AdaptHealth discloses June cyberattack resulting in patient data exposure

1 month ago 23

AdaptHealth has revealed it was deed by a cyberattack resulting successful information exfiltration past month, yet stressed that captious lawsuit information specified arsenic outgo paper accusation was not compromised by the breach.

In a Form 8-K filed with the US Securities and Exchange Commission (SEC) connected 2 July, the supplier of home-based aesculapian devices including continuous affirmative airway unit (CPAP) machines said a menace histrion reached retired connected 15 June, claiming to person obtained definite information from AdaptHealth's systems.

AdaptHealth confirmed that a breach had occurred, resulting successful the vulnerability of diligent data, including stored password files associated with security billing mandates and definite personally identifiable and protected wellness accusation (PHI). The cyber attacker had gained entree done the company's cloud-based applications, including definite diligent absorption and papers retention platforms.

By 27 June, AdaptHealth determined the incidental 'material', fixed its quality and the imaginable measurement of information placed astatine risk.

The Pennsylvania-based institution stressed, however, that nary Social Security numbers oregon idiosyncratic fiscal relationship oregon outgo paper accusation of its customers had been exposed, fixed that nary specified accusation was stored wrong the systems.

Offering much details, AdaptHealth shared that since becoming alert of the cyberattack, it had discovered that the incidental was the effect of a 'successful societal engineering attack' that compromised a idiosyncratic league associated with a third-party contractor.

Following detection, AdaptHealth promptly implemented containment measures, including disabling the compromised idiosyncratic account, resetting affected credentials, and implementing further entree controls, and the incidental has been contained, the institution stated.

While the afloat scope of affected datasets has not yet been determined, AdaptHealth concluded the Form 8-K by stating that it is continuing to analyse the quality and scope of the incidental and taking steps to mitigate the hazard of immoderate exfiltrated data's dissemination.

AdaptHealth's breach is the latest successful a maelstrom of cyberattacks that person impacted companies operating successful the healthcare abstraction successful caller months. Medtronic was impacted by a cyber breach comparable to AdaptHealth's successful April, portion Stryker was deed by an Iran-linked cyberattack successful March that caused wide disruption to its operations.

"AdaptHealth discloses June cyberattack resulting successful diligent information exposure" was primitively created and published by Medical Device Network, a GlobalData owned brand.

Read Entire Article