On Jan. 8, the vendor informed the Jefferson, S.C.-based practice that it had experienced a ransomware attack. Cyberattackers used compromised credentials to access the vendor’s system Sept. 23, 2020.
The attackers accessed Sandhills’ system on Nov. 15 and extracted Sandhills’ data before the ransomware attack was launched on Dec. 3.
Sandhill determined Social Security numbers, driver’s license numbers and birth dates were among information that was affected. Medical records, bank account numbers and credit card numbers were not affected. The vendor paid the ransom and was assured copies of the patient data were deleted.
More articles on cybersecurity:
Texas Medicaid subcontractor dumped after data breach
Pittsburgh hospital employee inappropriately disclosed patient health information, UPMC says
65,000 Humana members’ information exposed in wrongful records access incidents
At the Becker's 11th Annual IT + Revenue Cycle Conference: The Future of AI & Digital Health, taking place September 14–17 in Chicago, healthcare executives and digital leaders from across the country will come together to explore how AI, interoperability, cybersecurity, and revenue cycle innovation are transforming care delivery, strengthening financial performance, and driving the next era of digital health. Apply for complimentary registration now.