DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

Cove Family & Sports Medicine recovers from ransomware, but loses some data

Posted on July 1, 2017 by Dissent

There are different metrics for describing the impact of a breach, but one of the ones I use in my subjective system is whether patient data that might be needed for care have been lost, stolen, or corrupted.  In June, there were a lot of data breaches or security incidents and many involved ransomware. One incident, however, that pretty much flew under the media radar, actually resulted in loss of patient notes. In a June 13 notice to patients, Cove Family & Sports Medicine in Huntsville, Alabama wrote that unnamed ransomware encrypted patients’ medical records.

“The encrypted medical records contained patient information, including names, dates of birth, social security numbers, addresses, patient identification numbers, prescription information, diagnosis information, procedure information, and time and date of treatment,” the doctors write.

Cove Medicine did not pay the ransom. It elected to reinstall the operating system on its server and then it restored the majority of its patient records from backup copies. Their approach was only partially successful, though:

The backup records, however, were partially encrypted as well and the practice currently has not been able to restore its internal notes for visits that have occurred in approximately the past two years. Cove Medicine believes it will be able to restore all other treatment records, and that this will not impair its ability to provide care to its patients.

So the good news is that most of the data were recovered from backups, the doctors do not believe that care will be impacted, and there was no indication that any data were exfilitrated. But this was obviously not a total success, and it’s not clear whether the lost/unrecovered internal notes might impact care. The doctors write:

“We take patient privacy seriously, and are very sorry for any concern or inconvenience this incident has caused or may cause to anyone who has been affected,” said Dr. Jonathan Krichev, one of the physicians and partners of Cove Medicine.

With so much ransomware and so many attacks these days, what lessons can other entities learn from Cove Medicine’s experience? The doctors did not disclose how the ransomware got into their system, and there might be something to be learned from that. Nor do they explain how the backups wound up partially encrypted, too, and perhaps that’s something we can all learn from, too.

This is not to sound critical of Cove Medicine. They clearly did the best they could in an unfortunate situation that was not of their choosing and it no small measure of success that they recovered as much as they did. I’m just wondering what lessons can be learned that might save others the same misery.

At the present time, the incident is not up on HHS’s breach tool, and we do not know how many patients were notified of this incident.

Category: Breach IncidentsHealth DataMalwareU.S.

Post navigation

← Trump Hotels notifies some guests of payment card breach that began in 2016
So many notifications due to ransomware, but are these really necessary? →

1 thought on “Cove Family & Sports Medicine recovers from ransomware, but loses some data”

  1. ECA says:
    July 1, 2017 at 3:26 pm

    as you also would like more info, I would also..
    I have a few ideas tho..
    1. Backup data, is NOT FREE.. Unless you have a good computer person, the programs are not free.
    They also update and CHANGE the programs over time, for a few security reasons..
    2. Online/Offline data save..Data service tend to be STRANGE..Uploading Incremental data, and the service changes things…and you Could loose all of it..its the same with DMCA.
    3. built in, Backup program in the software, and the Creator changes it..you WONT get the old data back, unless you keep a copy of the OLD software.
    4. software that ENCODES its data, for many reasons including Keeping Smaller files.. and the same reason as #3..and DMCA again.

    I suggest MORE then 1 type of backup and STORE in more then 1 location, Preferably OFF SITE..

    2 years of RECENT data lost??
    I hate windows backup..The program I wish them to make, isnt easy. I would rather backup DATA/PROGRAMS/OS separately.. At this time, I would prefer a SECOND program, not one builtin to a PROGRAM, to do a manual backup of DATA..I dont like SERVICES that claim they can SAVE your data, and would rather keep my OWN copy, as well.

    A full system backup 1 timer per month, is the LEAST that should be done. but requires access to a GOOD sized NAS..that ONLY connects to the system at the TIME of backup..keeping 2-3 NAS backups can save allot of time, and a FULL system Backup/Everything is the best. you RELOAD windows, and then reinstall the WHOLE BACKUP..

    Im from the OLD school, when BUMPING your computer was reason to REINSTALL EVERYTHING..

Comments are closed.

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • Texas Doctor Who Falsely Diagnosed Patients as Part of Insurance Fraud Scheme Sentenced to 10 Years’ Imprisonment
  • VanHelsing ransomware builder leaked on hacking forum
  • Hack of Opexus Was at Root of Massive Federal Data Breach
  • ‘Deep concern’ for domestic abuse survivors as cybercriminals expected to publish confidential abuse survivors’ addresses
  • Western intelligence agencies unite to expose Russian hacking campaign against logistics and tech firms
  • Disrupting Lumma Stealer: Microsoft leads global action against favored cybercrime tool
  • Researchers Scrape 2 Billion Discord Messages and Publish Them Online
  • Privilege Under Fire: Protecting Forensic Reports in the Wake of a Data Breach
  • Hacker who breached communications app used by Trump aide stole data from across US government
  • Massachusetts hacker to plead guilty to PowerSchool data breach (1)

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • Widow of slain Saudi journalist can’t pursue surveillance claims against Israeli spyware firm
  • Researchers Scrape 2 Billion Discord Messages and Publish Them Online
  • GDPR is cracking: Brussels rewrites its prized privacy law
  • Telegram Gave Authorities Data on More than 20,000 Users
  • Police secretly monitored New Orleans with facial recognition cameras
  • Cocospy stalkerware apps go offline after data breach
  • Drugmaker Regeneron to acquire 23andMe out of bankruptcy

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.