Boston Children's physician group suffers data breach

Boston Children’s Health Physicians notified patients and the public of a Sept. 6 data breach of its systems, caused by an IT vendor. The multispecialty group said in a statement that it immediately deployed cyberattack response protocols once it became aware of the incident. 

The unnamed IT vendor alerted Boston Children’s to suspicious network activity, after which an investigation showed an unauthorized third party had gained access to systems and stolen data files. 

The information taken included the names, dates of birth, Social Security numbers, insurance and billing information, driver’s license numbers, and medical record numbers from employees and patients. However, the electronic health record was not breached, meaning clinical data on patients was not stolen, Boston Children’s said. 

Hacker group BrianLian claimed responsibility for the attack on a dark web forum, where the data is likely to be put up for sale. 

BianLian has claimed responsibility for 60 ransomware incidents so far this year, data from Comapritech shows. However, there is no evidence ransomware was deployed in the breach at Boston Children’s. 

The physician group said it worked with a cyber forensics agency to investigate the attack. That investigation appears to now be concluded, as Boston Children’s started sending letters to impacted patients on Oct 4. 

The full cybersecurity incident announcement can be found here.

Chad Van Alstin Health Imaging Health Exec

Chad is an award-winning writer and editor with over 15 years of experience working in media. He has a decade-long professional background in healthcare, working as a writer and in public relations.

Around the web

“Now more than ever, we must recognize that our country’s leadership in groundbreaking medical research spurs scientific innovation, improves public health and creates new innovations that save and improve lives nationwide,” Joseph C. Wu, MD, PhD, explained in a statement. 

The technology used to diagnose, treat and manage cardiovascular disease is always evolving, keeping FDA officials quite busy. But have the agency's standards been slipping in recent years? A cardiologist with Cedars-Sinai Medical Center explored that very question.

No devices need to be returned at this time. However, the FDA warned, using these heart pumps without reviewing the updated instructions could result in "serious injury or death.”