DocGo discloses cyberattack that exposed patient health data
- Organization
- DocGo
- Exploit
- Hacking
- Industry
- Healthcare
DocGo, a mobile medical services and medical transportation company operating in 26 US states and the United Kingdom, disclosed a cybersecurity incident in a Form 8-K filed with the US Securities and Exchange Commission on 7 May 2024.
The filing said a threat actor had accessed and acquired data, including certain protected health information, from what the company described as "a limited number" of healthcare records. DocGo said the intrusion was confined to its US based ambulance transportation business and that no other line of business was involved.
DocGo did not say how many patients were affected, when the intrusion began, or what categories of health information were taken. It said it had engaged an outside cybersecurity and incident response firm, removed the attacker from its systems, and found no evidence of continuing unauthorized activity. The company said it had begun notifying affected individuals.
In the same filing DocGo told investors the incident had not had a material impact on its operations and that it did not expect a material impact on its overall financial condition or ongoing results. No ransomware group or other threat actor publicly claimed responsibility. As of the reporting date the investigation was still open and the scope of the breach had not been quantified publicly.