NextGen Healthcare breach exposed data on more than one million patients

Organization
NextGen Healthcare
Exploit
Credential Compromise
Industry
Health IT

NextGen Healthcare, a vendor of electronic health record and practice management software, disclosed in May 2023 that attackers had taken personal data belonging to just over one million people. The breach notification filed with the Maine Attorney General's office put the figure at 1,049,375 individuals, including roughly 4,000 Maine residents.

The company said it identified suspicious activity on March 30, 2023 and that its investigation found unauthorized access to a database between March 29 and April 14. NextGen attributed the intrusion to client credentials that it said appeared to have been stolen from other sources or incidents unrelated to the company.

The exposed records included names, addresses, dates of birth and Social Security numbers. NextGen holds that information on behalf of the customer practices it serves. The company said its investigation revealed no evidence of access to or impact on any health or medical records.

NextGen reset passwords, engaged outside cybersecurity specialists, notified law enforcement and began writing to affected individuals in late April. It offered 24 months of complimentary fraud detection and identity theft protection. The incident followed a separate attack on the company in January 2023 that the ALPHV group claimed.

Sources