BORN Ontario says MOVEit breach exposed health data on 3.4 million people
- Organization
- BORN Ontario (Better Outcomes Registry & Network)
- Exploit
- Supply Chain Attack
- Industry
- Healthcare
The Better Outcomes Registry and Network, Ontario's provincially funded perinatal, newborn and child registry known as BORN Ontario, disclosed in late September 2023 that attackers had copied files from its systems by exploiting a vulnerability in the MOVEit managed file transfer product made by Progress Software. The registry said it was made aware of the vulnerability late on the evening of May 31, 2023. No exact date for the copying was disclosed.
BORN Ontario put the number of affected people at about 3.4 million, made up of roughly 1.4 million individuals who received pregnancy care and about 1.9 million newborns and children. The records spanned care delivered between January 2010 and May 2023.
Exposed fields included names, addresses, dates of birth, health card numbers, dates of service, laboratory and screening test results, pregnancy risk factors, birth types and procedures, and pregnancy and birth outcomes. Fertility treatment records covering in vitro fertilization and egg banking were also involved.
The registry notified the Ontario Provincial Police and reported the incident to Ontario's Information and Privacy Commissioner on June 14, 2023, roughly three months before it notified the public. The commissioner opened a review that remained open at the time of reporting. BORN said it had stopped using MOVEit and was monitoring for signs the data had surfaced online, telling reporters it had seen none. The Clop extortion group was responsible for the wider MOVEit campaign.