Planned Parenthood cyber attack exposes data of 400,000 patients
Patients have been advised to check their health insurance statements for fraudulent activity
The Los Angeles chapter of nonprofit healthcare provider Planned Parenthood has fallen victim of a cyber attack that has exposed the data of an estimated 400,000 patients.
The incident, which took place in October, saw an unauthorised person gain access to Planned Parenthood LA’s networks and steal files from its systems.
The compromised information includes home addresses, insurance information, dates of birth, as well as information relating to procedures and prescriptions.
A letter detailing the attack was sent out to affected patients on 30 November, a copy of which was obtained by the Washington Post.
Planned Parenthood stated that it has “no evidence” that the stolen data “has been used for fraudulent purposes”.
The organisation has launched an investigation into the incident alongside a “third-party cyber security firm”, as well as notifying law enforcement. It also committed to enhancing its cyber security measures by increasing network monitoring and expanding its own cyber security team. However, it didn’t disclose whether the attackers had requested a ransom, and whether it had been paid.
Patients were advised to review their health insurance statements in case their data was being used to charge for services they weren’t using.
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
However, the breach could present other threats, especially in the US’ increasingly-polarised political climate regarding reproductive rights. Concerns are mounting that US Supreme Court could overturn the 1973 Roe v Wade and 1992 Planned Parenthood v Casey landmark court case rulings that allows women to have an abortion without excessive government restriction.
RELATED RESOURCE
It's feared a breach of this kind could make it possible for anti-abortion protesters, who are known to harrass patients outside Planned Parenthood clinics, to identify those who had undergone the procedure and threaten them.
The breach could also affect patients that are trans and undergoing hormone therapy, which is another Planned Parenthood service that has faced long-standing backlash. Similarly, the data breach could allow for trans patients to be identified and placed in danger.
The incident comes as the latest attack on American healthcare providers, following FBI reports from earlier this year that revealed the Conti ransomware gang had attempted to hack a dozen US healthcare and first responder organisations. Conti was also linked to attacks on Ireland's Health Service Executive (HSE) and its Department of Health (DoH).
Planned Parenthood wasn’t available for comment.
Having only graduated from City University in 2019, Sabina has already demonstrated her abilities as a keen writer and effective journalist. Currently a content writer for Drapers, Sabina spent a number of years writing for ITPro, specialising in networking and telecommunications, as well as charting the efforts of technology companies to improve their inclusion and diversity strategies, a topic close to her heart.
Sabina has also held a number of editorial roles at Harper's Bazaar, Cube Collective, and HighClouds.
-
AI layoffs could spark a new wave of offshoringNews Analysts expect a wave of rehiring next year in the wake of AI layoffs. That may sound like good news for workers, but it'll probably involve offshoring or outsourcing.
-
Hackers are using these malicious npm packages to target developers Windows, macOS, and Linux systemsNews Security experts have issued a warning to developers after ten malicious npm packages were found to deliver infostealer malware across Windows, Linux, and macOS systems.
-
Cisco ASA customers urged to take immediate action as NCSC, CISA issue critical vulnerability warningsNews Cisco customers are urged to upgrade and secure systems immediately
-
Edge devices are now your weakest link: VPNs, firewalls, and routers were the leading source of initial compromise in 30% of incidents last year – here’s whyNews Compromised network edge devices have rapidly emerged as one of the biggest attack points for small and medium businesses.
-
Billions of IoT devices will need to be secured in the next four years – zero trust could be the key to successNews Researchers have warned more than 28 billion IoT devices will need to be secured by 2028 as attacks on connected devices surge.
-
Cisco claims new smart switches provide next-level perimeter defenseNews Cisco’s ‘security everywhere’ mantra has just taken on new meaning with the launch of a series of smart network switches.
-
Five Eyes cyber agencies issue guidance on edge device vulnerabilitiesNews Cybersecurity agencies including the NCSC and CISA have issued fresh guidance on edge device security.
-
T-Mobile security chief insists its defenses stood up to attacks linked to Salt TyphoonNews No T-Mobile customers or services were affected after its security teams detected suspicious activity on their routers
-
Securing your network in every direction with zero trustWhitepaper Webinar on the evolution of network security
-
Turning your log and incident data into real-time security insightsWhitepaper Integrate multiple data sources for a comprehensive security view
