Four small care providers tie breach notices to ransomware claims

Four small care providers tied fresh breach notices to ransomware activity, with claims from Devman 2.0, Brain Cipher, and Interlock attached.

MedRisk Staff
By
2 Min Read

Breach letters mailed this summer by four small care providers all carry the fingerprints of extortion crews, from the Devman 2.0 claim against a North Carolina pain practice to an Interlock-linked ransomware hit on a chiropractic office in Maine.

Crystal Coast Pain Management, a division of East Carolina Anesthesia Associates, said intruders copied files containing names, birth dates, medical information, and Social Security numbers, with suspicious activity first spotted in January and the theft confirmed in April. The practice wiped and rebuilt affected systems. Golden State Orthopedics & Spine, which runs 13 locations around the San Francisco Bay Area, reported unauthorized access on July 2 touching similar data plus health insurance details; Brain Cipher claimed it took 150 GB, though the practice has not said how many patients were affected.

Up to 5,000 patients of Gardiner Family Chiropractic may be caught in a July 17 ransomware attack involving file encryption and data theft, according to the clinic’s report to federal regulators. The Maine office said the attack was blocked, no ransom was paid, and affected devices were wiped and replaced. BestCare Treatment Services, an Oregon behavioral health provider, reported 4,216 affected individuals after spotting unauthorized network access on June 15, with letters mailed August 10.

None of the four providers has reported evidence of data misuse, and several are offering credit monitoring.

Share This Article