Nearly 50,000 AdventHealth Patients Impacted in Yearlong Data Breach

Nearly 50,000 AdventHealth Patients Impacted in Yearlong Data Breach

AdventHealth's system was breached for over a year, impacting 42,000 patients and their data.

Nearly 50,000 AdventHealth Medical Group Pulmonary and Sleep Medicine patents are being notified that their personal and health information was breached for more than a year due to a hack of the Florida provider's systems.

On December 27, 2018, officials of the provider discovered a hacker gained access to the AdventHealth systems beginning in August 2017 — more than 16 months earlier. 

The breached data of 42,000 patients contained troves of personal and health data, including medical histories, insurance carriers, Social Security numbers and some demographic information like names, phone numbers and email addresses. 

AdventHealth said that any patient who's information was made vulnerable will receive a year of free identity monitoring services. The company also said it has since improved its processes to bolder its auditing and system safeguards. 

“While the longstanding focus of attackers has been financial data from retail, e-commerce, and financial services sectors, the untapped trove of personal data are a series of softer targets such as localities, social services, and healthcare," Warren Poschman, senior solutions architect at comforte AG said. "Not only are these systems just as rich with data as the traditional targets but security often lags due to the focus on, in the case of healthcare, patient care over IT."

Poschman said AdventHealth had a series of perimeter and intrusion security measures but none of those security measures ultimately detected a 16-month long breach.

"Similar to Equifax and other long-term breaches, data was accessed and likely exfiltrated because it was stored in the clear or protected by passive means such as volume level encryption or database encryption," Poschman said. "Therein lies the issue – attackers went undetected because the perimeter was breached and once inside there was nothing substantial to stop the attackers from accessing the real target, their patient data. Instead of focusing solely on the perimeter and network levels, healthcare providers are highly advised to implement strong data protection strategies that deal with the eventuality of attackers gaining some level of access to a network – after all, it’s the data that the attackers are after, not the firewalls, servers, and other infrastructure."

Poschman suggests that companies dealing with healthcare data adopt a data-centric security model that allows for the data to be protected as it is acquired and traverses through the organization. If an attacker gains access through the perimeter, then the risk that the actual personal data will be exposed is dramatically reduced, because of this high amount of security.


About the Author

Sydny Shepard is the Executive Editor of Campus Security & Life Safety.

Featured

  • 2025 Security LeadHER Conference Program Announced

    ASIS International and the Security Industry Association (SIA) – the leading membership associations for the security industry – have announced details for the 2025 Security LeadHER conference, a special event dedicated to advancing, connecting and empowering women in the security profession. The third annual Security LeadHER conference will be held Monday, June 9 – Tuesday, June 10, 2025, at the Detroit Marriott Renaissance Center in Detroit, Michigan. This carefully crafted program represents a comprehensive professional development opportunity for women in security this year. To view the full lineup at this year’s event, please visit securityleadher.org. Read Now

    • Industry Events
  • Report: 82 Percent of Phishing Emails Used AI

    KnowBe4, the world-renowned cybersecurity platform that comprehensively addresses human risk management, today launched its Phishing Threat Trend Report, detailing key trends, new data, and threat intelligence insights surrounding phishing threats targeting organizations at the start of 2025. Read Now

  • NRF Supports Federal Bill to Thwart Retail Crime

    The National Retail Federation recently announced its support for the Combating Organized Retail Crime Act of 2025. The act was introduced by Chairman Chuck Grassley, R-Iowa, Senator Catherine Cortez Masto, D-Nev., and Representative Dave Joyce, R-Ohio. Read Now

  • ISC West 2025 Brings Almost 29,000 Industry Professionals to Las Vegas

    ISC West 2025, organized by RX and in collaboration with the Security Industry Association, concluded at the Venetian Expo in Las Vegas last week. The nation’s leading comprehensive and converged security event attracted nearly 29,000 industry professionals and left a lasting impression on the global security community. Over five action-packed days, ISC West welcomed more than 19,000 attendees and featured 750 exhibiting brands. Read Now

    • Industry Events
    • ISC West
  • Tradeshow Work Can Be Fun

    While at ISC West last week, I ran into numerous friends and associates all of which was a pleasant experience. The first question always seemed to be, “How many does this make for you?” Read Now

    • Industry Events
    • ISC West

New Products

  • ResponderLink

    ResponderLink

    Shooter Detection Systems (SDS), an Alarm.com company and a global leader in gunshot detection solutions, has introduced ResponderLink, a groundbreaking new 911 notification service for gunshot events. ResponderLink completes the circle from detection to 911 notification to first responder awareness, giving law enforcement enhanced situational intelligence they urgently need to save lives. Integrating SDS’s proven gunshot detection system with Noonlight’s SendPolice platform, ResponderLink is the first solution to automatically deliver real-time gunshot detection data to 911 call centers and first responders. When shots are detected, the 911 dispatching center, also known as the Public Safety Answering Point or PSAP, is contacted based on the gunfire location, enabling faster initiation of life-saving emergency protocols.

  • EasyGate SPT and SPD

    EasyGate SPT SPD

    Security solutions do not have to be ordinary, let alone unattractive. Having renewed their best-selling speed gates, Cominfo has once again demonstrated their Art of Security philosophy in practice — and confirmed their position as an industry-leading manufacturers of premium speed gates and turnstiles.

  • Compact IP Video Intercom

    Viking’s X-205 Series of intercoms provide HD IP video and two-way voice communication - all wrapped up in an attractive compact chassis.