Covenant Health says May data breach impacted nearly 478,000 patients
Covenant Health报告称去年5月发生的数据泄露事件影响近50万人,最初报告仅7864人受影响,后经分析发现更多人受影响。该事件由Qilin勒索软件攻击引发,涉及患者姓名、地址、出生日期、社保号等敏感信息,已加强安全措施并为受影响者提供一年免费身份保护服务。 2026-1-2 19:15:17 Author: www.bleepingcomputer.com(查看原文) 阅读量:3 收藏

Covenant Health says May data breach impacted nearly 478,000 patients

The Covenant Health organization has revised to nearly 500,000 the number of individuals affected by a data breach discovered last May.

The healthcare entity initially reported in July that the data of 7,864 people had been exposed, but further analysis has revealed a larger impact.

After completing “the bulk of its data analysis,” Covenant Health now says that 478,188 individuals were affected.

Wiz

Covenant Health is a Catholic healthcare provider based in Andover, Massachusetts, operating hospitals, nursing and rehabilitation centers, assisted living residences, and elder care organizations across New England and parts of Pennsylvania.

Qilin ransomware attack

Covenant Health learned on May 26, 2025, that an attacker had breached its systems eight days earlier, on May 18, and gained access to patient data.

In late June, the Qilin ransomware group claimed the attack, stating that it had stolen 852 GB of data comprising nearly 1.35 million files.

Qilin ransomware lists Covenant Health on its data leak site
Qilin ransomware lists Covenant Health on its data leak site
source: BleepingComputer

The organization says the exposed information may include names, addresses, dates of birth, medical record numbers, Social Security numbers, health insurance information, and treatment details (e.g., diagnoses, dates of treatment, type of treatment).

In a copy of the notice, Covenant Health says it engaged third-party forensic specialists to determine what data was affected and how many individuals were impacted.

"That review is ongoing," the organization said, without providing a timeline for finishing the investigation and its impact. Covenant Health said that it has strengthened the security of its systems, to prevent similar incidents in the future.

The healthcare entity Covenant Health is offering affected individuals 12 months of free identity protection services to help detect potential misuse of their information.

Beginning December 31, the organization started mailing data breach notification letters to patients whose information may have been compromised in the May intrusion.

Wiz

7 Security Best Practices for MCP

As MCP (Model Context Protocol) becomes the standard for connecting LLMs to tools and data, security teams are moving fast to keep these new services safe.

This free cheat sheet outlines 7 best practices you can start using today.


文章来源: https://www.bleepingcomputer.com/news/security/covenant-health-says-may-data-breach-impacted-nearly-478-000-patients/
如有侵权请联系:admin#unsafe.sh