NorthStar EMS notifies about 82,000 patients of 2022 network intrusion

Organization
NorthStar Emergency Medical Services
Exploit
Hacking
Industry
Emergency Medical Services

NorthStar Emergency Medical Services, an ambulance provider based in Tuscaloosa, Alabama, told patients in March 2023 that an intruder had reached data on its network the previous autumn.

The company said it detected unusual activity in its environment on September 16, 2022, secured the environment and hired independent cybersecurity experts to investigate. That review found that an unauthorised actor had accessed certain data stored on the network. NorthStar completed its determination of who was affected on March 8, 2023 and began mailing written notices on March 14.

The information that may have been involved included names, Social Security numbers, dates of birth, patient identification numbers, treatment information, Medicare or Medicaid numbers and health insurance details. Local outlet the Tuscaloosa Thread reported that the notification covered about 82,000 current and former patients, while some other coverage put the figure at more than 80,000. NorthStar's own notice did not give a number.

NorthStar said it had found no evidence that the data accessed had been misused. The company reported the incident to law enforcement, said it had strengthened its security controls and set up a dedicated toll-free line for patients with questions. Almost six months passed between detection and patient notification.

Sources