Nearly 50,000 AdventHealth Patients Impacted in Yearlong Data Breach

Nearly 50,000 AdventHealth Patients Impacted in Yearlong Data Breach

AdventHealth's system was breached for over a year, impacting 42,000 patients and their data.

Nearly 50,000 AdventHealth Medical Group Pulmonary and Sleep Medicine patents are being notified that their personal and health information was breached for more than a year due to a hack of the Florida provider's systems.

On December 27, 2018, officials of the provider discovered a hacker gained access to the AdventHealth systems beginning in August 2017 — more than 16 months earlier. 

The breached data of 42,000 patients contained troves of personal and health data, including medical histories, insurance carriers, Social Security numbers and some demographic information like names, phone numbers and email addresses. 

AdventHealth said that any patient who's information was made vulnerable will receive a year of free identity monitoring services. The company also said it has since improved its processes to bolder its auditing and system safeguards. 

“While the longstanding focus of attackers has been financial data from retail, e-commerce, and financial services sectors, the untapped trove of personal data are a series of softer targets such as localities, social services, and healthcare," Warren Poschman, senior solutions architect at comforte AG said. "Not only are these systems just as rich with data as the traditional targets but security often lags due to the focus on, in the case of healthcare, patient care over IT."

Poschman said AdventHealth had a series of perimeter and intrusion security measures but none of those security measures ultimately detected a 16-month long breach.

"Similar to Equifax and other long-term breaches, data was accessed and likely exfiltrated because it was stored in the clear or protected by passive means such as volume level encryption or database encryption," Poschman said. "Therein lies the issue – attackers went undetected because the perimeter was breached and once inside there was nothing substantial to stop the attackers from accessing the real target, their patient data. Instead of focusing solely on the perimeter and network levels, healthcare providers are highly advised to implement strong data protection strategies that deal with the eventuality of attackers gaining some level of access to a network – after all, it’s the data that the attackers are after, not the firewalls, servers, and other infrastructure."

Poschman suggests that companies dealing with healthcare data adopt a data-centric security model that allows for the data to be protected as it is acquired and traverses through the organization. If an attacker gains access through the perimeter, then the risk that the actual personal data will be exposed is dramatically reduced, because of this high amount of security.


About the Author

Sydny Shepard is the Executive Editor of Campus Security & Life Safety.

Featured

  • UL Solutions Launches Artificial Intelligence Safety Certification Services

    UL Solutions Inc., a global leader in safety science, today announced the launch of artificial intelligence (AI) safety certification services, enabling comprehensive assessments for evaluating the safety of AI-powered products. Read Now

  • ESA Announces Initiative to Introduce the SECURE Act in State Legislatures

    The Electronic Security Association (ESA), the national voice for the electronic security and life safety industry, has announced plans to introduce the SECURE Act in state legislatures across the country beginning in 2025. The proposal, known as Safeguarding Election Candidates Using Reasonable Expenditures, provides a clear framework that allows candidates and elected officials to use campaign funds for professional security services. Read Now

    • Guard Services
  • Ransomware Attacks Rise for the First Time in Six Months

    Ransomware attacks have risen for the first time in six months, increasing by 28% month-on-month to 421 attacks. While overall attack volume remained below 500, the uptick may signal a renewed escalation heading into the year’s most active period for cyber criminals. Read Now

  • Report: 47 Percent of Security Service Providers Are Not Yet Using AI or Automation Tools

    Trackforce, a provider of security workforce management platforms, today announced the launch of its 2025 Physical Security Operations Benchmark Report, an industry-first study that benchmarks both private security service providers and corporate security teams side by side. Based on a survey of over 300 security professionals across the globe, the report provides a comprehensive look at the state of physical security operations. Read Now

    • Guard Services
  • Identity Governance at the Crossroads of Complexity and Scale

    Modern enterprises are grappling with an increasing number of identities, both human and machine, across an ever-growing number of systems. They must also deal with increased operational demands, including faster onboarding, more scalable models, and tighter security enforcement. Navigating these ever-growing challenges with speed and accuracy requires a new approach to identity governance that is built for the future enterprise. Read Now

New Products

  • Automatic Systems V07

    Automatic Systems V07

    Automatic Systems, an industry-leading manufacturer of pedestrian and vehicle secure entrance control access systems, is pleased to announce the release of its groundbreaking V07 software. The V07 software update is designed specifically to address cybersecurity concerns and will ensure the integrity and confidentiality of Automatic Systems applications. With the new V07 software, updates will be delivered by means of an encrypted file.

  • Luma x20

    Luma x20

    Snap One has announced its popular Luma x20 family of surveillance products now offers even greater security and privacy for home and business owners across the globe by giving them full control over integrators’ system access to view live and recorded video. According to Snap One Product Manager Derek Webb, the new “customer handoff” feature provides enhanced user control after initial installation, allowing the owners to have total privacy while also making it easy to reinstate integrator access when maintenance or assistance is required. This new feature is now available to all Luma x20 users globally. “The Luma x20 family of surveillance solutions provides excellent image and audio capture, and with the new customer handoff feature, it now offers absolute privacy for camera feeds and recordings,” Webb said. “With notifications and integrator access controlled through the powerful OvrC remote system management platform, it’s easy for integrators to give their clients full control of their footage and then to get temporary access from the client for any troubleshooting needs.”

  • AC Nio

    AC Nio

    Aiphone, a leading international manufacturer of intercom, access control, and emergency communication products, has introduced the AC Nio, its access control management software, an important addition to its new line of access control solutions.