HMG Healthcare breach hit residents and staff at 40 nursing facilities
- Organization
- HMG Healthcare
- Exploit
- Hacking
- Industry
- Healthcare
HMG Healthcare, a Texas-based operator and manager of long-term care facilities, disclosed in January 2024 that attackers had stolen unencrypted files containing personal and medical information belonging to residents and employees.
The company said the intrusion took place in August 2023 but was not discovered until November 2023. Forty affiliated nursing and rehabilitation facilities in Texas and Kansas were affected, some of which operate under names other than HMG, including Tanglewood Health and Rehabilitation and Smoky Hill Health and Rehabilitation.
The files held names, dates of birth, contact details, health and medical treatment information, Social Security numbers and employment records. HMG said the data on the compromised server was not encrypted and that it could not establish precisely which records had been taken, describing that identification as "not feasible." Current and former residents and staff were advised to monitor account statements and credit reports.
In its filing with the Texas Attorney General, HMG reported roughly 75,000 affected Texas residents. Its notification put the total number of individuals whose protected health information was exposed at up to 80,000 across the 40 affiliated facilities. Chief executive Derek Prince confirmed the breach and said the company had strengthened its data security controls. HMG did not say publicly whether any payment was made to keep the stolen files from being published, and no ransomware group had claimed the attack as of the disclosure.