CyberInsider reports that ShinyHunters claims to have hit a major healthcare software provider, and that hundreds of millions of records have been acquired, although the number of unique patients is not yet determined. McKesson has acknowledged that it is investigating the claims.
The ShinyHunters threat group claims it compromised McKesson and obtained data on over 284 million patient records, including highly sensitive medical, identity, prescription, and healthcare provider information.
CyberInsider reviewed samples privately provided by the threat actor that appear consistent with the types of information described in the data breach claims.
[…]
Update: ShinyHunters has further clarified to CyberInsider that 284 million records were obtained, linked to tens of millions of patients, but the exact number of people in the breach is not yet known.
According to ShinyHunters, the allegedly stolen patient data includes:
- Identity and contact information: full names, home addresses, dates of birth, phone numbers, email addresses, and Social Security numbers.
- Healthcare identifiers: patient IDs, medical record numbers (MRNs), and Medicaid numbers.
- Medical information: illnesses and diagnoses, allergies, medications, disabilities, patient notes, appointment details, and physician information.
- Highly sensitive records: hospice and terminal illness information, causes of death, autopsy details, sexual orientation, and other personal status information.
- Predictive health data: disease-risk assessments, including cancer predictions linked to individual patients.
- Prescription and billing records: medication orders, invoice and billing information, shipment addresses, dates, and tracking numbers.
Read more at CyberInsider.
