Data breach at French healthcare services firm puts millions at risk

20 tháng 2, 2024

French healthcare services firm Viamedis suffered a cyberattack that exposed the data of policyholders and healthcare professionals in the country.


Though the company's website remains offline at the time of writing, an announcement was posted on LinkedIn warning of the data breach.


The data exposed in the attack includes a beneficiary's marital status, date of birth, social security number, name of health insurer, and guarantees open to third-party payment. 


The company has clarified that the breached systems did not store people's banking information, postal details, telephone numbers, and email addresses.




Viamedis data breach notice




For healthcare professionals, Viamedis says they will be sending different notifications about what data was exposed.


Viamedis has informed impacted health organizations, filed a complaint with the public prosecutor, and notified the authorities (CNIL, ANSSI) accordingly. Currently, the company continues to investigate the impact of the cyberattack.


Regarding the scale of the breach, Viamedis has not stated the number of exposed individuals, but it is known that it manages payments for 84 healthcare organizations covering 20 million insured individuals.


The firm's General Director, Christophe Cande, told Agence France-Presse (AFP) that an investigation is underway to determine the scope of the breach.


"To date, we do not have the number of insured individuals impacted; we are still in the process of investigation." - Cande (GD Viamedis)


Cande has also clarified that the cyberattack wasn't ransomware. Instead, he said a successful phishing attack on an employee allowed the threat actor to breach its systems.


One of the organizations working with Viamedis, Malakoff Humanis, has posted a notice on its website confirming the indirect impact of the Viamedis data breach.



Malakoff's notice banner




The company is also sending data breach notifications to impacted customers to inform them of the cyberattack and disruption of services.


Their message reiterates the information disclosed in the Viamedis notice and assures clients that no banking, medical, or contact details stored on the platforms have been compromised.


Malakoff Humanis says access to user accounts and reimbursement claims remains available. However, the temporary disconnection of the Viamedis platform is expected to affect the provision of certain healthcare services.


Other service providers using Viamedis, including Carte Blanche Partenaires, Itelis, Kalixia, Santéclair, and Audiens, are expected to experience similar situations.


Local media in France reported that Viamedis wasn't the only target of the cyberattack. Reportedly, a company named "Almerys," which is also a payment processor for healthcare organizations, was also targeted.



Source: bleepingcomputer.com


Bạn cũng có thể quan tâm

4 tháng 6, 2024
Bộ định tuyến chơi game TP-Link Archer C5400X dễ mắc phải các lỗi bảo mật có thể cho phép kẻ tấn công từ xa, không được xác thực thực thi các lệnh trên thiết bị.
3 tháng 6, 2024
Ngày 27 tháng 5 Check Point đã cảnh báo rằng các tác nhân đe dọa đang nhắm mục tiêu vào các thiết bị VPN truy cập từ xa của Check Point trong một chiến dịch đang diễn ra nhằm xâm phạm mạng doanh nghiệp.
31 tháng 5, 2024
Công ty quản lý đơn thuốc Sav-Rx cảnh báo hơn 2,8 triệu cá nhân ở Hoa Kỳ việc họ đã bị vi phạm dữ liệu và dữ liệu cá nhân của họ đã bị đánh cắp trong một cuộc tấn công mạng năm 2023.
Thêm bài viết
Share by: