DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

OnePoint Patient Care notifies almost 800,000 patients of August ransomware attack

Posted on October 25, 2024 by Dissent

On September 15, INC Ransom added OnePoint Patient Care to its leak site. The threat actors claimed to have encrypted the hospice dispensing pharmacy and pharmacy benefits management service’s files. It wasn’t long after that INC leaked all of the data.

The Arizona-based provider notified HHS of the incident on October 14, reporting that 795,916 patients had been affected.

A substitute notice on OnePoint’s site indicates that the incident had no impact on its operations. In a letter to patients, a copy of which was provided to the California Attorney General’s Office, OnePoint states that the attack occurred between August 6 and August 8, and was first detected on August 8.

“While we have no reason to believe that your information has been misused for the purpose of committing fraud or identity theft, we are writing in accordance with relevant law to advise you about the incident and to provide you with guidance on what you can do to protect yourself, should you feel it is appropriate to do so,” they write. The types of information involved included the patient’s name, address, residence information, medical record number, diagnosis, Social Security number, and prescription information.

“While we are uncertain that your personal information was obtained,” they add, “out of an abundance of caution, we are notifying you of that potential.” They do not reveal whether they obtained and reviewed the entire data tranche, which might have confirmed whether patients’ data was obtained or not.

But would patients feel “it is appropriate” to take steps to protect themselves if they knew their data had been leaked and may be in an untold number of hands? Nowhere in its letter does OnePoint reveal if this was a ransomware attack and if the data was leaked because they didn’t pay the ransom. The notification is totally silent about any encryption or ransom demand, neither denying nor confirming what INC’s site suggests.

DataBreaches is not suggesting that OnePoint should have paid any ransom demand, but DataBreaches thinks covered entities should inform patients when their data has actually been leaked or put up for sale as a result of an incident.

Category: Health DataMalwareU.S.

Post navigation

← Cardiology of Virginia patient data appears to be up for sale. Has the entity issued any statement at all?
Indian court tells Star Health to share details of leak so Telegram can delete chatbots →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • Researchers Scrape 2 Billion Discord Messages and Publish Them Online
  • Privilege Under Fire: Protecting Forensic Reports in the Wake of a Data Breach
  • Hacker who breached communications app used by Trump aide stole data from across US government
  • Massachusetts hacker to plead guilty to PowerSchool data breach
  • Cyberattack brings down Kettering Health phone lines, MyChart patient portal access (1)
  • Gujarat ATS arrests 18-year-old for cyberattacks during Operation Sindoor
  • Hackers Nab 15 Years of UK Legal Aid Applicant Data
  • Supplier to major UK supermarkets Aldi, Tesco & Sainsbury’s hit by cyber attack with ransom demand
  • UK: Post Office to compensate hundreds of data leak victims
  • How the Signal Knockoff App TeleMessage Got Hacked in 20 Minutes

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • Researchers Scrape 2 Billion Discord Messages and Publish Them Online
  • GDPR is cracking: Brussels rewrites its prized privacy law
  • Telegram Gave Authorities Data on More than 20,000 Users
  • Police secretly monitored New Orleans with facial recognition cameras
  • Cocospy stalkerware apps go offline after data breach
  • Drugmaker Regeneron to acquire 23andMe out of bankruptcy
  • Massachusetts Senate Committee Approves Robust Comprehensive Privacy Law

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.
Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report