Voyage Technology Blog

Voyage Technology has been serving the Beaver Dam area since 1999, providing IT Support such as technical helpdesk support, computer support, and consulting to small and medium-sized businesses.

100 Million Compromised Medical Records Shakes Patient Confidence

100 Million Compromised Medical Records Shakes Patient Confidence

Online threats against healthcare organizations are currently one of the biggest cybersecurity issues. A reported 100-million-plus total medical records have been compromised, according to IBM’s 2016 Cyber Security Intelligence Index. How could a hacker profit off of accessing someone’s medical records? Simply put: ransomware.

The use of ransomware shows enough evidence of a hacker being hard-hearted on its own, but healthcare ransomware suggests an entirely different level of depravity. Hospitals that have been struck by ransomware attacks have found themselves unable to access critical patient records, leaving the administration with little choice but to pay the ransom in order to protect their patients.

Of course, medical records contain other bits of information that hackers would certainly be able to find some nefarious use for. Financial details, home addresses, and social security numbers are all often present within these records, handing the cyber criminal a blueprint to steal your identity.

One particular hacker with the handle “TheDarkOverlord” recently put over 650,000 patient records up for sale on the dark web. TheDarkOverlord was able to obtain these records by taking advantage of some vulnerability in a particular implementation method of remote desktop protocols, before accessing the databases containing the medical records. Rather than posting them for sale immediately, TheDarkOverlord offered each of the affected companies information as to the nature of the vulnerability. Naturally, the hacker demanded money for the vulnerability.

It was only when each of the three companies (one located in Farmington, Missouri, one in Georgia, and one somewhere in the Central/Midwest region) refused to pay, that TheDarkOverlord put the databases up for sale on a dark web marketplace. The Georgia haul has apparently already brought the hacker some money; a buyer purchased all of the insurance records for patients covered by BlueCross/BlueShield from the organization located in Georgia. In a markedly ominous statement, TheDarkOverlord had a message to deliver to these companies:

“Next time an adversary comes to you and offers you an opportunity to cover this up and make it go away for a small fee to prevent the leak, take the offer. There is a lot more to come.”

Additionally, there have been hacking intrusions into the hospital networks themselves, allowing the hackers to not only steal the medical and financial records hospitals keep on their patients, but also to interfere with the medical devices that sustain many patients. As a result, these attacking criminals are capable of potentially turning off or altering the settings of devices that are being used to keep patients alive, be they full life-support systems or intravenous medication dispensers.

For doctors and hospital administrators, the consequences of these circumstances must be terrifying to consider: after all, they are stuck paying a ransom to avoid facing a malpractice lawsuit.

However, when all of the factors that make healthcare organizations such valuable targets are considered, the lack of preparedness for these attacks that the overwhelming majority of organizations have is astounding. Some of this lack of preparation is almost understandable; after all, hospitals may not have the capability to fully back up all of the data that is produced every day, making it a relatively frightening concept. What’s worse is that 25 percent of those polled have no means of determining whether or not they had been a potential victim of a ransomware attack.

So how can hospital systems (or any industry’s systems, for that matter) be better defended against such attacks? As a high-value target, a healthcare system will almost certainly be targeted eventually. This is especially probable considering that most small businesses will be attacked as well. Therefore, it is in the best interest of any organization to implement a solid plan to defend against these consequences.

  • Establish an isolated backup solution: Whenever there is critical data involved in the day-to-day operation, a backup solution is something that is absolutely necessary for the organization’s safety and security. In the case of a healthcare organization losing their files to some nefarious intruder, a backup will allow them to continue their operations without putting the health and safety of the patients at risk. However, for this backup to be truly effective, it must be isolated from the original system; otherwise, the hacker will likely be able to access the backup as well. As an added advantage, this separation also protects the data against disasters, such as fires, floods, or user error.
  • Implement a reliable defense strategy: Considering that most external attacks take advantage of system vulnerabilities, this facet is intended to remove the vulnerabilities from your system. As vulnerabilities come in different varieties, your strategy will need to be multifaceted to cover all bases. Install and maintain reliable antivirus and malware blockers, and educate yourself and your users on industry best practices for data security.

Has your IT shown symptoms of security vulnerabilities? To fill your prescription for best practice guidelines, be sure to visit Voyage Technology’s blog regularly.

 

Comments

No comments made yet. Be the first to submit a comment
Already Registered? Login Here
Guest
Sunday, 14 December 2025

Captcha Image

Sign Up For Our Newsletter!

Mobile? Grab this Article!

Qr Code

Tag Cloud

Security Technology Tip of the Week Best Practices Data Business Computing Business Productivity Software Innovation Cloud Hackers Hardware Efficiency Network Security User Tips Internet Malware IT Support Privacy Google Email Workplace Tips Computer Phishing IT Services Collaboration Hosted Solutions Users Workplace Strategy Ransomware Mobile Device Microsoft Small Business Backup Productivity Passwords Quick Tips Saving Money Communication Cybersecurity Managed Service Data Backup Smartphone Android Upgrade Business Management Data Recovery VoIP Smartphones AI Disaster Recovery Mobile Devices communications Windows Browser Social Media Microsoft Office Managed IT Services Current Events Network Tech Term Remote Internet of Things Automation Artificial Intelligence Facebook Miscellaneous Information Holiday Training Gadgets Cloud Computing Covid-19 Remote Work Server Managed Service Provider Outsourced IT Compliance Employee/Employer Relationship IT Support Encryption Spam Windows 10 Office Data Management Business Continuity Government Business Technology Windows 10 Bandwidth Virtualization Blockchain Wi-Fi Two-factor Authentication Mobile Office Data Security Apps Vendor Mobile Device Management Chrome Tip of the week Gmail Budget Managed Services Voice over Internet Protocol Apple Networking App Employer-Employee Relationship BYOD Applications Avoiding Downtime Marketing Office 365 Access Control Conferencing WiFi How To BDR Computing HIPAA Hacker Information Technology Virtual Private Network Website Health 2FA Analytics Office Tips Help Desk Augmented Reality Storage Retail Password Healthcare Bring Your Own Device Big Data Managed IT Services Operating System Computers Router Risk Management Display Printer Paperless Office Windows 11 Infrastructure Monitoring Firewall Excel Document Management Remote Workers The Internet of Things Telephone Scam Data loss Social Cooperation Free Resource Project Management Windows 7 Going Green Patch Management Save Money Microsoft 365 Customer Service Remote Monitoring Vulnerability End of Support Cybercrime Vendor Management Solutions Physical Security User Tip Modem Virtual Desktop Processor Computer Repair Mobile Security Data storage LiFi Holidays Word Data Storage Outlook Smart Technology Supply Chain Money Video Conferencing Machine Learning Managed Services Provider Humor Saving Time Virtual Machines Professional Services Safety Sports Managed IT Service Mouse Maintenance Antivirus Downloads iPhone Licensing Administration Entertainment Vulnerabilities Data Privacy Images 101 Customer Relationship Management Telephone System Multi-Factor Authentication Robot Mobility Settings Wireless Cost Management Printing Content Filtering Hacking YouTube Presentation IT Management VPN Employees Meetings Cryptocurrency Integration Wireless Technology Managing Costs Amazon IP Address Google Docs Unified Communications Experience Username Point of Sale eCommerce Black Friday SSID Bitcoin Running Cable Database Surveillance Virtual Assistant Outsource IT Google Wallet Tech Support IT Technicians Virtual Machine Environment Media Recovery Network Management Proxy Server Reviews Cookies Monitors Cyber Monday Medical IT Hard Drives Windows 8 Laptop Drones Tactics Development Hotspot Transportation Small Businesses Domains Websites Mirgation Hypervisor Displays Halloween Shopping Nanotechnology Optimization PowerPoint Refrigeration Electronic Medical Records Language Employer/Employee Relationships Outsourcing Public Speaking SharePoint Addiction Management PCI DSS Chatbots Lithium-ion battery Navigation Entrepreneur Scary Stories Lenovo Gig Economy Screen Reader Writing Distributed Denial of Service Workplace Hacks Virtual Reality Computing Infrastructure Teamwork Hiring/Firing Fun Service Level Agreement Internet Service Provider Server Management Regulations Compliance Private Cloud Identity Evernote Paperless Deep Learning Superfish Bookmark Identity Theft Smart Tech Memes Co-managed IT Undo Twitter Alerts SQL Server Technology Care Education Download Net Neutrality Financial Data Error History Business Communications Browsers Smartwatch Connectivity IT Social Engineering Break Fix Scams Mobile Computing Remote Computing Azure Hybrid Work Search Upload Procurement Social Network Telework Cyber security Multi-Factor Security Tech Human Resources Application Best Practice Buisness CES Tablet IoT Communitications Dark Web Cables Alert IBM Legal IT solutions Trends Supply Chain Management Managed IT Customer Resource management FinTech File Sharing Regulations Dark Data Google Calendar Term Google Apps Business Growth Data Analysis Star Wars IT Assessment How To Microsoft Excel IT Maintenance Notifications Staff Value Business Intelligence Cortana Gamification Flexibility Organization Travel Social Networking Legislation Shortcuts Alt Codes Downtime Techology Fileless Malware Digital Security Cameras Google Maps Smart Devices Ransmoware Competition Wearable Technology Memory Vendors Hosted Solution Content Remote Working Health IT Unified Threat Management Motherboard Data Breach Comparison Google Play Be Proactive Typing Unified Threat Management Directions Videos Assessment Electronic Health Records Permissions Workforce Wasting Time Threats Google Drive User Knowledge Trend Micro Network Congestion Specifications Security Cameras Workplace Strategies 5G User Error Microchip Internet Exlporer Software as a Service Fraud Meta

Blog Archive