back to article Heartless hackers break into Florida cancer clinic network – 2.2 million records exposed

US cancer clinic 21st Century Oncology has admitted that a breach on its systems may have exposed private information on 2.2 million patients and employees. Unidentified hackers were able to access sensitive patient and employee data, including names, SSNs, diagnosis and treatment details and insurance information after …

  1. TonyJ

    Scumbags

    That is all.

  2. Anonymous Coward
    Anonymous Coward

    This is

    exactley what will happen to the UK health.care.data.slurp. or whatver the hell it's calling itself.

    Guaranteed...

    That much data on that many people is just too much of a goldmine to not hack.

    Either by social engineering or just careless practice and it will be a fuck-ton more than 2.2 million records..

    Once THAT genie is out of the bottlle, there is no putting it back. Trust in the system is low now, imagine how low* it will be after the inevitable data theft.

    *if it could get any lower...

  3. JimmyPage Silver badge
    Stop

    Patients *and* employees ?

    Is it just me, or does this suggest a system not fit for purpose in the first place ?

    Let's hope some of the employees exposed were the CEO and board of directors ...

    1. Hans Neeson-Bumpsadese Silver badge

      Re: Patients *and* employees ?

      To me it seems reasonable to have both within the same system...patient data cos the system is about patients, and employee data because presumably there's a list of employees allowed to access the data, references in patient data to doctors/specialists who have treated patients, etc.

  4. x 7

    are there now any USA Health Care providers or insurers left who HAVEN'T been hacked in the last year or so?

    1. Chris G

      When you think about it, who are the people most likely to be interested in people's health?

      Oh! Medical Insurance companies andf health care providers!

      What more can I say?

  5. Anonymous Coward
    Anonymous Coward

    Cancer

    One might wish it on such scumbags

  6. asdf

    not to be that guy

    Was going to go off on Florida's broken state government and regulation (low hanging fruit) but sure this is probably coming soon to where you live as well.

  7. Anonymous Coward
    Anonymous Coward

    This is precisely why...

    ...the judicial system needs to mead out serious prison sentences for hackers. The crims should not see the light of day for a minimum of 25 years. You won't be able to stop all hacking but you can bet if these lowlifes are in solitary confinement for 25 years, they won't be hacking any time soon.

    1. Gene Cash Silver badge

      Re: This is precisely why...

      Not just the hackers. The company board members need a serious beating with a clue stick too.

      I can't believe they get informed of a hack BY THE FBI and nobody goes to prison.

    2. Graham Marsden
      Facepalm

      Re: This is precisely why...

      Excuse me, but I think you've mistaken this for the Daily Mail comments page...

  8. Pascal Monett Silver badge
    Pint

    Well would you look at that

    Seems our daily quota has been reached for the day.

    Time for a cold one, then.

  9. Blofeld's Cat
    FAIL

    Hmm...

    Perhaps the headline could have read: "Cancer clinic fails to protect the data of its patients and employees - hackers blamed".

    That "the clinic was informed of the breach by the FBI" does not really inspire confidence in the way access to the data was controlled and/or audited.

    "... no evidence that the leaked data has been misused ...".

    Surely the fact that somebody accessed it (and the FBI noticed before the company did) could be considered evidence of misuse.

  10. Terry 6 Silver badge

    Electricity

    As it happens, today we read that the recommendation is that 'leccy companies keep, and share, a database of customers who have been on the standard tariff for a while.

    There will have been organised gangs planning to hack this even before the ink on the report had dried

    The value of that data to scammers is beyond imagining.

    "Hello, is that Mr Elbow of the Grange, Wimbleshire? I'm calling from your electricity company EDF ( or whatever). Could you just tell me your password and bank account details and we will send you a special refund.

    Or something along these lines. Probably more sophisticated than I can imagine.

    1. Mark 85

      Re: Electricity

      Define "sophisticated"? The Nigerian scams are still working.... the MS Support Center "virus" scams are still working. There's more but you get the idea. Doesn't take much to pull off a scam lately.

      1. Terry 6 Silver badge

        Re: Electricity

        Mark, I was being optimistic; or something.

  11. John Brown (no body) Silver badge

    Hang on a mo'

    "The clinic was informed of the breach by the FBI in November 2015 but the Feds asked 21st Century to hold off from disclosing the incident until a thorough investigation had been completed. This explains why the clinic only went public in admitting the breach this week. Hackers accessed the systems at the beginning of October last year."

    What exactly were the FBI up to that they were romping through the access logs or whatever and found the data had been copied? Are they working on the side as commercial pen testers now? Or is this something where companies invite them to look over the systems? It's obviously not live monitoring so it's not like the were responding to a "burglar alarm". Do they do this unannounced and will they be do doing the same with the providers "protected" by Privacy Shield holding EU data? How deep is their access?

  12. Anonymous Coward
    Anonymous Coward

    How low

    Damn low!

  13. Raedwald Bretwalda

    no evidence that the leaked data has been misused

    "there’s no evidence that the leaked data has been misused"

    What reason would anyone have to break in to access such data other than to misuse it? Given that knowing much of that data would constitute misuse . Or are there guerilla free oncologists out there trying treat patients locked into 21st Century Healthcare's methods?

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon

Other stories you might like