DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

NY: Personal Touch Holding Corp. hit by ransomware attack at MSP, more than 750,000 affected

Posted on March 26, 2021 by Dissent

March 25, 2021 /PRNewswire/ — Today, Personal Touch Holding Corp. (PTHC) announced it is addressing a data breach it discovered on January 27, 2021.

PTHC is the parent company of subsidiaries that operate Medicare-certified home health agencies, licensed home care service agencies, hospice at home services and Early Intervention Programs, as well as a managed care plan in New York. A complete list of these subsidiaries is available at www.pthomecare.com/protects.

PTHC is a business associate of its subsidiaries. In that capacity PTHC performs services that require it have access to personal information of patients and members of its subsidiaries.

Personal Touch Holding Corp. began notifying potentially affected individuals, including current and former patients, and members of its subsidiaries, on March 24, 2021.

  • Patient’s information may include medical treatment information, insurance card and health plan benefit numbers, medical record numbers, first and last name, address, telephone numbers, date of birth, Social Security number, and financial information, including check copies, credit card numbers, and bank account information.
  • Member information may include Medicaid ID number, ID number, provider name, clinical/medical information, first and last name, address, telephone number, date of birth, Social Security numbers, and credit card numbers and/or banking information, if members paid their Medicaid surplus through credit card or check.

Read the full press release on PRNewswire.

But what was the breach? And how did it occur? The press release provides no details, but a notice on their web site says that on January 27, they discovered that they experienced “a cybersecurity attack on the private cloud hosted by its managed service providers.”  Was this a ransomware attack  or something else? And who is the managed service provider? Did that MSP have other customers impacted, too? And will Personal Touch be offering any mitigation services to those impacted? This notification seems to omit a lot of information that might help those impacted gauge their risk and what steps they should take to protect themselves.

Ah, There’s the Answer!

DataBreaches.net subsequently located a notification to Maine by their external counsel,  Ruskin Moscou Faltischek, P.C. Their notification indicated that the following entities were affected:

Personal Touch Holding Corp., business associate to its direct and indirect subsidiaries Personal Touch Home Care of Greater Portsmouth, Inc., Personal Touch Home Care of S.E. Mass., Inc., Personal-Touch Home Care of N.Y., Inc., Personal Touch Home Care of Baltimore, Inc., Personal Touch Home Care of VA, Inc. and Personal Touch Home –Aides, Inc. (MA)

Significantly, while notification letters remained silent on details, the mandated notification to the state indicated that this was a ransomware attack. And at least some, but seemingly not all of those impacted are being offered some mitigation services:

In addition, we are offering identity theft protection services through IDX, the data breach and recovery services expert.
IDX identity protection services include: 12 months of credit and CyberScan monitoring, a $1,000,000 insurance
reimbursement policy, and fully managed id theft recovery services. With this protection, IDX will help you resolve
issues if your identity is compromised.

The breach reportedly impacted  753,107 people. It is not clear what subset of these were patients as opposed to employees.

The notification to the state does not name the managed service providers.

History Repeats Itself? 

January does not seem to be a good month for Personal Touch. One  year ago, in January, 2020, Personal Touch revealed that they had been informed in December by Crossroads Technologies of a ransomware attack by Maze threat actors. That incident was reported to HHS as impacting more than 150,000 patients at multiple locations. And now they experienced another ransomware attack? Ouch.

No related posts.

Category: Breach IncidentsCommentaries and AnalysesHealth DataMalwareOf NoteU.S.

Post navigation

← Jefit Data Incident Public Announcement
NZ: Canterbury District Health Board apologizes for software privacy breach →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • Kentfield Hospital victim of cyberattack by World Leaks, patient data involved
  • India’s Max Financial says hacker accessed customer data from its insurance unit
  • Brazil’s central bank service provider hacked, $140M stolen
  • Iranian and Pro-Regime Cyberattacks Against Americans (2011-Present)
  • Nigerian National Pleads Guilty to International Fraud Scheme that Defrauded Elderly U.S. Victims
  • Nova Scotia Power Data Breach Exposed Information of 280,000 Customers
  • No need to hack when it’s leaking: Brandt Kettwick Defense edition
  • SK Telecom to be fined for late data breach report, ordered to waive cancellation fees, criminal investigation into them launched
  • Louis Vuitton Korea suffers cyberattack as customer data leaked
  • Hunters International to provide free decryptors for all victims as they shut down (2)

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • German court awards Facebook user €5,000 for data protection violations
  • Record-Breaking $1.55M CCPA Settlement Against Health Information Website Publisher
  • Ninth Circuit Reviews Website Tracking Class Actions and the Reach of California’s Privacy Law
  • US healthcare offshoring: Navigating patient data privacy laws and regulations
  • Data breach reveals Catwatchful ‘stalkerware’ is spying on thousands of phones
  • Google Trackers: What You Can Actually Escape And What You Can’t
  • Oregon Amends Its Comprehensive Privacy Statute

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.