Anna Jaques Hospital has confirmed on its web site that a ransomware assault it suffered virtually exactly a yr in the past, on December 25, 2023, has uncovered delicate well being knowledge for over 310,000 sufferers.
Anna Jaques is a not-for-profit neighborhood hospital in Massachusetts, acknowledged for delivering high-quality care and performing over 4,700 surgical procedures yearly.
As a mid-size acute hospital offering 83 beds, 200 physicians, and 1,200 workers members, AJH performs an important position in Merrimack Valley, North Shore, and southern New Hampshire, offering important healthcare companies to the native inhabitants.
In 2023, at Christmas time, Anna Jaques discovered {that a} cyberattack had impacted particular methods and took speedy motion to include the injury by taking them offline and alerting regulation enforcement.
The healthcare group launched an investigation on January 24, 2024, a couple of days after the ‘Cash Message’ ransomware group started publicly extorting the hospital on January 19.
The risk actors leaked knowledge samples allegedly stolen from Anna Jaques on their darkish internet extortion website, threatening to show delicate affected person data if their calls for weren’t met.
Subsequent updates on the Cash Message web page confirmed that the hospital’s directors did not interact with the risk actors, and the state of affairs culminated with the discharge of all knowledge on January 26.
Anna Jaques states that the forensic investigation into what the risk actors had stolen was thorough and prolonged, involving guide doc evaluation, so it was solely accomplished on November 5, 2024.
In line with the associated entry on the Workplace of the Maine Legal professional Basic, the place Anna Jaques posted a pattern of the notification it despatched to affected people yesterday, the incident has impacted 316,342 sufferers.
In line with its outcomes, the next data has been uncovered:
- Demographic data
- Medical data
- Medical insurance data
- Social Safety quantity
- Driver’s license quantity
- Monetary data
- Different private or well being data offered to Anna Jacques
“Anna Jaques has no indication that there was any fraud because of this incident,” reads the announcement.
“Nevertheless, out of an abundance of warning, commencing on December 5, 2024, Anna Jaques notified people whose data could have been impacted because of the incident to the extent Anna Jaques had their tackle.”
“Moreover, Anna Jaques reminds its workers and sufferers to stay vigilant in reviewing monetary account statements regularly for any fraudulent exercise.”
These impacted are supplied 24-month-long identification safety and credit score monitoring companies by way of Experian and 1B and are urged to contemplate putting a fraud alert or safety freeze on their credit score file.