"The data was returned after the ransom was paid and we have no reason to believe it has been or will be further used or disclosed," the company says. "On January 18, 2021, Woodcreek received a copy of the recovered data set and has been working diligently since then to notify affected individuals."
How has Multicare responded?
It appears as if Multicare is leaving most of the breach response to Woodcreek, providing no notice information on the incident available on its
own website. Woodcreek sent
formal notice of the data breach to Washington's Attorney General, as well as to the Office for Civil Rights under the federal Department of Health and Human Services (netting an entry on the "
Wall of Shame"). Woodcreek meanwhile sent letters to anyone who received care between January 2005 and November 2020, as well as a few patients from as far back as 1997. The company is offering free enrollment in credit monitoring and identity theft protection services. Finally, Woodcreek is is maintaining a call center and a
special website for this breach.
Has Multicare suffered other data breaches?
In this most recent case, Multicare was ensnared in a data breach via a service provider that was used by a partner organization. Last year, Multicare's direct business associate Blackbaud
suffered a different data breach. That breach impacted more than 3.4 million people affiliated with dozens of organizations that used its
ResearchPoint and DonorCentric applications. And in 2016, Multicare
experienced a direct breach of its systems when an outside party gained access to an employee’s email account.
What can others learn from this breach?
It's not clear exactly how Netgain's systems were compromised, although ransomware is among the most common types of
malware sent via
phishing emails to employees. Unfortunately, even if a company follows
email best practices and provides regular
cybersecurity training, its data can still be compromised through an external vendor, making the
business associate agreement an especially important legal document. Whether you're a healthcare organization or a service provider that handles information from one,
HIPAA compliant email is a must.
Paubox Email Suite Plus provides both inbound and outbound email security features, including our patented
ExectProtect solution which stops
display name spoofing emails from ever reaching the inbox.
Try Paubox Email Suite Plus for FREE today.