Attacks on small to medium-sized medical entities proceed, as this week’s breach posts sadly attest. Today, Vice Society added Atlanta Perinatal Associates in Georgia to its leak website. As they’ve executed previously, Vice Society didn’t simply add the medical apply with a warning or risk. When Vice Society provides an entity, they concurrently dump a replica of all of the data they declare they exfiltrated.
Preliminary inspection of the leaked recordsdata reveals that they didn’t leak any main EMR system or billing system, however they seem to have accessed affected person information corresponding to ultrasound testing. The recordsdata seemed to be from 2019 to early April 2022.
As is typical of ultrasound stories, the stories comprise the affected person’s title, date of beginning, affected person ID quantity, anticipated due date of supply, referring doctor, sonographer, and naturally, the findings from the ultrasound. Each 6-page report additionally included the sonographer’s feedback and detailed historical past with a overview of techniques, notation of any allergy symptoms, historical past of alcohol or smoking, household and social components, and different health-related points. The varieties don’t appear to incorporate insurance coverage data or Social Security numbers.
Top of ultrasound report; 6-page report. Redacted by DataBreaches.web
Other Obstetrics-related information had been additionally discovered within the leaked recordsdata, as had been recordsdata that included medical health insurance data. Yet different recordsdata included bank card data if the affected person paid by bank card on the time of their go to or appointment.
Although the listing of folders included personnel-related or payroll-related folders, these folders seemed to be empty. A number of direct deposit or payroll-related recordsdata had been seen, nonetheless.
Atlanta Perinatal Associates was contacted through their web site contact type earlier at this time however no reply has been obtained. DataBreaches additionally reached out to Vice Society through electronic mail to inquire whether or not they had encrypted Atlanta Perinatal’s recordsdata, and whether or not they might affirm that exfiltration occurred on or about April 9, 2022. This submit will likely be up to date if a response is obtained from both Atlanta Perinatal or Vice Society.