DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

NY: Personal Touch Holding Corp. hit by ransomware attack at MSP, more than 750,000 affected

Posted on March 26, 2021 by Dissent

March 25, 2021 /PRNewswire/ — Today, Personal Touch Holding Corp. (PTHC) announced it is addressing a data breach it discovered on January 27, 2021.

PTHC is the parent company of subsidiaries that operate Medicare-certified home health agencies, licensed home care service agencies, hospice at home services and Early Intervention Programs, as well as a managed care plan in New York. A complete list of these subsidiaries is available at www.pthomecare.com/protects.

PTHC is a business associate of its subsidiaries. In that capacity PTHC performs services that require it have access to personal information of patients and members of its subsidiaries.

Personal Touch Holding Corp. began notifying potentially affected individuals, including current and former patients, and members of its subsidiaries, on March 24, 2021.

  • Patient’s information may include medical treatment information, insurance card and health plan benefit numbers, medical record numbers, first and last name, address, telephone numbers, date of birth, Social Security number, and financial information, including check copies, credit card numbers, and bank account information.
  • Member information may include Medicaid ID number, ID number, provider name, clinical/medical information, first and last name, address, telephone number, date of birth, Social Security numbers, and credit card numbers and/or banking information, if members paid their Medicaid surplus through credit card or check.

Read the full press release on PRNewswire.

But what was the breach? And how did it occur? The press release provides no details, but a notice on their web site says that on January 27, they discovered that they experienced “a cybersecurity attack on the private cloud hosted by its managed service providers.”  Was this a ransomware attack  or something else? And who is the managed service provider? Did that MSP have other customers impacted, too? And will Personal Touch be offering any mitigation services to those impacted? This notification seems to omit a lot of information that might help those impacted gauge their risk and what steps they should take to protect themselves.

Ah, There’s the Answer!

DataBreaches.net subsequently located a notification to Maine by their external counsel,  Ruskin Moscou Faltischek, P.C. Their notification indicated that the following entities were affected:

Personal Touch Holding Corp., business associate to its direct and indirect subsidiaries Personal Touch Home Care of Greater Portsmouth, Inc., Personal Touch Home Care of S.E. Mass., Inc., Personal-Touch Home Care of N.Y., Inc., Personal Touch Home Care of Baltimore, Inc., Personal Touch Home Care of VA, Inc. and Personal Touch Home –Aides, Inc. (MA)

Significantly, while notification letters remained silent on details, the mandated notification to the state indicated that this was a ransomware attack. And at least some, but seemingly not all of those impacted are being offered some mitigation services:

In addition, we are offering identity theft protection services through IDX, the data breach and recovery services expert.
IDX identity protection services include: 12 months of credit and CyberScan monitoring, a $1,000,000 insurance
reimbursement policy, and fully managed id theft recovery services. With this protection, IDX will help you resolve
issues if your identity is compromised.

The breach reportedly impacted  753,107 people. It is not clear what subset of these were patients as opposed to employees.

The notification to the state does not name the managed service providers.

History Repeats Itself? 

January does not seem to be a good month for Personal Touch. One  year ago, in January, 2020, Personal Touch revealed that they had been informed in December by Crossroads Technologies of a ransomware attack by Maze threat actors. That incident was reported to HHS as impacting more than 150,000 patients at multiple locations. And now they experienced another ransomware attack? Ouch.

Category: Breach IncidentsCommentaries and AnalysesHealth DataMalwareOf NoteU.S.

Post navigation

← Jefit Data Incident Public Announcement
NZ: Canterbury District Health Board apologizes for software privacy breach →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • Massachusetts hacker to plead guilty to PowerSchool data breach
  • Cyberattack brings down Kettering Health phone lines, MyChart patient portal access (1)
  • Gujarat ATS arrests 18-year-old for cyberattacks during Operation Sindoor
  • Hackers Nab 15 Years of UK Legal Aid Applicant Data
  • Supplier to major UK supermarkets Aldi, Tesco & Sainsbury’s hit by cyber attack with ransom demand
  • UK: Post Office to compensate hundreds of data leak victims
  • How the Signal Knockoff App TeleMessage Got Hacked in 20 Minutes
  • Cocospy stalkerware apps go offline after data breach
  • Ex-NSA bad-guy hunter listened to Scattered Spider’s fake help-desk calls: ‘Those guys are good’
  • Former Sussex Police officer facing trial for rape charged with 18 further offences relating to computer misuse

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • Telegram Gave Authorities Data on More than 20,000 Users
  • Police secretly monitored New Orleans with facial recognition cameras
  • Cocospy stalkerware apps go offline after data breach
  • Drugmaker Regeneron to acquire 23andMe out of bankruptcy
  • Massachusetts Senate Committee Approves Robust Comprehensive Privacy Law
  • Montana Becomes First State to Close the Law Enforcement Data Broker Loophole
  • Privacy enforcement under Andrew Ferguson’s FTC

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.