25% off all training courses Offer ends May 29, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends May 29, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Ransomware Attacks Affect Community Access Unlimited and CareSouth Carolina Patients

Hartsville, SC-based CareSouth Carolina has notified 76,035 patients that some of their protected health information has potentially been compromised in a ransomware attack on its IT vendor, Netgain Technologies.

CareSouth Carolina was informed by Netgain on January 14, 2021 that the company had experienced a ransomware attack in December 2020, and the attackers had access to servers containing patient data from late November, some of which was exfiltrated prior to the use of ransomware.

On April 13, 2021, Netgain provided CareSouth Carolina with a copy of the data that was potentially compromised. CareSouth Carolina conducted a review of the data and on April 27, 2021 confirmed the dataset included patient names, date of birth, address, diagnosis/conditions, lab results, medications, and other clinical information. For a small number of patients, Social Security numbers were involved.

The attackers issued a ransom demand to Netgain and threatened to sell the stolen data if payment was made. Netgain took the decision to pay the ransom and received assurances that the stolen data was deleted and had not been further disclosed.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

Netgain and CareSouth have since implemented additional security measures to prevent any repeat attacks, and CareSouth is offering affected patients complimentary identity theft protection services.

Community Access Unlimited Ransomware Attack Impacts 13,813 Individuals

Elizabeth, NJ-based Community Access Unlimited has started notifying 13,813 individuals that their protected health information was stored on systems that were accessed by unauthorized individuals.

Community Access Unlimited identified suspicious activity within its internal systems on November 10, 2020. The systems were immediately taken offline, and third-party forensics specialists were engaged to determine the nature and scope of the breach.

The investigation revealed its systems were accessed by unauthorized individuals between June 29, 2020 and November 12, 2020, but it was not possible to determine whether any patient data was accessed or exfiltrated by the attackers.

A review of the compromised systems revealed the following data could potentially have been accessed or obtained: Names, dates of birth, driver’s license numbers, state identification card numbers, non-resident identification numbers, health information, health insurance beneficiary numbers, and usernames and passwords.

Policies and procedures have since been reviewed and enhanced to reduce the potential for a further attack. Affected individuals have now been notified and complimentary credit monitoring and identity restoration services have been offered to potentially impacted individuals.

Author: Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist