http://www.washingtonpost.com/news/morning-mix/wp/2014/08/19/chinese-hackers-may-have-stolen-your-medical-records/


Chinese hackers may have stolen your medical records

Chinese hackers have stolen medical records for 4.5 million patients,
according to a regulatory filing
<http://www.sec.gov/Archives/edgar/data/1108109/000119312514312504/d776541d8k.htm>
from Community Health Systems, a publicly-traded company that runs 206
hospitals in 29 states <http://www.chs.net/>.

The stolen data includes records for patients of who have seen doctors
affiliated with the company in the past five years.

Mandiant, a cybersecurity firm hired by the company, believes the attacks
originated in China. The FBI is also investigating the break-in.

Between April and June, hackers bypassed the company’s security systems and
stole personal data including names, addresses, birth dates, telephone
numbers and social security numbers. The stolen information did not include
patients’ credit card numbers, medical or clinical data.

[image: hospitalshacked0819]

The theft was unusual for Chinese hackers “known for seeking intellectual
property, such as product design, or information that might be of use in
business or political negotiations,” Reuters said
<http://www.reuters.com/article/2014/08/18/us-community-health-cybersecurity-idUSKBN0GI16N20140818>.
“Social Security numbers and other personal data are typically stolen by
cybercriminals to sell on underground exchanges for use by others in
identity theft.”

The hacking group wasn’t named in the filing, but Charles Carmakal,
managing director of Mandiant, told Bloomberg
<http://www.bloomberg.com/news/2014-08-18/why-would-chinese-hackers-steal-millions-of-medical-records-.html>
in an e-mail that the group, which he identified as “APT 18,” “typically
targets companies in the aerospace and defense, construction and
engineering, technology, financial services, and health-care industry.”

Another cybersecurity firm, Crowdstrike, which has been tracking the group
for four years, told Reuters
<http://www.reuters.com/article/2014/08/18/us-community-health-cybersecurity-idUSKBN0GI16N20140818>
it believes the hackers are either backed by Beijing or work directly for
the government based on the targets they have chosen. The firm’s chief
technology officer, Dmitri Alperovitch, said “APT 18,” also known as
“Dynamite Panda,” has “above average skill” among Chinese hackers.

So why are sophisticated hackers known for corporate espionage turning to
identity theft?

Bloomberg’s Michael Riley and Jordan Robertson spoke with someone familiar
with the investigation and said there are a couple of theories
<http://www.bloomberg.com/news/2014-08-18/why-would-chinese-hackers-steal-millions-of-medical-records-.html>.
The
hackers might have “stolen the information for the purposes of locating new
targets or adding private data to the profiles of existing targets.” The
more likely explanation is that rogue members of the hacking group stole
the data without approval from their superiors in hopes of selling it on
the black market for extra cash.

According to the New York Times
<http://bits.blogs.nytimes.com/2014/08/18/hack-of-community-health-systems-affects-4-5-million-patients/>,
security experts have warned that digitization of medical records would
invite hackers. The U.S. Health and Human Services Department keeps track
<http://www.hhs.gov/ocr/privacy/hipaa/administrative/breachnotificationrule/breachtool.html>
of breaches
of private health data affecting 500 or more people. Using the data,
computer virus researchers Stephen Cobb of ESET calculated that every day
last year 24,800 Americans had protected health information exposed, the
Times said.

Mandiant told Reuters
<http://www.reuters.com/article/2014/08/18/us-community-health-cybersecurity-idUSKBN0GI16N20140818>
it has seen a spike in cyberattacks on healthcare providers in the past six
months. The FBI has warned the industry of its vulnerability.

Community Health discovered the hack in July and has since removed the
malware from its systems. The company also said in the regulatory filing
that it has beefed up its security systems.

As required by law, patients whose information was stolen will be notified.
The company will also offer identity theft protection services.

The company has liability insurance and doesn’t expect the take a major
financial hit as a result of the incident.

China has denied similar attacks in the past, but did not respond to
Bloomberg’s request for comment.




__._,_.___
 ------------------------------
Posted by: "Beowulf" <[email protected]>
------------------------------


 Visit Your Group
<https://groups.yahoo.com/neo/groups/grendelreport/info;_ylc=X3oDMTJmNzR2ajVoBF9TAzk3MzU5NzE0BGdycElkAzIwMTk0ODA2BGdycHNwSWQDMTcwNTMyMzY2NwRzZWMDdnRsBHNsawN2Z2hwBHN0aW1lAzE0MDg0NTgzMTQ->


 [image: Yahoo! Groups]
<https://groups.yahoo.com/neo;_ylc=X3oDMTJlMXV2a21xBF9TAzk3NDc2NTkwBGdycElkAzIwMTk0ODA2BGdycHNwSWQDMTcwNTMyMzY2NwRzZWMDZnRyBHNsawNnZnAEc3RpbWUDMTQwODQ1ODMxNA-->
• Privacy <https://info.yahoo.com/privacy/us/yahoo/groups/details.html> •
Unsubscribe <[email protected]?subject=Unsubscribe>
• Terms of Use <https://info.yahoo.com/legal/us/yahoo/utos/terms/>

__,_._,___

-- 
-- 
Thanks for being part of "PoliticalForum" at Google Groups.
For options & help see http://groups.google.com/group/PoliticalForum

* Visit our other community at http://www.PoliticalForum.com/  
* It's active and moderated. Register and vote in our polls. 
* Read the latest breaking news, and more.

--- 
You received this message because you are subscribed to the Google Groups 
"PoliticalForum" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
For more options, visit https://groups.google.com/d/optout.

Reply via email to