DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

NYS settles charges against PracticeFirst stemming from 2020 ransomware incident

Posted on May 24, 2023 by Dissent

In July 2021, Professional Business Systems, Inc. d/b/a Practicefirst Medical Management Solutions and PBS Medcode Corp., a medical management company that processes data for health care providers, issued a press release about a hacking incident that occurred in December 2020.  As DataBreaches noted at the time, it appeared that they likely paid ransom because one line in their statement was, “The actor who took the copy has advised that the Information is destroyed and was not shared.”

The breach was reported to both the Maine Attorney General’s Office and HHS as affecting 1,210,688 people. The incident appears to be still under investigation by HHS, but the NYS Attorney General’s Office has settled charges against the upstate firm. In a press release issued yesterday, the AG’s office writes:

New York Attorney General Letitia James recouped $550,000 from a medical management company, Professional Business Systems, Inc. d/b/a Practicefirst Medical Management Solutions and PBS Medcode Corp. (Practicefirst), for failing to protect New Yorkers’ personal information, including health records. Practicefirst’s failure to make a timely software update made their networks susceptible to a cyberattack, which affected more than 1.2 million individuals nationwide, including over 428,000 New Yorkers. Practicefirst’s data security failures violated both state law and the federal Health Insurance Portability and Accountability Act (HIPAA). As a result of today’s agreement, Practicefirst has agreed to pay $550,000 in penalties to New York, strengthen its data security practices, and offer affected consumers free credit monitoring services.

According to the state’s investigation, Practicefirst failed to update its firewall in January 2019 when the firewall provider issued an updated version that was designed to patch a critical vulnerability. The OAG found:

Between May 2019 and August 2019, the firewall provider published an advisory for the vulnerability, the National Institute of Standards and Technology’s National Vulnerability Database (“NVD”) published an entry about the vulnerability, security researchers presented about the vulnerability at a Black Hat security conference, and a Metasploit module demonstrating the exploitation of the vulnerability was published online.

Between May 2019 and December 2020, Practicefirst and its managed service provider did not conduct any penetration tests, vulnerability scans, or other security testing that would have identified the vulnerability.

An attacker exploited that vulnerability in November 2020, gained access, and then deployed ransomware and exfiltrated unencrypted files with patient data.  “Days later, screenshots containing personal information of 13 consumers were discovered on the dark web,” the Attorney General’s Office notes.

As DataBreaches had suggested in 2021, PracticeFirst had paid ransom. The OAG noted that after the payment, Practicefirst obtained a written attestation that the unauthorized actor had destroyed the exfiltrated data. “The unauthorized actor
provided information indicating 80 gigabytes of data, containing 79,000 files, were exfiltrated,” the OAG noted.

The Assurance of Discontinuance identifies specific security protections PracticeFirst must implement.

 


Related:

  • Cyber-Attack On Bectu’s Parent Union Sparks UK National Security Concerns
  • Attorney General James Announces Settlement with Wojeski & Company Accounting Firm
  • JFL Lost Up to $800,000 Weekly After Cyberattack, CEO Says No Patient or Staff Data Was Compromised
  • John Bolton Indictment Provides Interesting Details About Hack of His AOL Account and Extortion Attempt
  • UK: 'Catastrophic' attack as Russians hack files on EIGHT MoD bases and post them on the dark web
  • A business's cyber insurance policy included ransom coverage, but when they needed it, the insurer refused to pay. Why?
Category: Commentaries and AnalysesHealth DataMalwareOf NoteState/LocalU.S.

Post navigation

← Apria Healthcare notifies 1.2 million patients of hacking incidents in 2019 and 2021
Microsoft: Notorious FIN7 hackers return in Clop ransomware attacks →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • District of Massachusetts Allows Higher-Ed Student Data Breach Claims to Survive
  • End of the game for cybercrime infrastructure: 1025 servers taken down
  • Doctor Alliance Data Breach: 353GB of Patient Files Allegedly Compromised, Ransom Demanded
  • St. Thomas Brushed Off Red Flags Before Dark-Web Data Dump Rocks Houston
  • A Wiltshire police breach posed possible safety concerns for violent crime victims as well as prison officers
  • Amendment 13 is gamechanger on data security enforcement in Israel
  • Almost two years later, Alpha Omega Winery notifies those affected by a data breach.
  • Court of Appeal reaffirms MFSA liability in data leak case, orders regulator to shoulder costs
  • A jailed hacking kingpin reveals all about the gang that left a trail of destruction
  • Army gynecologist took secret videos of patients during intimate exams, lawsuit says

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • As shoplifting surges, British retailers roll out ‘invasive’ facial recognition tools
  • Data broker Kochava agrees to change business practices to settle lawsuit
  • Amendment 13 is gamechanger on data security enforcement in Israel
  • Changes in the Rules for Disclosure for Substance Use Disorder Treatment Records: 42 CFR Part 2: What Changed, Why It Matters, and How It Aligns with HIPAAs
  • Always watching: How ICE’s plan to monitor social media 24/7 threatens privacy and civic participation

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net
Security Issue: security[at]databreaches.net
Mastodon: Infosec.Exchange/@PogoWasRight
Signal: +1 516-776-7756
DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.