Bloom Hearing Specialists ransomware attack exposed patient and staff records

Organization
Bloom Hearing Specialists
Exploit
Ransomware
Industry
Healthcare

Bloom Hearing Specialists, an audiology group running hundreds of clinics across Australia and New Zealand, became aware on July 5, 2024 of a ransomware attack that encrypted data on several systems and affected a number of its applications. The business published an initial security notice on July 9 and confirmed in late August that data had been stolen.

The affected entities included Active Hearing Pty Ltd, which trades as Bloom hearing specialists, TotalCare Hearing and Chris Laird's YP Audiology, along with HearClear Audiology Pty Ltd and Hutchinson Audiology Clinics Pty Ltd.

The company said the compromised information covered current, former and prospective patients as well as current and former employees and contractors. Categories it listed included names, addresses, contact details and dates of birth, audiograms and appointment notes, bank account and other financial details, insurance information, employment records and government identifiers such as Medicare, Centrelink, DVA, NDIS and driver's licence numbers. Neither the company nor Australian media put a figure on the number of people involved.

Bloom notified the Office of the Australian Information Commissioner, the New Zealand Office of the Privacy Commissioner and law enforcement in both countries, and arranged free identity protection support through IDCare. Customers were emailed from August 22, 2024, and some told Australian media that notification had been slow and support difficult to reach.

Sources