AnMed probe finds SSNs and financial data in stolen files

AnMed says files copied during its cyber incident may include patient Social Security numbers, driver's license numbers, and financial account information.

MedRisk Staff
By
2 Min Read

AnMed, the nonprofit health system built around a 461-bed medical center in Anderson, South Carolina, says files copied during the cyber incident first disclosed on July 26 may include patient Social Security numbers, driver’s license numbers, and financial account information. The health system said its investigation is nearly complete and has confirmed unauthorized copying of files from certain network systems.

The disclosure is the first concrete detail about what the intruders took. AnMed acknowledged on August 21 that some data was exposed while casting doubt on the extortion group’s claim of roughly 6 TB of stolen records. That group hijacked AnMed’s Facebook page on August 11 to post ransom demands and claimed the haul included sensitive record categories such as sexual assault and mental health information, which AnMed has not confirmed.

AnMed plans to contact affected individuals directly once its review wraps up and has said it will offer support to people whose data was touched. Telephone lines, electronic health record access, and the MyChart patient portal are back in service.

For other health systems, the timeline is the lesson: more than a month passed between the initial lockdown and confirmation of the data categories involved. Breach response plans should assume data-type confirmation will lag the first disclosure and prepare notification templates well in advance.

Share This Article