1. #1
    Russian Rocket
    Kleptoman
    Russian Rocket's Avatar Become A Pro!
    Join Date: 09-02-12
    Posts: 43,910
    Betpoints: 533

    Hackers steal 4.5 million patient records from multi-state hospital network

    About 4.5 million patients at any of the 206 Community Health Systems-operated hospitals around the United States have had their records stolen by hackers, the company announced Monday. The stolen data includes very sensitive information.
    Anyone who received treatment in a CHS-operated hospital over the last five years is affected by the breach. However, patients who were merely referred to one of the company’s hospitals during that time period are also impacted. The hackers stole names, Social Security numbers, physical address, birthdays and telephone numbers in two attacks this spring. It does not include ***********, medical or clinical information, the Wall Street Journal reported.
    The attackers appear to be from a sophisticated "Advanced Persistent Threat" hacking group in China that has breached other major US companies across several industries, said Charles Carmakal, managing director with FireEye Inc's Mandiant forensics unit, which led the investigation of the attacks on Community Health in April and June.
    "They have fairly advanced techniques for breaking into organizations as well as maintaining access for fairly long periods of times without getting detected," he told Reuters.
    The intruder uses high-end, sophisticated malware to conduct corporate espionage, and has typically sought valuable intellectual property, such as medical device and equipment development data, according to federal authorities and Mandiant, the company said.
    CHS is notifying patients affected by the attack and offering them identity theft protection services. The company owns, leases or operates 206 hospitals in 29 states, mostly in rural locations, according to the Wall Street Journal. It would be the largest theft of personal patient information since a US Department of Health and Human Services website began tracking medical breaches in 2009, Reuters reported.

    Locations of Community Health Systems-operated hospitals (Image by CHS, Inc.)



    The 4.5 million affected patients and referrals are at heightened risk for identity theft, as the hackers ‒ or those they sell the data to ‒ could potentially open bank accounts or ************ under their names. They could also take out loans and otherwise ruin people’s personal credit history.
    The company is working closely with government law enforcement authorities during the course of their investigation. The Federal Bureau of Investigation said it's working closely with the hospital network and "committing significant resources and efforts to target, disrupt, dismantle and arrest the perpetrators," according to CNNMoney.

    CHS also hired cybersecurity firm Mandiant to investigate, and has since eradicated the malware from its systems. It has also implemented remediation efforts to prevent similar attacks in the future.

    The hospital operator is located in Franklin, Tennessee. Shares of Community Health climbed 38 cents to $51.38 late Monday morning, while broader trading indexes also rose less than 1 percent, the Associated Press reported.

  2. #2
    jtoler
    jtoler's Avatar Become A Pro!
    Join Date: 12-17-13
    Posts: 30,967
    Betpoints: 6337

    Are you russian or american.

  3. #3
    Russian Rocket
    Kleptoman
    Russian Rocket's Avatar Become A Pro!
    Join Date: 09-02-12
    Posts: 43,910
    Betpoints: 533

    Quote Originally Posted by jtoler View Post
    Are you russian or american.
    hey Jtoler what's happening pal? you've never seen a Russian speak English before?

    call me

  4. #4
    jtoler
    jtoler's Avatar Become A Pro!
    Join Date: 12-17-13
    Posts: 30,967
    Betpoints: 6337

    Just was curious, there is alot of hacker activity in Eastern Europe as well as the U.S., went to school for Electrical and Computer Engineering, hating writing code until I met some real geeks, I see you seem to have an interest in it from your past threads, do you play around any.

  5. #5
    Russian Rocket
    Kleptoman
    Russian Rocket's Avatar Become A Pro!
    Join Date: 09-02-12
    Posts: 43,910
    Betpoints: 533

    Quote Originally Posted by jtoler View Post
    Just was curious, there is alot of hacker activity in Eastern Europe as well as the U.S., went to school for Electrical and Computer Engineering, hating writing code until I met some real geeks, I see you seem to have an interest in it from your past threads, do you play around any.
    yeah I have a degree in CS and I also worked in high-tech industry for many years...know some folks on a good and bad sides of the hacking world

    obviously majority of gamblers here don't have the knowledge of this kind of stuff...so I think sharing this type of articles is important, especially when it relates to stolen personal information

  6. #6
    gauchojake
    Have Some Asthma
    gauchojake's Avatar SBR PRO
    Join Date: 09-17-10
    Posts: 33,725
    Betpoints: 13200

    Patient data is so vulnerable it's ridiculous. Nurses carry around lap tops and hand held devices to their home bound patients. I'm fairly certain they are not the most trustworthy caretakers of your data. Many are employees of systems that serve millions of people. And this data isn't exactly your sbr username and password.

  7. #7
    jtoler
    jtoler's Avatar Become A Pro!
    Join Date: 12-17-13
    Posts: 30,967
    Betpoints: 6337

    Quote Originally Posted by Russian Rocket View Post
    yeah I have a degree in CS and I also worked in high-tech industry for many years...know some folks on a good and bad sides of the hacking world

    obviously majority of gamblers here don't have the knowledge of this kind of stuff...so I think sharing this type of articles is important, especially when it relates to stolen personal information
    Thats cool, I kinda keep up with that side of the news sometimes, I dont think the majority of people care yet until it directly affects them, have a friend who works in card fraud, she updates me quite a bit on little stuff like that, used to tell me when Cam Newton, Billy Ray Cyrus and quite a bit of other famous people's cards were being ripped off at the very moment its happening.

  8. #8
    Russian Rocket
    Kleptoman
    Russian Rocket's Avatar Become A Pro!
    Join Date: 09-02-12
    Posts: 43,910
    Betpoints: 533

    Quote Originally Posted by gauchojake View Post
    Patient data is so vulnerable it's ridiculous. Nurses carry around lap tops and hand held devices to their home bound patients. I'm fairly certain they are not the most trustworthy caretakers of your data. Many are employees of systems that serve millions of people. And this data isn't exactly your sbr username and password.
    The highest security that I've ever seen personaly was at the company where I worked about 7 years ago. We were specializing in personal genomics...basically anyone who pays an x amount of dollars could get a breakdown of their DNA where they can see what conditions, such as diff types of cancers or diseases, they're predisposed to have.
    So besides a high security at the actual workplace, every DNA batch with samples was delivered to us in an armored truck with a private security escort.

  9. #9
    Russian Rocket
    Kleptoman
    Russian Rocket's Avatar Become A Pro!
    Join Date: 09-02-12
    Posts: 43,910
    Betpoints: 533

    Quote Originally Posted by jtoler View Post
    Thats cool, I kinda keep up with that side of the news sometimes, I dont think the majority of people care yet until it directly affects them, have a friend who works in card fraud, she updates me quite a bit on little stuff like that, used to tell me when Cam Newton, Billy Ray Cyrus and quite a bit of other famous people's cards were being ripped off at the very moment its happening.
    that's a great friend to have!

  10. #10
    Vegas39
    Vegas39's Avatar Become A Pro!
    Join Date: 09-22-11
    Posts: 30,686
    Betpoints: 214

    Quote Originally Posted by Russian Rocket View Post
    The highest security that I've ever seen personaly was at the company where I worked about 7 years ago. We were specializing in personal genomics...basically anyone who pays an x amount of dollars could get a breakdown of their DNA where they can see what conditions, such as diff types of cancers or diseases, they're predisposed to have.
    So besides a high security at the actual workplace, every DNA batch with samples was delivered to us in an armored truck with a private security escort.

    they search you before leaving work each day

  11. #11
    Russian Rocket
    Kleptoman
    Russian Rocket's Avatar Become A Pro!
    Join Date: 09-02-12
    Posts: 43,910
    Betpoints: 533

    Quote Originally Posted by Vegas39 View Post
    they search you before leaving work each day
    not every day...but they could have if they wanted to

  12. #12
    gauchojake
    Have Some Asthma
    gauchojake's Avatar SBR PRO
    Join Date: 09-17-10
    Posts: 33,725
    Betpoints: 13200

    Quote Originally Posted by Russian Rocket View Post
    The highest security that I've ever seen personaly was at the company where I worked about 7 years ago. We were specializing in personal genomics...basically anyone who pays an x amount of dollars could get a breakdown of their DNA where they can see what conditions, such as diff types of cancers or diseases, they're predisposed to have.
    So besides a high security at the actual workplace, every DNA batch with samples was delivered to us in an armored truck with a private security escort.
    The problem in healthcare is that you have a mandated electronic medical record. That record is often touched by many providers. Trust me when I tell you that your medical records are an open book to so many people it's ridiculous. Let's just say I could have entered death pools with certain locks that no one else would know about never having had any contact with the patient or doctor.

  13. #13
    Vegas39
    Vegas39's Avatar Become A Pro!
    Join Date: 09-22-11
    Posts: 30,686
    Betpoints: 214

    Quote Originally Posted by Russian Rocket View Post
    not every day...but they could have if they wanted to
    got it, was curious on that, as gaucho said so many hands on medical records and most hospitals haver terrible security

  14. #14
    Russian Rocket
    Kleptoman
    Russian Rocket's Avatar Become A Pro!
    Join Date: 09-02-12
    Posts: 43,910
    Betpoints: 533

    Quote Originally Posted by Vegas39 View Post
    got it, was curious on that, as gaucho said so many hands on medical records and most hospitals haver terrible security
    but the security at the workplace was pretty tight...I mean we're talking about even encrypting every email that you send out inside the company's network, changing all the passwords every 10 days and so on...and that was 7 years ago

  15. #15
    Booya711
    Big Dikk Energy
    Booya711's Avatar SBR PRO
    Join Date: 12-20-11
    Posts: 27,328
    Betpoints: 16121

    Interesting story rocket....it was around 2007-2009 that one of my customers in the health system was sold to CHS...

Top