Hand in a glove on a laptop keyboard and a medical stethoscope showing healthcare provider data breach

Massive Data Breach at Healthcare Provider ILS Compromises Millions of Patients

The Miami-based managed healthcare provider Independent Living Systems (ILS) disclosed a data breach that affected more than four million individuals.

According to data breach notification letters sent to affected individuals on March 14, 2023, Independent Living Systems said it discovered “inaccessibility of certain computer systems” on July 5, 2022, and began investigating with a third-party firm.

In a data breach notification filed with the Office of the Maine Attorney General, ILS disclosed that 4,226,508 individuals were impacted. The victims were direct customers of ILS or ILS-covered entity subsidiaries such as Florida Community Care LLC and HPMP of Florida Inc. (also operating as Florida Complete Care) or ILS-covered health plans.

According to a statement on its website, Independent Living Systems offers clinical and administrative services to managed care providers serving “high-cost complex member populations in the Medicare, Medicaid and Dual-Eligible Market.”

Data breach on managed healthcare provider ILS leaked PII and PHI

Healthcare provider ILS responded immediately by launching an investigation with a third-party cyber forensic firm and learned that an unauthorized actor obtained access to certain ILS systems between June 30 and July 5, 2022.

“During that period, some information stored on the ILS network was acquired by the unauthorized actor, and other information was accessible and potentially viewed,” ILS posted on its website.

After a preliminary investigation, ILS posted a data breach alert on its website in September 2022. However, the healthcare provider did not directly contact the victims until March 2023, several months after the probe concluded on January 17, 2023.

According to the final assessment, the Independent Living Systems breach exposed both personal and protected health information, including:

  • Full names, dates of birth, and addresses
  • Driver’s license and Social Security numbers,
  • State, taxpayer, Medicare, and Medicaid IDs,
  • Financial account information
  • Medical diagnosis, admission, and discharge information
  • Mental and physical health information
  • Treatment and prescription information
  • Food delivery information
  • Health insurance, billing, and claims information.

However, the type of information leaked varies from one patient to another. Nevertheless, it severely impacts the victims’ privacy and could lead to phishing attacks and identity theft. Meanwhile, ILS said it was unaware of any identity theft resulting from the data breach but had notified relevant regulatory authorities and credit monitoring services out of an abundance of precaution.

Additionally, the healthcare provider said it would take additional steps to improve its cyber security and prevent future attacks by strengthening credential requirements, bolstering its perimeter firewalls, timely notifying victims, enhancing internal control protocols, and training employees, among others.

Although ILS withheld information regarding the nature of the attack, its statement suggests it was a ransomware incident, given that some computers became inaccessible, possibly after being encrypted.

More cyber attacks targeting healthcare organizations

Given the vast amount of valuable health and personal information they store, healthcare providers have always been attractive targets for cybercriminals.

The healthcare sector has already recorded multiple high-profile attacks in Q1 2023, apart from the Independent Living Systems data breach, which is the largest healthcare data leak so far this year.

In February 2023, healthcare provider Community Health Systems (CHS) disclosed a data breach exploiting a zero-day vulnerability in Fortra’s GoAnywhere MFT (managed file transfer) tool.

Similarly, Heritage Provider Network members reported a data breach that exposed the Protected Health Information of 3.3 million patients.

“The series of data breaches against healthcare organizations come as no surprise, but what is surprising is that week after week, more organizations fall prey to the same type of attacks,” said Jocelyn Houle, Senior Director, Data Governance at Securiti.

According to Houle, these data breaches demonstrate the need for healthcare organizations to prioritize data privacy and security.

“Healthcare data – the most treasured record in the Underground Economy,” noted Tim Schultz, VP of Research & Development at SCYTHE, “The healthcare industry is going to continue to be targeted by threat actors and I don’t see it stopping anytime soon.”