Bitmarck took systems offline across German health insurers after a cyberattack
- Organization
- Bitmarck
- Exploit
- Hacking
- Industry
- Healthcare IT
Bitmarck, one of the largest IT service providers to Germany's statutory health insurance system, disclosed in late April 2023 that it had been the target of a cyberattack. The company said its early warning tools detected a breach of an internal system, after which it shut down customer-facing and internal systems in a controlled manner. In some cases entire Bitmarck data centers were taken offline.
Bitmarck said that, on the state of knowledge at the time, no data theft had been identified and that customer, patient and insured persons' data had not been endangered. It cautioned that an investigation by external experts was still under way. The company said it could not answer questions about who carried out the attack or how the intruders got in.
The shutdown had wide reach because Bitmarck's software underpins operations at dozens of German health insurers. Electronic sick leave certificates, which employers rely on to authorize sick pay, became unavailable, and Bitmarck warned that pharmacies it works with might also experience technical problems. SBK, one of the larger insurers, told its members that its telephone, email and app services were down as a result.
Bitmarck notified law enforcement and regulators and engaged outside security specialists. It restored a limited set of services quickly but warned customers to expect long delays, saying restart speed would vary by customer and that it was prioritizing security over speed.