Yale New Haven Health data breach affects 5.5 million patients
耶鲁纽黑文健康系统于3月遭受网络攻击,导致550万患者个人信息被盗,包括姓名、出生日期、地址等敏感数据,但未涉及财务或医疗记录。该机构已聘请专家进行调查并通知相关部门,同时向受影响患者提供信用监控服务,事件已引发集体诉讼准备。 2025-4-24 14:30:32 Author: www.bleepingcomputer.com(查看原文) 阅读量:6 收藏

Yale NewHaven Health Hospital

Yale New Haven Health (YNHHS) is warning that threat actors stole the personal data of 5.5 million patients in a cyberattack earlier this month.

YNHHS is a nonprofit healthcare network in Connecticut, the largest in the state, providing comprehensive care across five hospitals and 360 outpatient locations. It employs 30,000 health professionals and has an annual revenue of over $5.6 billion.

On March 11, 2025, the organization first reported that it was dealing with a cybersecurity incident that occurred three days earlier. This incident caused IT system disruptions but did not impact patient care.

Yale New Haven Health hired Mandiant to help with system restoration and forensic investigation while federal authorities were notified about the incident.

On April 11, 2025, YNHHS informed the public that its investigation into the incident confirmed a data breach that may have exposed sensitive patient information to unauthorized actors.

The stolen information varies by patient and includes the following:

  • Full name
  • Date of birth
  • Home address
  • Telephone number
  • Email address
  • Race/ethnicity
  • Social Security number (SSN)
  • Patient type
  • Medical record number

It was clarified that the exposure did not include financial information, medical records, or treatment details.

Starting on April 14, 2025, YNHHS mailed letters to patients confirmed to have been impacted by the incident, enclosing instructions on enrolling in complimentary credit monitoring and identity protection services for those with their SSN exposed.

A new entry on the U.S. Department of Health and Human Services breach portal confirmed that the data breach impacted 5,556,702 patients.

Figure
Source: ocrportal.hhs.gov

Given the extent of the impact, class action lawsuits are already being prepared by law firms representing impacted individuals seeking reimbursement for the exposure of their sensitive information.

At the time of writing, no ransomware groups have taken responsibility for the attack at Yale New Haven Health, so the attackers remain unknown.


文章来源: https://www.bleepingcomputer.com/news/security/yale-new-haven-health-data-breach-affects-55-million-patients/
如有侵权请联系:admin#unsafe.sh