenue of $421 Million

February 7, 2023

Archives

  • February 2023 (337)
  • January 2023 (1391)
  • December 2022 (1144)
  • November 2022 (1595)
  • October 2022 (1574)
  • September 2022 (1571)
  • August 2022 (1581)
  • July 2022 (1365)
  • June 2022 (1711)
  • May 2022 (1651)
  • April 2022 (1618)
  • March 2022 (1924)
  • February 2022 (1549)
  • January 2022 (1472)
  • December 2021 (1446)
  • November 2021 (1835)
  • October 2021 (1777)
  • September 2021 (1697)
  • August 2021 (1661)
  • July 2021 (1566)
  • June 2021 (1768)
  • May 2021 (1666)
  • April 2021 (1798)
  • March 2021 (1907)
  • February 2021 (1038)
  • January 2021 (554)
  • December 2020 (30)
  • November 2020 (35)
  • October 2020 (48)
  • September 2020 (57)
  • August 2020 (52)
  • July 2020 (40)
  • June 2020 (72)
  • May 2020 (46)
  • April 2020 (59)
  • March 2020 (46)
  • February 2020 (28)
  • January 2020 (36)
  • December 2019 (22)
  • November 2019 (11)
  • October 2019 (36)
  • September 2019 (44)
  • August 2019 (77)
  • July 2019 (117)
  • June 2019 (106)
  • May 2019 (49)
  • April 2019 (47)
  • March 2019 (24)
  • February 2019 (37)
  • January 2019 (12)
  • ARTICLES & NEWS

    • Business Continuity
    • Disaster Recovery
    • Crisis Management & Communications
    • Risk Management
    • Article Archives
    • Industry News

    THE JOURNAL

    • Digital Edition
    • Advertising & Media Kit
    • Submit an Article
    • Career Spotlight

    RESOURCES

    • White Papers
    • Rules & Regulations
    • FAQs
    • Glossary of Terms
    • Industry Groups
    • Business & Resource Directory
    • Business Resilience Decoded
    • Careers

    EVENTS

    • Spring 2023

    WEBINARS

    • Watch Now
    • Upcoming

    CONTACT

    • Article Submission
    • Media Kit
    • Contact Us

    ABOUT DRJ

    Disaster Recovery Journal is the industry’s largest resource for business continuity, disaster recovery, crisis management, and risk management, reaching a global network of more than 138,000 professionals. Offering weekly webinars, the latest industry news, rules and regulations, podcasts, the industry’s only official mentoring program, a quarterly magazine, and two annual live conferences, DRJ is leading the way to keep professionals up-to-date and connected in an ever-changing world.

    LEARN MORE

    TWITTER

    Disaster Recovery Journal is the leading publication/event covering business continuity/disaster recovery.

    Follow us for daily updates @drjournal

    Newsletter

    The Journal, right in your inbox.

    Be informed and stay connected by getting the latest in news, events, webinars and whitepapers on Business Continuity and Disaster Recovery.

    Subscribe Now
    Copyright 2023 Disater Recovery Journal
    • Terms of Use
    • Privacy Policy