Menu
Browse

Cyber Incident Victim: Benefit Recovery Specialists, Inc.

Date:

Apr 2020

Location:

United States of America

Summary

A Texas-based billing and collections company specializing in healthcare services suffered a malicious malware attack compromising sensitive personal and protected health information of approximately 275,000 individuals. The breach enabled unauthorized access to names, dates of birth, healthcare provider details, policy identifiers, and Social Security numbers. The organization detected the intrusion through malware presence on its systems, initiating customer notifications shortly thereafter while urging vigilance against potential identity theft. Exposed data belonged to clients of healthcare providers and payers serviced by the company, with unauthorized file access occurring over a multi-day intrusion period.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

Benefit Recovery Specialists, Inc. (BRSI), a Houston-based billing and collections company serving healthcare providers and payers, experienced a significant data breach after detecting malware on its systems. The malicious software infiltration, discovered during an internal investigation, potentially enabled unauthorized actors to access and exfiltrate sensitive personal and protected health information (PHI). The compromise impacted 274,837 individuals whose data was processed by BRSI for billing-related services. Forensic analysis determined the attack commenced on April 20, 2020, with confirmed unauthorized access to customer files occurring between April 20 and April 30, 2020. The malware’s presence created a window during which attackers could view and obtain confidential records stored on BRSI’s compromised infrastructure.

Cyber Incident Image

Exposed information included names, dates of birth, healthcare provider names, insurance policy identification numbers, and, for a subset of individuals, Social Security numbers. BRSI initiated customer notification procedures on June 2, 2020, approximately six weeks after concluding its investigation into the breach’s scope and timeline. The company advised affected individuals to remain vigilant against potential identity theft and fraudulent activity stemming from the exposure of their sensitive data. No specific details regarding malware variant, attack vector, or containment measures were publicly disclosed beyond the confirmation of malware as the intrusion mechanism. The incident disrupted BRSI’s operations during the investigation period and necessitated engagement with forensic specialists to assess the breach’s technical origins and data impact.

Sources
Sources available to members
1 source