Skip to main content
Sister Publication Links
  • ModernHealthcare.com
Subscribe
  • My Account
  • Login
  • Register
  • Consumer Centric
  • Provider/Payer Centric
  • Funding/M&A
  • Policy
  • Data
  • Opinion
  • MORE+
    • Webinars
    • Advertise
MENU
Breadcrumb
  1. Home
  2. Technology
July 06, 2022 01:27 PM

Ransomware attack at payment vendor affects 600 providers

Jessica Kim Cohen
  • Tweet
  • Share
  • Share
  • Email
  • More
    Reprints Print
    cyber story_FLAT_WEB_i_i.jpg
    MH Illustration/Getty Images

    A ransomware attack at Professional Finance Company may have exposed data from patients at about 600 healthcare providers.

    Greeley, Colorado-based PFC, an accounts receivable management company, discovered the ransomware attack in February, after an unauthorized user accessed and disabled some of the company's computer systems. PFC disconnected the affected systems and has worked with third-party forensic specialists to investigate the incident and secure its network, according to a notice from the company.

    PFC's investigation found that during the ransomware attack, hackers may have accessed files containing some patients' personal information. The company notified healthcare providers whose patient data may have been exposed May 5, and last week began mailing letters to patients.

    The ransomware attack hit company systems that held data from facilities at DispatchHealth, Banner Health, Renown Health and multiple other provider customers.

    A company spokesperson declined a request for comment on the number of affected patients and whether the company paid a ransom.

    PFC said it hasn't found evidence to suggest patient data has been misused by hackers, but it's possible information including names, addresses, accounts receivable balance, dates of birth, Social Security numbers and health insurance and medical treatment information could have been accessed by hackers.

    PFC has "wiped and rebuilt affected systems" since the ransomware attack, among other steps to improve its network security, according to the notice.

    "We are committed to mitigating the chance of a similar, future incident, and have taken specific and robust measures to ensure that our data is more secure than ever before," a company spokesperson wrote in an emailed statement. "We have made significant investments to advance our security posture, including adding AI threat protection and contracting with two leading cybersecurity firms."

    Healthcare entities covered by the Health Insurance Portability and Accountability Act are required to disclose data breaches to the Health and Human Services Department's Office for Civil Rights within 60 days of discovering them. The incident has not been posted to the department's breach portal.

    Healthcare providers, insurers and their business associates have submitted nearly 330 data breach reports in 2022, according to the Office for Civil Rights' breach portal. The largest data breach reported this year took place at Shields Health Care Group, where a cyberattack in March compromised data on an estimated 2 million patients.

    Letter
    to the
    Editor

    Send us a letter

    Have an opinion about this story? Click here to submit a Letter to the Editor, and we may publish it online.

    Recommended for You
    laptop computer generic file.png
    Cybersecurity attacks cost healthcare systems more than any other sector, new report finds
    Robot performing simulated surgery tasks
    Robotic surgery’s next frontier is space
    Sponsored Content
    Get Newsletters

    Newsletters for providers, payers, investors and innovators across the digital health ecosystem. Sign up to get breaking digital health news including digital health deals, M&A, finance, IPOs. as they happen, right to your inbox.

    Buy Q2 Report Today
    Quarterly Report Cover Image

    The Digital Health Funding and M&A Q2 report delivers the most comprehensive insight and data around the financial health of the sector.

    Purchase Today
    Connect with Us
    • LinkedIn
    • Twitter
    • Facebook
    • RSS

    Digital Health Business & Technology delivers news, data, insights and analysis covering the entire digital healthcare ecosystem.

    Logo
    Contact Us

    (877) 812-1581

    Email us

     

    Editorial Dept
    • Submission Guidelines
    • Code of Ethics
    Resources
    • About Us
    • Contact Us
    • Staff
    • Advertise with Us
    • Ad Choices Ad Choices
    • Sitemap
    Legal
    • Terms and Conditions
    • Privacy Policy
    • Privacy Request
    Digital Health Business & Technology
    Copyright © 1996-2022. Crain Communications, Inc. All Rights Reserved.
    • Consumer Centric
    • Provider/Payer Centric
    • Funding/M&A
    • Policy
    • Data
    • Opinion
    • MORE+
      • Webinars
      • Advertise