Nearly 50,000 AdventHealth Patients Impacted in Yearlong Data Breach

Nearly 50,000 AdventHealth Patients Impacted in Yearlong Data Breach

AdventHealth's system was breached for over a year, impacting 42,000 patients and their data.

Nearly 50,000 AdventHealth Medical Group Pulmonary and Sleep Medicine patents are being notified that their personal and health information was breached for more than a year due to a hack of the Florida provider's systems.

On December 27, 2018, officials of the provider discovered a hacker gained access to the AdventHealth systems beginning in August 2017 — more than 16 months earlier. 

The breached data of 42,000 patients contained troves of personal and health data, including medical histories, insurance carriers, Social Security numbers and some demographic information like names, phone numbers and email addresses. 

AdventHealth said that any patient who's information was made vulnerable will receive a year of free identity monitoring services. The company also said it has since improved its processes to bolder its auditing and system safeguards. 

“While the longstanding focus of attackers has been financial data from retail, e-commerce, and financial services sectors, the untapped trove of personal data are a series of softer targets such as localities, social services, and healthcare," Warren Poschman, senior solutions architect at comforte AG said. "Not only are these systems just as rich with data as the traditional targets but security often lags due to the focus on, in the case of healthcare, patient care over IT."

Poschman said AdventHealth had a series of perimeter and intrusion security measures but none of those security measures ultimately detected a 16-month long breach.

"Similar to Equifax and other long-term breaches, data was accessed and likely exfiltrated because it was stored in the clear or protected by passive means such as volume level encryption or database encryption," Poschman said. "Therein lies the issue – attackers went undetected because the perimeter was breached and once inside there was nothing substantial to stop the attackers from accessing the real target, their patient data. Instead of focusing solely on the perimeter and network levels, healthcare providers are highly advised to implement strong data protection strategies that deal with the eventuality of attackers gaining some level of access to a network – after all, it’s the data that the attackers are after, not the firewalls, servers, and other infrastructure."

Poschman suggests that companies dealing with healthcare data adopt a data-centric security model that allows for the data to be protected as it is acquired and traverses through the organization. If an attacker gains access through the perimeter, then the risk that the actual personal data will be exposed is dramatically reduced, because of this high amount of security.


About the Author

Sydny Shepard is the Executive Editor of Campus Security & Life Safety.

Featured

  • The Future is Happening Outside the Cloud

    For years, the cloud has captivated the physical security industry. And for good reason. Remote access, elastic scalability and simplified maintenance reshaped how we think about deploying and managing systems. But as the number of cameras grows and resolutions push from HD to 4K and beyond, the cloud’s limits are becoming unavoidable. Bandwidth bottlenecks. Latency lags. Rising storage costs. These are not abstract concerns. Read Now

  • The Impact of Convergence Between IT and Physical Security

    For years, the worlds of physical security and information technology (IT) remained separate. While they shared common goals and interests, they often worked in silos. Read Now

  • Unlocking Trustworthy AI: Building Transparency in Security Governance

    In situations where AI supports important security tasks like leading investigations and detecting threats and anomalies, transparency is essential. When an incident occurs, investigators must trace the logic behind each automated response to confirm its validity or spot errors. Demanding interpretable AI turns opaque “black boxes” into accountable partners that enhance, rather than compromise, organizational defense. Read Now

  • Seeking Innovative Solutions

    Denial, Anger, Bargaining, Depression and Acceptance. You may recognize these terms as the “5 Phases” of a grieving process, but they could easily describe the phases one goes through before adopting any new or emerging innovation or technology, especially in a highly risk-averse industry like security. However, the desire for convenience in all aspects of modern life is finally beginning to turn the tide from old school hardware as the go-to towards more user-friendly, yet still secure, door solutions. Read Now

  • Where AI Meets Human Judgment

    Artificial intelligence is everywhere these days. It is driving business growth, shaping consumer experiences, and showing up in places most of us never imagined just a few years ago. Read Now

New Products

  • Compact IP Video Intercom

    Viking’s X-205 Series of intercoms provide HD IP video and two-way voice communication - all wrapped up in an attractive compact chassis.

  • EasyGate SPT and SPD

    EasyGate SPT SPD

    Security solutions do not have to be ordinary, let alone unattractive. Having renewed their best-selling speed gates, Cominfo has once again demonstrated their Art of Security philosophy in practice — and confirmed their position as an industry-leading manufacturers of premium speed gates and turnstiles.

  • PE80 Series

    PE80 Series by SARGENT / ED4000/PED5000 Series by Corbin Russwin

    ASSA ABLOY, a global leader in access solutions, has announced the launch of two next generation exit devices from long-standing leaders in the premium exit device market: the PE80 Series by SARGENT and the PED4000/PED5000 Series by Corbin Russwin. These new exit devices boast industry-first features that are specifically designed to provide enhanced safety, security and convenience, setting new standards for exit solutions. The SARGENT PE80 and Corbin Russwin PED4000/PED5000 Series exit devices are engineered to meet the ever-evolving needs of modern buildings. Featuring the high strength, security and durability that ASSA ABLOY is known for, the new exit devices deliver several innovative, industry-first features in addition to elegant design finishes for every opening.