Veterans Health Administration notifies 2,302 veterans after vendor attack
- Organization
- U.S. Veterans Health Administration
- Exploit
- Third-Party Data Breach
- Industry
- Government Healthcare
The US Veterans Health Administration said in late November 2024 that it was writing to 2,302 veterans whose protected health information may have been exposed in a cyberattack on a server run by DBP, Inc., a contracted medical transcription vendor.
According to the agency, files on the vendor's server were locked down by the attacker and may also have been copied. The affected transcribed documents contained some or all of a veteran's full name, medical record information and Social Security number. VHA staff conducted an investigation and determined that the attack did not affect any medical record information held in the VA's own electronic health record system.
The notifications spanned six VA health care systems. Amarillo accounted for the largest group at 1,069 veterans, followed by Minneapolis with 616, Boston with 386, Togus in Maine with 144, Connecticut with 37 and Baltimore with 25.
VHA said the compromised server was shut down and disconnected from the internet, and that DBP purchased replacement hardware and moved to implement strengthened security controls. Affected veterans were told they would receive a privacy notification letter setting out the details of the incident, and the agency opened a telephone line staffed on weekdays, with privacy officers returning calls within two business days.
Sources
- U.S. Department of Veterans Affairs, Veterans Health Administration notifying Veterans of potential information disclosure
- HIPAA Journal, Colonial Behavioral Health & Veterans Health Administration Patients Affected by Ransomware Attacks
- FOX 9 Minneapolis-St. Paul, Veterans Health Administration cyberattack compromises thousands of records