INTEGRIS Health said a 2023 breach exposed data on 2.4 million patients

Organization
INTEGRIS Health
Exploit
Hacking
Industry
Healthcare

INTEGRIS Health, Oklahoma's largest not-for-profit health system, reported in February 2024 that a cyberattack the previous November had exposed the personal information of about 2.4 million people. The figure filed with the U.S. Department of Health and Human Services was 2,385,646 individuals.

An unauthorized party reached the health system's network on November 28, 2023 and copied files. The attackers did not encrypt systems, and INTEGRIS said patient care was not interrupted.

The health system posted a public notice on December 24, 2023 after patients began receiving extortion emails sent directly by the attackers. The messages pointed recipients to a site on the Tor network where, according to court filings, they were told they could pay $50 to have their own records deleted or $3 to view records belonging to someone else, with a deadline of January 5, 2024. INTEGRIS urged patients not to engage.

Exposed information varied by person and included names, dates of birth, contact and demographic details and Social Security numbers. INTEGRIS said employment records, driver's license numbers, financial and payment data and account credentials were not accessed.

Litigation followed and was consolidated into a class action alleging that more than 2.4 million people were affected, including hundreds of thousands of minors. INTEGRIS later agreed to a $30 million settlement.

Sources