Pepper faints again, reading Amazon’s response–it’s ‘archived’ data that “only impacts certain legacy Iora Health and One Medical Seniors patients”. The ShinyHunters data extortion group published their ‘final warning’ on its ‘dark web’ site with a negotiation start date of last Monday (22 June) before they would publish 8.8 terabytes of stolen information. Making the ShinyHunters threat less credible is that they haven’t released any sample data, so there is no idea if the contents are high value–typically containing personally identifiable information such as Social Security number, credit cards, and sensitive health information. Amazon One Medical is admitting the loss of only a “subset of files containing demographic and clinical records”.
Amazon One Medical published a notification on its One Medical Seniors (the former Iora Medical) website summing up the following:
- They learned on 13 June that a third-party file storage system used to store archived patient information had been accessed by an unauthorized person
- Data had been exfiltrated between 8-11 June
- It’s apparently “legacy” information only and affecting only certain old Iora/Amazon One Medical Seniors records
- The clinics affected are legacy Iora clinics located in Atlanta, Cape Cod, Charlotte, Piedmont Triad, Denver, Houston, Phoenix, Tucson, and Seattle.
- They took immediate action including the revocation of all user access and rotating credentials for all employees with access to the system.
- Neither Amazon One Medical (non-Seniors) patients, Seniors patients outside these markets, nor their EHR and medical services have been affected.
Patients are given a number to call and an email to write if they have questions. It is not known if patients were notified in other ways, for example through the patient portal, email, or standard US Mail. There is no public indication that Amazon One Medical has contacted ShinyHunters or is negotiating with them, whoever they are.
ShinyHunters is notorious for taking credit for other attacks on healthcare organizations, always going big, then going home after gaining their ransom. Their last target was Medtronic, hacking 9 million patient records plus terabytes of corporate information in April [TTA 30 April]. After the leak information was pulled from their website, the conclusion was that Medtronic paid up. ShinyHunters also attacked dental benefits administrator DentaQuest earlier this year. Other big game: Zara, Carnival, 7-Eleven, Pitney Bowes, The Canada Life Assurance Company, and Hallmark.
Amazon One Medical is staying mum, but this will be updated as additional information is disclosed. Cybernews, Healthcare IT News, HIPAA Journal







Leave a Reply