Reventics breach exposed data on more than 250,000 patients
- Organization
- Reventics, LLC
- Exploit
- Ransomware
- Industry
- Healthcare Services
Reventics, a Colorado revenue cycle management company that handles billing and coding work for healthcare providers, disclosed a breach of its network that affected patients of several of its client organizations. The company said it detected an intruder on December 15, 2022 and confirmed on December 27 that data had been taken.
Reventics reported 250,918 affected individuals to the U.S. Department of Health and Human Services. The compromised information varied by person and included names, addresses, dates of birth, medical record and patient account numbers, Social Security numbers, driver's licence numbers, health plan names and identification numbers, financial details, procedure and service codes and clinical data.
The Royal ransomware group claimed the attack and demanded payment to keep roughly 16GB of stolen files offline. When it was not paid, Royal began publishing the material on its leak site in February 2023. Reventics' own notice described a cyber intruder and did not use the word ransomware.
Breach notices began appearing in February 2023, including one posted by Regional One Health in Memphis, which used Reventics as a business associate. Reventics said it contained the intrusion, brought in outside cybersecurity consultants, added encryption controls, revised its security risk analysis process and expanded staff training. A proposed class action was subsequently filed against the company in the U.S. District Court for the District of Colorado.