Arietis Health reported a MOVEit breach affecting nearly 2 million patients
- Organization
- Arietis Health, LLC
- Exploit
- Hacking
- Industry
- Healthcare Billing
Arietis Health, a Florida based revenue cycle management firm that handles medical billing for provider groups, reported that patient data was taken from its file transfer server during the mass exploitation of Progress Software's MOVEit Transfer product. The company said Progress alerted customers to the zero-day flaw on May 31, 2023 and that it secured and patched its server in line with the vendor's instructions.
A subsequent review found that attackers had reached files before the patch was applied. Arietis confirmed the unauthorized access on July 26, 2023 and notified its client NorthStar Anesthesia on August 3. Notification letters to individuals began going out at the end of September 2023.
The filing Arietis submitted to the U.S. Department of Health and Human Services Office for Civil Rights listed 1,975,066 people. The HIPAA Journal reported the data covered 54 entities served by NorthStar Anesthesia, the anesthesia group for which Arietis performed billing work. Most, but not all, of the listed entities are anesthesia, pain or gastroenterology practices. Exposed fields included names, dates of birth, addresses, Social Security numbers, driver's license or state identification numbers, medical record and patient account numbers, health insurance details, diagnosis and treatment information, clinical and prescription records and provider names.
Arietis said it had no evidence the information had been misused and offered complimentary credit and identity monitoring to those it notified. The wider MOVEit campaign, attributed to the Clop extortion group, affected thousands of organizations during 2023.