2.8 million people affected by data breach at Baylor Genetics testing and diagnostic firm


Baylor Genetics, a US-based clinical diagnostic laboratory, suffered a cyberattack in which it lost sensitive data on 2.8 million people – both patients and employees.

In a security update posted on its website earlier this week, the company said it spotted the intrusion in a “limited portion” of its IT environment on or around June 15. Subsequent investigation determined that both patients and employees have had their data stolen, including those who are not working at Baylor anymore.

For patients, crooks stole names, dates of birth, medical testing information, laboratory test results, and “potentially health insurance information, as well as Social Security number”. SSNs, Baylor Genetics stressed, were taken from a “very limited subset of patients”.

Read more…
Source:  Tech Radar News


Sign up for the Cyber Security Review Newsletter
The latest cyber security news and insights delivered right to your inbox


Related:

  • New Jersey: Montclair, Westwood Hospitals Divert Ambulances After Cyber Attack

    November 27, 2023

    Two hospitals in North Jersey are diverting ambulances from their emergency rooms after a cyber attack, authorities confirmed Monday. The attack impacted the computer systems at Mountainside Medical Center in Montclair, and Pascack Valley Medical Center in Westwood. Read more… Source: MSN News  

  • Updates to U.S. State Data Privacy Laws: What You Need to Know

    November 22, 2023

    The United States is trying to catch up with global data privacy laws passed in recent years. While the European Union (EU) passed the General Data Protection Regulation (GDPR) which went into effect in 2018, the U.S. has not been able to pass its version called the American Data Privacy and Protection Act (ADPPA) into ...

  • FCC wants to improve cyber protections for schools, libraries

    November 21, 2023

    Ransomware attacks and cybersecurity threats against schools are multiplying and have led to some dramatic consequences. Last year, the Los Angeles Unified School District was hit by a ransomware attack that resulted in hackers posting 500 gigabytes of stolen data online, after the district’s superintendent refused to pay the ransom. The attack compromised about 2,000 student ...

  • U.S. DOD strategy warns emerging tech is ‘at the forefront’ of information threats

    November 21, 2023

    The Pentagon publicly released its strategy for operating in the information environment – which covers both physical and digital sources of information – on Friday, outlining how the agency plans to modernize its collecting, processing and sharing of data to better counteract adversaries’ weaponization of the internet and emerging technologies. DOD “must embrace a cultural shift ...

  • #StopRansomware: LockBit 3.0 Ransomware Affiliates Exploit CVE 2023-4966 Citrix Bleed Vulnerability

    November 21, 2023

    The Cybersecurity and Infrastructure Security Agency (CISA), Federal Bureau of Investigation (FBI), Multi-State Information Sharing & Analysis Center (MS-ISAC), and Australian Signals Directorate’s Australian Cyber Security Center (ASD’s ACSC) are releasing this joint Cybersecurity Advisory (CSA) to disseminate IOCs, TTPs, and detection methods associated with LockBit 3.0 ransomware exploiting CVE-2023-4966, labeled Citrix Bleed, affecting Citrix ...

  • Binance CEO pleads guilty to money laundering charges

    November 21, 2023

    The Binance chief executive, Changpeng Zhao, has resigned after pleading guilty to money laundering violations. The Justice Department said it was requiring Binance, the largest crypto-exchange in the world, to pay $4.3bn (£3.4bn) in penalties and forfeitures. It said Binance had helped users bypass sanctions across the world. Read more… Source: BBC News