MCNA Dental breach affected 8.9 million people after LockBit attack

Organization
MCNA Dental
Exploit
Ransomware
Industry
Health Insurance

Managed Care of North America, which operates as MCNA Dental and administers government-sponsored dental benefits under Medicaid and CHIP, notified 8,923,662 people that their information had been taken in a ransomware attack.

The company said it found unauthorized activity in its systems on March 6, 2023, and that investigators traced the initial intrusion back to February 26. The LockBit ransomware group claimed the attack on March 7 and posted the first samples of stolen files.

LockBit said it held 700GB of data and demanded 10 million dollars. MCNA did not pay, and on April 7 the group published the full set of files on its leak site, making them freely downloadable.

MCNA completed its review of the affected data on May 3 and issued its breach notice at the end of May. Exposed information included names, addresses, dates of birth, phone numbers, email addresses, Social Security numbers, driver's license and other government identification numbers, health insurance plan details and Medicaid or Medicare identifiers, and treatment records covering dental visits, providers and orthodontic care. Because the plans cover children, some records related to a parent, guardian or guarantor rather than to the patient.

The company said it had remediated the incident, strengthened its systems and contacted law enforcement, and it offered 12 months of identity protection and credit monitoring through IDX. TechCrunch described it as the largest health information breach reported in 2023 to that point.

Sources