Menu
Browse

Cyber Incident Victim: LifeLong Medical Care

Date:

Nov 2020

Location:

United States of America

Summary

A ransomware attack targeting LifeLong Medical Care through a third-party vendor compromised sensitive personal and medical information of approximately 115,000 individuals. The vendor detected anomalous network activity, later confirmed as ransomware, leading to an investigation that determined unauthorized access to data including names, Social Security numbers, dates of birth, patient identifiers, and treatment details. Affected individuals were notified and offered credit monitoring services alongside a dedicated response line for inquiries.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

On November 24, 2020, LifeLong Medical Care experienced a ransomware attack impacting approximately 115,000 individuals. The incident originated through systems managed by Netgain, a third-party service provider, which initially detected anomalous network activity but did not confirm the ransomware nature of the intrusion until February 25, 2021. The investigation, conducted jointly by LifeLong Medical Care and Netgain, concluded on August 9, 2021, revealing that attackers accessed and/or acquired sensitive patient information. This included full names, Social Security numbers, dates of birth, patient cardholder numbers, treatment details, and diagnosis data. LifeLong Medical Care began notifying affected individuals via breach notification letters following the investigation’s completion, advising them to monitor financial accounts, credit reports, and explanation of benefits statements for fraudulent activity.

Cyber Incident Image

The organization established a toll-free response line (855-851-1278) for inquiries and recommended affected individuals enroll in credit monitoring services, place fraud alerts or security freezes on credit files, and obtain credit reports. The breach occurred amid heightened ransomware targeting of healthcare providers during the COVID-19 pandemic, though the specific ransomware group involved was not identified. LifeLong Medical Care’s notification did not disclose whether ransom demands were made or paid, nor did it specify operational disruptions beyond data compromise. The incident underscored third-party security risks, as Netgain’s systems facilitated the attack. No additional technical details regarding attack vectors, containment measures, or data restoration efforts were disclosed in the notification.

Sources
Sources available to members
1 source