Center for Vein Restoration breach exposed data on 446,094 patients and staff
- Organization
- Center for Vein Restoration
- Exploit
- Hacking
- Industry
- Healthcare
Center for Vein Restoration, a Maryland-headquartered operator of vein treatment clinics across the United States, disclosed in December 2024 that an unauthorized party had reached files containing patient and employee information.
The provider said it identified suspicious activity on its network on October 6, 2024. Its investigation determined that files had been accessed and potentially copied. It reported the breach to the U.S. Department of Health and Human Services as affecting 446,094 individuals.
According to the notification, the data involved varied from person to person and could include names alongside addresses, dates of birth, Social Security numbers, driver's licence numbers, medical record numbers, diagnoses, laboratory results, medications, treatment information, health insurance details, provider names, dates of treatment and financial information. Records relating to current and former employees were also caught up in the incident.
Center for Vein Restoration said it isolated the affected systems, notified law enforcement, engaged forensic specialists and put additional safeguards and technical monitoring in place. It mailed notification letters to the last known addresses of affected individuals and offered complimentary identity theft protection services.
The company did not explain how the intrusion occurred or identify the attacker, and no ransomware group publicly claimed responsibility, as SecurityWeek noted at the time.