Ransomware

HIPAA Journal

πŸ“… 2024-04-01 🏒 MediSecure eScripts prescription delivery platform
Primary Source β†—

Incident Details

MediSecure, an Australian electronic prescription delivery service provider, suffered a ransomware attack in April 2024. Approximately 6.5 TB of data was exfiltrated, impacting approximately 12.9 million Australians who used the service between March 2019 and November 2023. Compromised data included names, dates of birth, email addresses, postal addresses, phone numbers, Medicare numbers, healthcare identifier numbers, medication details (prescribed drugs, strength, quantity), and reasons for prescriptions. MediSecure subsequently entered voluntary administration and the company later went into liquidation. This was one of Australia’s largest healthcare data breaches.

Technical Details

Initial Attack Vector
CWE-284: Improper Access Control
Vendor / Product
MediSecure eScripts prescription delivery platform

Timeline

  1. 2024-04-01 Breach occurred
  2. 2024-05-16 Publicly disclosed
  3. 2024-07-18 Customers notified