https://www.channelfutures.com/wp-content/themes/channelfutures_child/assets/images/logo/footer-new-logo.png
  • Home
  • Technologies
    • Back
    • SDN/SD-WAN
    • Cloud
    • RMM/PSA
    • Security
    • Telephony/UC/Collaboration
    • Cable
    • Mobility & Wireless
    • Fiber/Ethernet
    • Data Centers
    • Backup & Disaster Recovery
    • IoT
    • Desktop
    • Artificial Intelligence
    • Analytics
  • Strategy
    • Back
    • Mergers and Acquisitions
    • Channel Research
    • Business Models
    • Distribution
    • Technology Solutions Brokerages
    • Sales & Marketing
    • Best Practices
    • Vertical Markets
    • Regulation & Compliance
  • MSP 501
    • Back
    • 2023 MSP 501 Application
    • 2022 MSP 501 Rankings
    • 2022 NextGen 101 Rankings
  • Intelligence
    • Back
    • Galleries
    • Podcasts
    • From the Industry
    • Reports/Digital Issues
    • Webinars
    • White Papers
  • Channel Futures TV
  • EMEA
  • Channel Chatter
    • Back
    • People on the Move
    • New/Changing Channel Programs
    • New Products & Services
    • Industry Honors
  • Resources
    • Back
    • Advisory Boards
    • Industry Organizations
    • Our Sponsors
    • Advertise
    • 2023 Editorial Calendar
  • Awards
    • Back
    • 2022 MSP 501
    • Channel Influencers
    • Circle of Excellence
    • DE&I 101
    • Technology Advisor 101 (TA 101)
    • Channel Leaders Lists
  • Events
    • Back
    • 2023 Call for Speakers
    • CP Conference & Expo
    • MSP Summit
    • Channel Partners Europe
    • Channel Partners Event Coverage
    • Webinars
    • Industry Events
  • About Us
  • DE&I
Channel Futures
  • NEWSLETTER
  • Home
  • Technologies
    • Back
    • SDN/SD-WAN
    • Cloud
    • RMM/PSA
    • Security
    • Telephony/UC/Collaboration
    • Cable
    • Mobility & Wireless
    • Fiber/Ethernet
    • Data Centers
    • Backup & Disaster Recovery
    • IoT
    • Desktop
    • Artificial Intelligence
    • Analytics
  • Strategy
    • Back
    • Mergers and Acquisitions
    • Channel Research
    • Business Models
    • Distribution
    • Technology Solutions Brokerages
    • Sales & Marketing
    • Best Practices
    • Vertical Markets
    • Regulation & Compliance
  • MSP 501
    • Back
    • 2023 MSP 501 Application
    • 2022 MSP 501 Rankings
    • 2022 NextGen 101 Rankings
  • Intelligence
    • Back
    • Galleries
    • Podcasts
    • From the Industry
    • Reports/Digital Issues
    • Webinars
    • White Papers
  • Channel Futures TV
  • EMEA
  • Channel Chatter
    • Back
    • People on the Move
    • New/Changing Channel Programs
    • New Products & Services
    • Industry Honors
  • Resources
    • Back
    • Advisory Boards
    • Industry Organizations
    • Our Sponsors
    • Advertise
    • 2023 Editorial Calendar
  • Awards
    • Back
    • 2022 MSP 501
    • Channel Influencers
    • Circle of Excellence
    • DE&I 101
    • Technology Advisor 101 (TA 101)
    • Channel Leaders Lists
  • Events
    • Back
    • 2023 Call for Speakers
    • CP Conference & Expo
    • MSP Summit
    • Channel Partners Europe
    • Channel Partners Event Coverage
    • Webinars
    • Industry Events
  • About Us
  • DE&I
    • Newsletter
  • REGISTER
  • MSPs
  • VARs / SIs
  • Agents
  • Cloud Service Providers
  • Channel Partners Events
 Channel Futures


hospital

One Million Patients’ Information Stolen in CHS Cyberattack

  • Written by Edward Gately
  • February 18, 2023

Community Health Systems (CHS), one of the nation’s largest health care companies, has reported a cyberattack in which the attacker stole 1 million patients’ data.

Based in Tennessee, CHS has nearly 80 hospitals in 16 states. It reported the cyberattack in a filing with the U.S. Securities and Exchange Commission (SEC).

Fortra, a CHS third-party vendor, notified the health care company that it had experienced a security incident that resulted in the unauthorized disclosure of company data.

“Fortra is a cybersecurity firm that contracts with company affiliates to provide a secure file transfer software called GoAnywhere,” CHS said. “As a result of the security breach experienced by Fortra, protected health information (PHI), as defined by the Health Insurance Portability and Accountability Act (HIPAA) and personal information (PI) of certain patients of the company’s affiliates were exposed by Fortra’s attacker.”

Upon receiving notification of the security breach, CHS launched an investigation, including to determine whether any company information systems were affected, whether there was any impact to ongoing operations, and to what extent PHI or PI had been unlawfully accessed by the attacker.

“While that investigation is still ongoing, (CHS) believes that the Fortra breach has not had any impact on any of the company’s information systems and that there has not been any material interruption of the company’s business operations, including the delivery of patient care,” CHS said. “With regard to the PHI and PI compromised by the Fortra breach, the company currently estimates that approximately 1 million individuals may have been affected by this attack.”

CHS said it will ensure that appropriate notification is provided to any individuals affected by this attack, as well as to regulatory agencies as required by federal and state law. It also will be offering identity theft protection services to individuals affected by this attack.

CHS carries cyber/privacy liability insurance to protect it against certain losses related to matters of this nature. However, it may have incurred, and may incur in the future, expenses and losses related to this attack that are not covered by insurance.

“While the company is continuing to measure the impact, including certain remediation expenses and other potential liabilities, the company does not currently believe this incident will have a material adverse effect on its business, operations or financial results,” it said.

Almog Apirion is CEO and co-founder of Cyolo, a zero trust access provider.

“Health care organizations are unfortunately no stranger to cyberattacks and data breaches,” he said. “Institutions like CHS are an attractive target for threat actors due to their troves of personal information and their reliance on third parties both for cybersecurity and other aspects of their work. The reality is that when hackers exploit vulnerabilities in third-party security tools, the lives and privacy of patients are put at risk. Interoperability is vital for successful health care delivery, so a managed file transfer (MFT) is a needed solution. But when the admin console is accessible via the internet, it’s only a matter of time before data is breached. Any connection to a sensitive data source must be properly managed and secured.

Zero trust access strategies should be employed to support the needed connections, especially between care delivery partners, Apirion said.

 

 

 

 

Tags:

Edward Gately

Edward Gately

As news editor, Edward Gately covers cybersecurity, new channel programs and program changes, M&A and other IT channel trends. Prior to Informa, he spent 26 years as a newspaper journalist in Texas, Louisiana and Arizona.

Related Content

  • what MSPs should know about ChatGPT
    What MSPs Should Know about ChatGPT
  • Making Waves
    8 Channel People Making Waves This Week at Cisco, AppDirect, Kaseya, Proofpoint, More
  • Europol said the ransomware attack was ldquocriminally mindedrdquo others have suggested that it may have originated in RussianbspThe largest number of attacks occurred in Russia and the Ukraine As security expert Ian Trump told Penton Technology39s TC DoylenbspldquoLetrsquos be clear the Russians have an absolute history of using their own people with a cavalier consideration to their own health and welfarerdquo he says ldquoSo testing your own national infrastructure in th
    A Year In, Russia-Ukraine War Prompts New Battlefield for Cybersecurity
  • IGEL Disrupt 23 Munich
    IGEL Set to Release Revamped EUC Platform with IGEL Cosmos, App Portal

Upcoming Events

View all

Channel Partners Conference & Expo

May 1, 2023 - May 4, 2023

Channel Partners Europe

June 13, 2023 - June 14, 2023

Channel Futures Leadership Summit

October 30, 2023 - November 2, 2023

Galleries

View all

Channel Conflict, Controversy: Avaya Bankruptcy, Mass Layoffs, High-Profile Execs Depart

March 28, 2023

Enterprise Connect: RingCentral, LiveVox, Google Cloud, More Intro Latest AI, CX Innovations

March 27, 2023

The Gately Report: Live Patching Beneficial Tool for MSSPs, CISA Launches Early Ransomware Notification

March 27, 2023

Industry Perspectives

View all

Selling Your MSP: Strategic vs. Financial Buyers

March 22, 2023

10 Strategic Smart Enterprise Drivers for 2023

March 16, 2023

Does Your Company Have a Virtual Water Cooler?

March 13, 2023

Webinars

View all

Equipping the Hybrid Workforce: What It Takes to Execute

March 28, 2023

Give Customers the Power: How MSPs Can Leverage Cloud Choice

April 4, 2023

DE&I Dialogue: How the Right DE&I Initiatives Can Propel Your Business

April 5, 2023

White Papers

View all

6 UCaaS Reseller Challenges and How Real World Businesses Solved Them

February 1, 2023

Frost Radar: North American UCaaS Market, 2022

February 1, 2023

The Complete Guide to White-Label UCaaS for Reseller Success

February 1, 2023

Channel Futures TV

View all

Coffee with Craig and James Episode 121: Hewlett Packard Enterprise

Aryaka ‘Driving Value to the Channel Community’ with Throttle

March 24, 2023

Real-Life M&A: Advice for a Successful Channel Deal

March 13, 2023

Coffee with Craig and James Episode 120: Ronnell Richards

March 3, 2023

Twitter

ChannelFutures

Channel Conflict, Controversy: @Avaya #bankruptcy, massive #layoffs, @RobRae exits @KaseyaCorp, latest @TMobile hac… twitter.com/i/web/status/1…

March 28, 2023
ChannelFutures

At #EnterpriseConnect, @googlecloud and @RingCentral are among companies releasing dramatic new #AI solutions for t… twitter.com/i/web/status/1…

March 28, 2023
ChannelFutures

#CPExpo preview: @EntaraCorp's journey from MSP to XSP. #cybersecurity dlvr.it/SlZblp https://t.co/NjFRMW5Psp

March 27, 2023
ChannelFutures

.@dish facing class-action lawsuits stemming from recent #ransomware attack. dlvr.it/SlZFXk https://t.co/WrDozjZRR1

March 27, 2023
ChannelFutures

.@Microsoft, @Zoom gain, @Cisco declines in 2022 #UCC market. dlvr.it/SlZ6wR https://t.co/1OhlDpb6dL

March 27, 2023
ChannelFutures

IT industry mourns death of @intel co-founder Gordon Moore #MooresLaw dlvr.it/SlYs9K https://t.co/0ZXwcF3hEP

March 27, 2023
ChannelFutures

We asked women in the communications & IT channel to relate the most surprising thing said/done to them at work. Th… twitter.com/i/web/status/1…

March 27, 2023
ChannelFutures

Channel people making waves include: @jmcbain, @NetworkMoe, @ajassy, @JulieSweet, @Elvia_Valdes_M, @GovITDave… twitter.com/i/web/status/1…

March 24, 2023

MSP 501

The industry's largest and most comprehensive partner awards program.

Newsletters and Updates

Sign up for The Channel Report, Channel Futures Update, MSP 501 Newsletter and more.

Live Channel Events

Get the latest information on the next industry-leading Channel Partners event.

Galleries

Educational slide shows and images from live events.

Media Kit And Advertising

Want to reach our audience? Access our media kit.

DISCOVER MORE FROM INFORMA TECH

  • Channel Partners Events
  • Telecoms.com
  • MSP 501
  • Black Hat
  • IoT World Today
  • Omdia

WORKING WITH US

  • Contact
  • About Us
  • Advertise
  • Newsletter

FOLLOW Channel Futures ON SOCIAL

  • Privacy
  • CCPA: “Do Not Sell My Data”
  • Cookie Policy
  • Terms
Copyright © 2023 Informa PLC. Informa PLC is registered in England and Wales with company number 8860726 whose registered and Head office is 5 Howick Place, London, SW1P 1WG.
This website uses cookies, including third party ones, to allow for analysis of how people use our website in order to improve your experience and our services. By continuing to use our website, you agree to the use of such cookies. Click here for more information on our Cookie Policy and Privacy Policy.
X