{"id":835790,"date":"2025-03-21T14:12:01","date_gmt":"2025-03-21T19:12:01","guid":{"rendered":"https:\/\/newsycanuse.com\/index.php\/2025\/03\/21\/us-healthcare-provider-data-breach-impacts-1-million-patients\/"},"modified":"2025-03-21T14:12:01","modified_gmt":"2025-03-21T19:12:01","slug":"us-healthcare-provider-data-breach-impacts-1-million-patients","status":"publish","type":"post","link":"https:\/\/newsycanuse.com\/index.php\/2025\/03\/21\/us-healthcare-provider-data-breach-impacts-1-million-patients\/","title":{"rendered":"US healthcare provider data breach impacts 1 million patients"},"content":{"rendered":"<div>\n<p><img loading=\"lazy\" decoding=\"async\" alt=\"Hospital\" height=\"900\" src=\"https:\/\/www.bleepstatic.com\/content\/hl-images\/2024\/09\/18\/Hospital.jpg\" width=\"1600\"><\/p>\n<p>Community Health Center (CHC), a leading Connecticut healthcare provider, is notifying over 1 million patients of a data breach that impacted their personal and health data.<\/p>\n<p>The non-profit organization provides primary medical, dental, and mental health services to more than 145,000 active patients.<\/p>\n<p>CHC said in a Thursday <a href=\"https:\/\/www.maine.gov\/agviewer\/content\/ag\/985235c7-cb95-4be2-8792-a1252b4f8318\/ef9efbea-06fa-4d12-814a-40c6e4456e72.html\" target=\"_blank\" rel=\"nofollow noopener\">filing with Maine&#8217;s attorney general<\/a> that unknown attackers gained access to its network in mid-October 2024, a breach discovered more than two months later, on January 2, 2025.<\/p>\n<p>While the threat actors stole files containing patients&#8217; personal and health information belonging to 1,060,936 individuals, the healthcare organization says they didn&#8217;t encrypt any compromised systems and that the security breach didn&#8217;t impact its operations.<\/p>\n<p>Investigators hired to assess the incident&#8217;s impact and secure CHC&#8217;s systems found that &#8220;a skilled criminal hacker&#8221; was behind the attack.<\/p>\n<p>&#8220;Fortunately, the criminal hacker did not delete or lock any of our data, and the criminal&#8217;s activity did not affect our daily operations. We believe we stopped the criminal hacker&#8217;s access within hours, and that there is no current threat to our systems,&#8221; CHC added.<\/p>\n<p>Depending on the affected individuals, <a href=\"https:\/\/response.idx.us\/CommunityHealthCenter\/\" target=\"_blank\" rel=\"nofollow noopener\">including<\/a> &#8220;current and former patients and all individuals who received a COVID test or vaccine at a CHC clinic,&#8221; the attackers stole a combination of:<\/p>\n<ul>\n<li>personal (names, dates of birth, addresses, phone numbers, emails, Social Security numbers) or<\/li>\n<li>health information (medical diagnoses, treatment details, test results, and health insurance.<\/li>\n<\/ul>\n<p>A CHC spokesperson was not immediately available when BleepingComputer reached out for more details on the incident.<\/p>\n<p>While CHC said the hackers didn&#8217;t encrypt any of its systems, more ransomware operations have switched tactics to become data theft extortion groups in recent years.<\/p>\n<p><span>For instance, the BianLian ransomware gang <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/bianlian-ransomware-gang-shifts-focus-to-pure-data-extortion\/\" target=\"_blank\" rel=\"nofollow noopener\">gradually abandoned file encryption<\/a> after Avast <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/avast-releases-free-bianlian-ransomware-decryptor\/\" target=\"_blank\" rel=\"nofollow noopener\">released a free decryptor<\/a> in January 2023. A <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/cisa-says-bianlian-ransomware-now-focuses-only-on-data-theft\/\" target=\"_blank\" rel=\"nofollow noopener\">joint advisory<\/a> issued by CISA, the FBI, and the Australian Cyber Security Centre also confirmed this in November 2024.<\/span><\/p>\n<p>This week, the New York Blood Center (NYBC), one of the world&#8217;s largest independent blood collection and distribution organizations, also disclosed that a Sunday ransomware attack <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/ransomware-attack-disrupts-new-york-blood-donation-giant\/\" target=\"_blank\" rel=\"nofollow noopener\">forced it to reschedule some appointments<\/a>.<\/p>\n<p>Over the weekend, UnitedHealth also\u00a0<span>revealed that\u00a0<a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/unitedhealth-now-says-190-million-impacted-by-2024-data-breach\/\" target=\"_blank\" rel=\"nofollow noopener\">roughly 190 million Americans<\/a>\u00a0had their personal and healthcare data stolen in last year&#8217;s Change Healthcare ransomware attack, nearly\u00a0<a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/unitedhealth-says-data-of-100-million-stolen-in-change-healthcare-breach\/\" target=\"_blank\" rel=\"nofollow noopener\">doubling the\u00a0<\/a><\/span><a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/unitedhealth-says-data-of-100-million-stolen-in-change-healthcare-breach\/\" target=\"_blank\" rel=\"nofollow noopener\">figure of 100 million<\/a> disclosed in October.<\/p>\n<p>In response to this surge of massive healthcare security breaches, the U.S. Department of Health and Human Services (HHS) <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/massive-healthcare-breaches-prompt-us-cybersecurity-rules-overhaul\/\" rel=\"nofollow noopener\" target=\"_blank\">proposed updates to HIPAA<\/a> (short for Health Insurance Portability and Accountability Act of 1996) in late December to secure patients&#8217; health data.<\/p>\n<div>\n<p><a href=\"https:\/\/hubs.li\/Q039Tm490\" target=\"_blank\" rel=\"noopener sponsored\"><br \/>\n            <img decoding=\"async\" src=\"https:\/\/www.bleepstatic.com\/c\/p\/picus\/red-report-in-article.jpg\" alt=\"Red Report 2025\"><br \/>\n        <\/a>\n    <\/p>\n<\/div><\/div>\n<p> Sergiu Gatlan <br \/><a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/data-breach-at-us-healthcare-provider-chc-impacts-1-million-patients\/\" class=\"button purchase\" rel=\"nofollow noopener\" target=\"_blank\">Read More<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Community Health Center (CHC), a leading Connecticut healthcare provider, is notifying over 1 million patients of a data breach that impacted their personal and health data. The non-profit organization provides primary medical, dental, and mental health services to more than 145,000 active patients. CHC said in a Thursday filing with Maine&#8217;s attorney general that unknown<\/p>\n","protected":false},"author":1,"featured_media":835791,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[82,22468],"tags":[5572,46427],"class_list":{"0":"post-835790","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-healthcare","8":"category-provider","9":"tag-healthcare","10":"tag-provider"},"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/posts\/835790","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/comments?post=835790"}],"version-history":[{"count":0,"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/posts\/835790\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/media\/835791"}],"wp:attachment":[{"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/media?parent=835790"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/categories?post=835790"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/tags?post=835790"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}