DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

MN: Apple Valley Clinic notifies 157,939 patients about Netgain Technology breach

Posted on March 30, 2021 by Dissent

In November, 2020, cloud IT services provider Netgain Technology LLC experienced a ransomware attack that resulted in them taking some of their data centers offline. In December and January, they began notifying some of their clients.

In January, Ramsey County notified 8,700 clients of its Family Health Division about the breach. In February, Woodcreek Provider Services notified 207,000 patients, and in March, Sandhills Medical Foundation notified 39,602 patients. And now Apple Valley Clinic is notifying 157,939 patients.

Notice of Data Breach from Apple Valley Clinic

MINNEAPOLIS (March 26, 2021) — This notice is regarding a security incident of which the Apple Valley Clinic has become aware. The Apple Valley Clinic provides primary care and urgent care services. The Apple Valley Clinic contracts with Netgain Technology, LLC (Netgain), to host its information technology network and computer systems. 

On December 2, 2020, we were notified by Netgain that its systems had been compromised by a cyberattack. After discovering the cyberattack, Netgain notified law enforcement and ultimately regained control of its systems and recovered the affected data. On January 29, 2021 after the Netgain systems were restored, Allina Health received confirmation that the data involved in the cyberattack contained patient data. We have worked with experts to determine what patient data was affected in order to provide our patients with the most accurate information about the incident and the individuals potentially affected. 

Data maintained by the Apple Valley Clinic that was involved in the cyberattack on Netgain’s system included the following types of personal information: 

  • Names
  • Dates of birth
  • Social security numbers
  • Bank account and routing numbers
  • Patient billing information
  • Medical information, such medical symptoms and diagnosis

This incident only impacted individuals receiving health care services at the Apple Valley Clinic. No other Allina locations were impacted by the incident.

We are committed to our patient’s privacy and we understand that these types of events can cause concern. Although the Apple Valley Clinic was not targeted in this cyberattack, we are taking steps to enhance our own cybersecurity protocols and practices. In February, we implemented Allina Health’s electronic health record system and began migrating the Apple Valley Clinic to a new information technology system, used by Allina Health.

We are communicating regularly with Netgain to ensure they are taking appropriate steps to better maintain the security of the Apple Valley Clinic’s data. Netgain has provided written assurances that the threat to its systems has been contained and eliminated. Netgain is continuing to scan its environment to identify potential impacts from the attack and will work promptly to address any new vulnerabilities that may be identified. 

In the interest of protecting our patient’s privacy, and in accordance with law, Allina Health is in the process of contacting all patients who may have been affected. 

We are not aware that any data was disclosed or used by those responsible for the cyberattack. However, out of an abundance of caution, we are offering complimentary identity theft protection services to affected patients of the Apple Valley Clinic.

For More Information.  Patients who may have been impacted can call 833-978-2828. Monday – Friday from 8:00 AM to 6:00 PM (Central Time), beginning Monday, March 29, 2021.

Read our FAQs 

About Allina Health

Allina Health is dedicated to the prevention and treatment of illness and enhancing the greater health of individuals, families and communities throughout Minnesota and western Wisconsin. A not-for-profit health care system, Allina Health cares for patients from beginning to end-of-life through its 90+ clinics, 11 hospitals, 15 retail pharmacies, specialty care centers and specialty medical services, home care, and emergency medical transportation services.

Category: Breach IncidentsHealth DataSubcontractor

Post navigation

← Mobikwik offers master class in how NOT to respond to a breach; researchers scoff, consumers rage
North Texas Woman Guilty in Multimillion-Dollar Conspiracy Involving the Sale of Forged Prescriptions →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • Nigerian National Sentenced To More Than Five Years For Hacking, Fraud, And Identity Theft Scheme
  • Data breach of patient info ends in firing of Miami hospital employee
  • Texas DOT investigates breach of crash report records, sends notification letters
  • PowerSchool hacker pleads guilty, released on personal recognizance bond
  • Rewards for Justice offers $10M reward for info on RedLine developer or RedLine’s use by foreign governments
  • New evidence links long-running hacking group to Indian government
  • Zaporizhzhia Cyber ​​Police Exposes Hacker Who Caused Millions in Losses to Victims by Mining Cryptocurrency
  • Germany fines Vodafone $51 million for privacy, security breaches
  • Google: Hackers target Salesforce accounts in data extortion attacks
  • The US Grid Attack Looming on the Horizon

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • California county accused of using drones to spy on residents
  • How the FBI Sought a Warrant to Search Instagram of Columbia Student Protesters
  • Germany fines Vodafone $51 million for privacy, security breaches
  • Malaysia enacts data sharing rules for public sector
  • U.S. Enacts Take It Down Act
  • 23andMe Bankruptcy Judge Ponders Trump Bill’s Injunction Impact
  • Hell No: The ODNI Wants to Make it Easier for the Government to Buy Your Data Without Warrant

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.