Canadian health systems recovering from breach that forced thousands of appointment cancellations
Full article796 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
Attackers caused outages that lasted more than a week, though details have been scant.
Intruders accessed patient and employee data after infiltrating health-related IT systems in a breach that’s only now coming into focus.
A security incident affecting the province of Newfoundland and Labrador, first detected Oct. 30, took down multiple health networks, leading to the cancellation of thousands of appointments, including for chemotherapy treatments. The regional Eastern Health authority, which employees 13,000 people, only Thursday announced that its email system was again functioning.
“As part of the on-going investigation into a cyberattack that impacted health care IT systems in Newfoundland and Labrador, it has been determined that some personal information and personal health information was accessed from the systems,” the provincial government said in a Nov. 9 news release. “A review is ongoing to determine if any other information is affected in the incident and further updates will be provided as appropriate.”
Hackers obtained access to 14 years’ worth of information on current and former Eastern Health patients and employees, and nine years’ worth for Labrador Grenfell Health. Patient information includes name, address, health care number, reason for visit, their doctor and birth date. Employee information may include names, addresses, contact information and Social Insurance numbers, which are similar to U.S. Social Security numbers.
Canadian government officials have not said who is suspected in the latest incident, or whether ransomware was involved.
Attacks on health care have long been among the most urgent in cyberspace, given the potential life and death consequences of the sector going offline. A lawsuit in September alleged that a ransomware incident caused the death of an infant at an Alabama hospital. Meanwhile, at least one ransomware gang has specifically targeted hospitals, expecting them to be more likely to pay quickly given the risks.
In the U.S., the Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency on Tuesday issued an alert about software flaws potentially affecting thousands of medical devices.
More Scoops
Bipartisan health care cybersecurity legislation returns to address a cornucopia of issues
The bill, first introduced late last year, deals with regulations, training, grants and more.
Trump bill will have major impact on health care cybersecurity, experts warn Congress
How HHS has strengthened cybersecurity of hospitals and health care systems
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Chinese espionage groups swarm to exploit triple-link chain of zero-days
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/newfoundland-labrador-canada-cyberattack-health-it-systems/