News

Hackers steal data of millions of hospital patients nationwide

Hackers steal data of millions of hospital patients nationwide

COMMUNITY HEALTH: The stolen information included patient names, addresses, birth dates, telephone numbers and Social Security numbers of people who were referred for or received services from doctors affiliated with the hospital group in the last five years, it said in a regulatory filing on Monday. Photo: clipart.com

(Reuters) – Community Health Systems Inc, one of the biggest U.S. hospital groups, said it was the victim of a cyber attack that originated in China, resulting in the theft of personal data belonging to 4.5 million patients in April and June.

The stolen information included patient names, addresses, birth dates, telephone numbers and Social Security numbers of people who were referred for or received services from doctors affiliated with the hospital group in the last five years, it said in a regulatory filing on Monday.

Community Health Systems spokeswoman Tomi Galin said the company believes the attack originated from China because federal law enforcement and forensics experts with FireEye Inc unit Mandiant had told it that “the methods and techniques” employed by the hackers were consistent with a particular group of hackers operating in China.

Galin did not identify the group by name or say if it was believed to be linked to the Chinese government.

In May, a U.S. grand jury indicted five Chinese military officers on charges that they hacked into U.S. companies for sensitive manufacturing secrets, the toughest action taken by Washington to address cyber spying to date. China has denied the charges.

Community Health Systems said in the regulatory filing investigators have told it that the Chinese group believed to be behind the attack typically seeks valuable intellectual property, such as medical device and equipment development data, rather than the personal information stolen from the hospital group.

Galin told Reuters that the suspects had not stolen that type of information.

Officials with Mandiant could not immediately be reached for comment. FBI spokesman Joshua Campbell confirmed that the agency was investigating the case, but declined to elaborate.

The company’s filing said that the stolen data did not include credit card numbers, medical or clinical information, though the types of personal information stolen were still covered by the U.S. government’s Health Insurance Portability and Accountability Act, or HIPAA.

The FBI had warned healthcare providers in April that their cybersecurity systems were lax compared with other sectors, making them vulnerable to hackers looking for details that could be used to access bank accounts or obtain prescriptions.

Community Health, which has 206 hospitals in 29 states, said it has removed the malware from its systems and completed other remediation steps. It is now notifying patients and regulatory agencies as required by law.

It also said it is insured against such losses and does not at this time expect a material adverse effect on financial results.

Community Health’s stock was up 48 cents at $51.48 in late-morning trading on the New York Stock Exchange.

(Reporting by Caroline Humer, Jim Finkle and Shailesh Kuber; Editing by Joyjeet Das, Lisa Von Ahn, Chizu Nomiyama and Dan Grebler)

Recent Headlines

2 hours ago in Sports

Reigning NL batting champ banned 80 games for doping

Fresh
marlinsdeeREUTERS

Dee Gordon of the Miami Marlins was suspended 80 games without pay after testing positive for a performance-enhancing substance, Major League Baseball said.

6 hours ago in National

Teen pregnancies hit historic low

sexed296416402183

The annual survey shows the continuation of a downward trend that began in 2006 and continued through 2014, the latest year of complete data, when nearly 250,000 babies were born to girls and women aged 15 to 19.

6 hours ago in Sports

Watch Richard Sherman pick up unsuspecting passengers

20-overlay-14

The Seattle Seahawks Super Bowl winner takes a side gig as a driver for Lyft.

6 hours ago in Sports

NFL: Raiders hope to move to Vegas

markdavisraiders16119669574354

Raiders owner Mark Davis says he wants to move the team to Las Vegas and is willing to spend a half billion dollars as part of a deal for a new stadium in the city.

7 hours ago in National

U.S. high court approves rule change to expand FBI hacking power

A lock icon, signifying an encrypted Internet connection, is seen on an Internet Explorer browser in a photo illustration in Paris in this April 15, 2014 file photo.

The Supreme Court on Thursday approved a rule change that would let U.S. judges issue search warrants for access to computers located in any jurisdiction despite opposition from civil liberties groups who say it will greatly expand the FBI's hacking authority.