Medical equipment supplier’s cloud applications breached, leaking patient data to hackers
Last week, nationwide medical equipment group AdaptHealth revealed it was hit by a cyberattack that resulted in data from its customers being stolen by hackers. The data breach was revealed in a notice filed with the Securities and Exchange Commission (SEC) on July 2.
In the letter, AdaptHealth said it was still investigating the incident, presumed to involve its “cloud-based business applications,” mainly those used for the storage and management of documents pertaining to the patients it services with medical devices.
The date of the data breach was not confirmed, but the company said it was able to determine—as early as June 27—that the hack “incident is material,” meaning that it is considered significant enough to warrant disclosing to the public, so investors can assess the situation for themselves.
AdaptHealth said the “nature and potential volume of the data that is at risk” led it to making this determination.
As for how the breach happened, the company believes it stemmed from a “social engineering attack that compromised a user session associated with a third-party contractor."
That means one of its technology partners may be the complete source of the unauthorized intrusion, though the vendor was not named.
Accessed data was determined to have been moved offsite, and it includes information from electronic health record portals that integrate with AdaptHealth. Compromised data includes “passwords associated with insurance billing and certain personally identifiable information and protected health information of patients,” the company stated.
It added that Social Security numbers were not part of the swiped data trove, nor was any financial account information, such as credit card numbers. As for what precisely was taken, and what the number of victims may be, AdaptHealth said those details are still being looked into. Any more specifics are simply not yet available, and won’t be made public until an investigation is complete.
The medical equipment group said it’s working with a third-party cybersecurity firm to determine the scope of the breach. If protected health information was indeed stolen, AdaptHealth may be on the hook for notifying all victims, as required by the Health Insurance Portability and Accountability Act (HIPAA).
As for the impact all of the above may have on its business operations, AdaptHealth said it cannot yet make that determination; however, it did acknowledge that the cyberattack could carry “remediation and response costs, legal, regulatory and notification-related matters, and possible effects on patients, counterparties and the company’s reputation,” that could negatively impact its bottom line.
Held for ransom?
AdaptHealth supplies all kinds of medical devices through its network, working with a variety of manufacturers and developers. It sells CPAP machines, glucose monitors, insulin pumps, ventilators and more—mostly in service of the home-care market.
No data trove from the hack has been discovered on the dark web, but AdaptHealth said it was approached by a nefarious actor claiming to have its data—something seen commonly, where criminals will seek a ransom, promising to delete the trove.
Such a scenario may indicate ransomware as part of the attack, but that has yet to be confirmed.
HealthExec reached out to the company for more information.
