70,000 Patient Records Breached Due To Hacked Kaiser Permanente Email Account

Share post:

Kaiser Permanente, the biggest nonprofit health plan provider in America, recently announced a data breach that exposed highly sensitive health information of close to 70,000 patients.

In a June 3 notice sent to patients, Kaiser disclosed that a hacker was able to gain access to an employee’s emails at the Kaiser Foundation Health Plan of Washington on April 5. This contained protected health information such as patient names, dates of service, medical record numbers and lab test results information. However, according to the healthcare provider, financially sensitive information like social security and credit card numbers, was not exposed by the breach.

The company has kept mum on the scale of the breach, but a separate filing with the U.S. Department of Health and Human Services confirmed that 69,589 individuals were impacted.

“We terminated the unauthorized access within hours after it began and promptly commenced an investigation to determine the scope of the incident,” Kaiser said in its notice. 

Kaiser has also not discussed how an unauthorized third party was able to gain access to the employees’ emails. However, it said that the hacked employee “received additional training in safe email practices,” suggesting the breach may have been performed via credential stuffing or phishing.

The company has also not commented on why it took them almost two months to inform patients about the breach.

Kaiser Permanente is the latest in a long line of healthcare providers whose private data had been breached by hackers. 

For more information, read the original story in Techcrunch.

SUBSCRIBE NOW

Related articles

Cyber Security Today, May 3, 2024 – North Korea exploits weak email DMARC settings, and the latest Verizon analysis of thousands of data breaches

This episode reports on warnings about threats from China, Russia and North Korea, the hack of Dropbox Sign's infrastructure

Hashtag Trending for World Password Day, Thursday, May 2nd, 2024

Security firm Okta warns of an unprecendented password stuffing attack that is piggybacking on regular user’s mobile and...

Google Chrome’s new post-quantum cryptography causes connection issues

The latest update to Google Chrome, version 124, which integrates a new quantum-resistant encryption mechanism, has led to...

UK legislation bans weak passwords

Starting Monday, the UK will enforce new laws banning the sale of devices with weak default passwords such...

Become a member

New, Relevant Tech Stories. Our article selection is done by industry professionals. Our writers summarize them to give you the key takeaways