Patients sue diagnostic company over data breach


A class of Illinois patients alleged in a lawsuit filed Monday that the health care company Abbott Laboratories failed to adequately protect patient data.

CHICAGO (CN) – A group of Illinois patients said in a class action filed in Illinois federal court Monday that a Midwestern diagnostics company and its multinational parent company failed to adequately protect their private information from a data breach.

Medical device giant Abbott Laboratories said in a statement published on its website on July 16 that it was investigating a “cyber incident” after unauthorized access to patient data on some internal systems of Abbott and its affiliates’ cancer diagnostics businesses.

One of Abbott’s affected subsidiaries included Exact Sciences, a Wisconsin-based diagnostics company specializing in home cancer screening tests. Patients had to provide Exact Sciences and, by proxy, Abbott with their sensitive and confidential personal information to use these at-home tests, which a group of hackers then stole in a ransomware attack.

Abbott asserted in its statement that it did not expect any material business or financial impact from the attack, but the class noted in the complaint that “fraudulent activity resulting from a data breach may not come to light for years. There may be a time lag between when the damage occurs versus when it is discovered, and between when private information is stolen and when it is used.”

In one 46 page complaint filed in the U.S. District Court for the Northern District of Illinois, the patients claimed they were under the impression not only that the defendants would retain their sensitive information, but that the defendants would delete any sensitive information once they were no longer required to retain it.

The patient class reiterated during the appeal that the defendants knew their businesses were prime targets for data thieves, as hackers regularly target healthcare companies for storing highly sensitive information.

A person’s private and sensitive information is very valuable to cybercriminals because it can be sold for more on the black market. If a hacker steals someone’s credit card information, for example, the victim can simply cancel or close their credit cards. The information compromised in this data breach, however, is “impossible to ‘close’ and difficult, if not impossible, to change — namely the Social Security number,” the plaintiffs wrote in the complaint.

The notorious black hat cyber group ShinyHunters claimed responsibility for the attacks. ShinyHunters specializes in large-scale data breaches, extortion and selling stolen data online. The hacker group, formed in 2019, told cybersecurity publication BleepingComputer on July 17 that she gained access to the data through a voice phishing attack targeting Abbott employees. The attack allegedly allowed the group to compromise employees’ Microsoft Entra single sign-on accounts.

Cyber ​​crime group BleepingComputer said further he stole more than 30 million rows of customer data from multiple datasets containing names, email addresses, phone numbers, physical addresses, dates of birth and more than 1 million Social Security numbers. The group also said it stole more than 22 million customer records containing doctor-patient conversations and more than 20 million medical orders. Neither BleepingComputer nor Courthouse News has independently verified ShinyHunters’ claims about the stolen data.

A representative from Abbott Laboratories did not respond to Courthouse News’ request for comment. The Abbott Park, Illinois-based health care company was ranked 107th on the Fortune 500 this year with $44.3 billion in revenue. The company also faces a class action by its employeeswho said Abbott charged them for health insurance.

Subscribe to our free newsletters

Our weekly newsletter Closing arguments provides the latest on ongoing trials, major litigation and decisions in courts around the US and the world, while monthly Under the lights feeds legal dirt from Hollywood, sports, Big Tech and the arts.





Source link

Leave a Reply

Your email address will not be published. Required fields are marked *