Now on Demand Ransomware Resilience & Recovery Summit - All Sessions Available
Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Cybercrime

Additional Healthcare Firms Disclose Impact From Netgain Ransomware Attack

Healthcare providers Caring Communities and Entira Family Clinics are warning patients that their personal information may have been exposed in a data breach that hit tech vendor Netgain Technology more than a year ago.

Healthcare providers Caring Communities and Entira Family Clinics are warning patients that their personal information may have been exposed in a data breach that hit tech vendor Netgain Technology more than a year ago.

In late November 2020, Netgain, which provides managed IT services to organizations in sectors such as accounting, healthcare, and legal, fell victim to a ransomware attack that also resulted in the compromise of customer data.

By January 2021, Netgain had informed affected organizations of the incident, and numerous healthcare services providers began  sending  data breach notices over the next several months, including Ramsey County’s Family Health division, Woodcreek Provider Services, Sandhills Medical Foundation, Apple Valley Clinic, Neighborhood Healthcare, San Diego Family Care (and Health Center Partners of Southern California), SAC Health System, SouthCare Carolina, and Caravus.

Ransomware Virtual Event

During summer, more healthcare provides disclosed impact from the incident, including Minnesota Community Care, CentraCare Health and Carris Health – Willmar Lakeland Clinic, Family Health Centers of San Diego, Imperial Beach Community Clinic, and LifeLong Medical Care.

Last week, Caring Communities and Entira Family Clinics also  revealed the impact from the Netgain ransomware attack and began telling patients that their personal information might have been leaked.

In addition to medical history, data that was potentially compromised in the attack includes names, addresses, and Social Security numbers, both organizations said in their notification letters.

Entira told the Maine Attorney General’s Office that data of roughly 200,000 individuals was compromised in the incident. Overall, the Netgain incident appears to have impacted the data of more than 1 million patients.

Related: MRIoA Discloses Data Breach Affecting 134,000 People

Advertisement. Scroll to continue reading.

Related: 400,000 Individuals Affected by Email Breach at West Virginia Health Firm

Related: Preventing a Cyber Pandemic in Healthcare

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join the session as we discuss the challenges and best practices for cybersecurity leaders managing cloud identities.

Register

SecurityWeek’s Ransomware Resilience and Recovery Summit helps businesses to plan, prepare, and recover from a ransomware incident.

Register

People on the Move

MSSP Dataprise has appointed Nima Khamooshi as Vice President of Cybersecurity.

Backup and recovery firm Keepit has hired Kim Larsen as CISO.

Professional services company Slalom has appointed Christopher Burger as its first CISO.

More People On The Move

Expert Insights

Related Content

Cybercrime

A recently disclosed vBulletin vulnerability, which had a zero-day status for roughly two days last week, was exploited in a hacker attack targeting the...

Cybercrime

The changing nature of what we still generally call ransomware will continue through 2023, driven by three primary conditions.

Cybercrime

As it evolves, web3 will contain and increase all the security issues of web2 – and perhaps add a few more.

Cybercrime

Luxury retailer Neiman Marcus Group informed some customers last week that their online accounts had been breached by hackers.

Cybercrime

Zendesk is informing customers about a data breach that started with an SMS phishing campaign targeting the company’s employees.

Cybercrime

Patch Tuesday: Microsoft calls attention to a series of zero-day remote code execution attacks hitting its Office productivity suite.

Ransomware

A SaaS ransomware attack against a company’s Sharepoint Online was done without using a compromised endpoint.