Onix Group ransomware attack exposed data on about 320,000 patients and employees

Organization
Onix Group
Exploit
Ransomware
Industry
Real Estate and Healthcare Services

Onix Group, a Pennsylvania company with interests in commercial real estate, hospitality and healthcare, disclosed a ransomware attack that affected roughly 320,000 people. The incident was reported to the U.S. Department of Health and Human Services Office for Civil Rights, which listed 319,500 individuals.

According to the company's notice, an intruder had access to its network between March 20 and March 27, 2023, and deployed ransomware on March 27. Onix detected the encryption the same day and took its network offline. Files were taken during the week before the ransomware was launched.

The affected records covered individuals served by Onix and its affiliates, including Addiction Recovery Systems, Cadia Healthcare, Physician's Mobile X-Ray and Onix Hospitality Group. The data included names, Social Security numbers, dates of birth and scheduling, billing and clinical information. Human resources records for employees were also involved, containing names, Social Security numbers, direct deposit details and health plan enrollment information.

Onix said it secured its systems, engaged outside cybersecurity experts and completed a review of the affected files. Notification letters were mailed on May 26, 2023. The company set up a dedicated assistance line and offered complimentary credit monitoring and identity theft protection to those affected, and said it had strengthened its security controls after the incident.

Sources