Elara Caring, a home-based care provider, recently announced that patient data may have been exposed after a security breach in December 2020.
What happened?
Elara Caring was the victim of a phishing attack . On December 9, 2020, a phishing email was sent to employees which enabled a hacker to gain access to several employee accounts. Although Elara Caring detected the unauthorized access the same day, it wasn't able to contain the situation until December 16. Protected health information ( PHI ) may have been leaked during this data breach. As many as 100,400 patients had sensitive data exposed, including information like:- Name
- Date of birth
- Address
- Phone number
- Financial or bank account information
- Social Security number
- Insurance information
- Driver’s license number
Elara Caring claims that there's no evidence that PHI was accessed or misused. Its investigation also concluded that malware wasn't released into its network.
How did Elara Caring respond to the data breach?
Elara Caring sent notification letters of the data breach to all affected patients and is offering to pay for a two-year membership of Experian services to monitor for potential fraud. Elara Caring also made many internal changes. Some of these changes include:- Conducting an enterprise-wide password change
- Implementing multi-factor authentication
- Training employees on cybersecurity and how to spot scams
