US hospital hit by data-stealing malware

Mystery "virus" hits hospital server

By John E Dunn, Techworld |  Security Add a new comment

An Indiana hospital has had to write to 12,000 people after malware breached its security defences to compromise a server used to collect personal data from web forms.

The affected individuals were mostly people who might have applied for jobs at Goshen Hospital in recent years plus some outpatients. Information put at risk includes names, addresses, and social security numbers, the hospital has told local media.

The malware remains unidentified beyond it being described as "a relatively common virus that is malicious," which suggests an infection that remained undetected for some time. Patient records are isolated from the Internet and were never at risk.

Affected individuals have been contacted by letter and asked to check their credit reports for possible identity fraud with the hospital picking up the tab for fraud monitoring checks for at least 12 months.

The incident marks the second US hospital to be adversely affected by malware in as many months, after Gwinnett Medical Center in Lawrenceville Georgia was forced to turn away admissions after its systems were disrupted by a mystery "virus".

Around the same time in New Zealand, the St John's Ambulance service had problems in the radio coordination system used between its control centre and ambulances after a very similar malware outbreak.

Both of those incidents were more serious and involved operational disruption rather than static data breach. The commonest type of hospital data breach indecent the world over remains the lost USB stick.


Originally published on Techworld |  Click here to read the original story.

ITworld LIVE

SecurityWhite Papers & Webcasts

Webcast On Demand

Seven Deadly Sins of Cloud Security (Video)

As cloud computing gains popularity, too few people are aware of the security threats that are emerging. In this short video, experts from HP discuss the latest cloud security threats and explain measures to help overcome them. Hear about the seven deadly sins of cloud security and learn how to avoid becoming a victim of poor security in your cloud environment.Intel and the Intel logo are trademarks of Intel Corporation in the U.S. and/or other countries.

Sponsor: HP & Intel

White Paper

Establishing a Strategy for Database Security is No Longer Optional

The options for securing increasingly valuable databases are very broad and deep, and can be confusing. This research provides an overview of three categories of controls that should be implemented to ensure that enterprise data is protected in the most efficient and effective manner.

White Paper

Database Activity Monitoring Is Evolving

Read the analyst report and learn how you can leverage the core capabilities of a DAP solution for better database security.

White Paper

Protecting Against Database Attacks and Insider Threats: Top 5 Scenarios

Read this new eBook to learn the top five scenarios and essential best practices for preventing database attacks and insider threats.

Webcast On Demand

Distributed Database Security with Real-time Monitoring

View this demo and learn how IBM InfoSphere Guardium database activity monitoring can help protect your sensitive data in distributed DBMS environments with a holistic approach to data security and compliance.

Sponsor: IBM

See more White Papers | Webcasts

Ask a question

Ask a Question