Incident Report

Rx Marks the Spot: The Sav-Rx Breach and Why Healthcare is Prone to Cyber Ills

By

Matt Berns, Access Point Consulting

By

Access Point Consulting

Incident Overview

On October 3rd, the prescription management company Sav-Rx experienced a significant cyberattack that resulted in the exposure of sensitive information. The incident was discovered on October 8th when the company experienced a network disruption. Despite the breach, Sav-Rx successfully restored its IT system within 24 hours. An investigation, which concluded on April 30th, revealed that the hackers accessed non-clinical systems and obtained files related to the company's medication benefits management services. The company has since notified law enforcement and affected individuals.

Discovery and Immediate Response

The initial signs that raised suspicion about the incident included a network disruption that occurred on October 8, prompting further investigation. The impact of the cyberattack on Sav-Rx was substantial. The breach affected nearly 3 million individuals, exposing sensitive information including eligibility data, insurance identification numbers, and Social Security numbers. However, the company's pharmacy systems, including those related to their mail-order pharmacy, were not impacted. Not all customers and health plan participants were affected, and the disruption to prescription services was minimal as all prescriptions were shipped on time. The investigation aimed to provide accurate information to affected individuals, and all victims have been offered two years of credit monitoring services from Equifax.

Containment and Communication

In response to the ransomware attack, Sav-Rx took immediate action to contain the incident and limit its spread. The company's IT system was restored within 24 hours, ensuring that prescription services continued without interruption. An incident response plan was in place and proved adequate in addressing the breach. The incident was communicated to stakeholders, including executives, employees, customers, and regulatory bodies. Although Sav-Rx did not disclose whether a ransom was issued or paid, they worked with outside cybersecurity experts to ensure that any data acquired from their IT system was destroyed and not further disseminated.

The Vulnerability of Healthcare Data

The Sav-Rx incident, and many more recent attacks, highlight the critical need for robust cybersecurity measures in the healthcare sector, given the high value placed on keeping health data private and the increasing sophistication of cyber threats. Healthcare data is particularly vulnerable due to several factors. The rapid digitization of healthcare, including electronic health records, remote monitoring, and wearable devices, has increased the volume of data available. This makes healthcare data a lucrative target for hackers, who exploit vulnerabilities within the system.

Historical Underinvestment in IT Security

Historically, the healthcare sector has been underprepared and underinvested in IT security, leading to an increased risk of breaches. Additionally, the high connectivity within healthcare networks and the ease with which data can be ransomed due to its sensitive nature contribute to the sector's attractiveness to cybercriminals.

The Value of Health Data and Legal Repercussions

Healthcare data is notably easy to ransom because individuals place a high value on maintaining the privacy of their medical information. The impact of such breaches is significant, as individuals cannot change their medical history or prescriptions like they might change a password or credit card number. This places an immense responsibility on organizations holding health data to protect themselves and their patients against cyber threats. They must adopt rigorous cybersecurity protections, ensure rapid response capabilities when attacks occur, and implement resilience measures such as backups to quickly restore systems.

Legal Actions and Privacy Rights

In light of these challenges, there is a growing trend of patients taking legal action against companies that fail to protect their data adequately. The introduction of a right to sue for serious invasions of privacy under an amended Privacy Act signifies an important change, enabling individuals whose sensitive health information was compromised to pursue damages from breached companies.

Resources

Trending Articles & Security Reports

Resources

CyberWatch

November 22, 2024

Patch Updates, New Malware Threats, and the Ongoing Supply Chain Battle

On this episode of the CyberWatch podcast, there are updates to software across the application and OS spectrum. New malicious campaigns are threatening victims of all sizes, and researchers have performed dissections on malware to give defenders new clues about just what it is they're fighting. All this today, in CyberWatch.

Find out more
October 25, 2024

Ransomware, Supply Chain Attacks, and Nation-State Threats

CyberWatch, by Access Point Consulting, is your weekly source for emerging cybersecurity news, regulatory updates, and threat intelligence. Backed by experts in security consulting, regulatory compliance, and security operations, Access Point enables you to manage cyber risks, respond to incidents, and drive innovation in your company. Read here or on our website; listen on Spotify or Apple Podcasts; or watch on YouTube.website; listen on Spotify or Apple Podcasts; or watch on YouTube. .

Find out more
October 7, 2024

VINs and Losses: How Hackers Take Kias for a Ride

In the age of smart cars and connected devices, convenience often comes with hidden risks. A recently discovered critical vulnerability in Kia vehicles serves as a stark reminder of how our increasingly digital world is making cars new targets for cyberattacks. This vulnerability allowed hackers to remotely control various vehicle functions—using nothing more than a car's license plate number. It highlights the growing threat of cyberattacks on connected cars and the importance of cybersecurity in the automotive industry.

Find out more