医信观察 · MED IT
中文译文网络安全与信创

医疗IT供应商数据泄露,近400万份患者记录曝光

Health IT Vendor’s Data Breach Exposes Nearly 4M Patient Records

MedCity News··约 2 分钟阅读
译文892 字

医疗技术供应商

Unlimited Technology Systems披露了一起数据泄露事件,影响约380万名患者。

这家总部位于Ohio的收入周期管理供应商为4,500多家肿瘤诊所和6,500家专科医疗服务提供商处理账单业务。该公司表示,黑客于10月5日至10日期间访问了其商业数据中心。上个月,受影响患者开始陆续收到通知信。

这起事件成为今年向HHS报告的第二大医疗数据泄露事件,仅次于针对业务流程外包商Conduent Business Services的攻击;后者导致超过6,200万人的数据曝光。

这两起事件表明,单个遭到入侵的供应商究竟能够让多少患者面临风险——尽管依赖Unlimited进行账单和理赔处理的数千家医疗服务提供机构中,大多数与该公司从未有过直接接触,而且其本身也没有参与此次数据泄露。

Unlimited确认这是一起勒索软件攻击,但目前尚无任何团体声称对此次攻击负责。曝光的数据因患者而异,但包括社会安全号码、医疗记录、诊断和治疗详情以及扫描的保险卡。

该公司尚未说明是否支付了赎金,也未说明攻击者最初是如何访问其系统的。由于调查仍在进行,安全研究人员表示,受影响人员的总数可能会进一步增加,因为供应商数据泄露事件往往如此。

这起攻击属于一个更广泛的趋势。代表医疗服务提供机构处理理赔、账单和记录的供应商,占今年规模最大的十起医疗数据泄露事件中的六起——这促使HHS提议收紧HIPAA Security Rule中关于供应商监管的要求,不过该规则尚未最终确定。

这起事件发生的时间也与行业数据相吻合。根据Comparitech的月度跟踪数据,仅7月份,针对医疗保健公司的勒索软件攻击就增加了46%;该数据还显示,与2025年同期相比,截至目前针对医疗服务提供机构的攻击增加了20%。

在另一起7月事件中,黑客声称从另一家医疗账单软件供应商Craneware Group窃取了近1TB的文件数据。

如果2026年的趋势持续下去,Unlimited此次数据泄露事件无论是在规模还是在涉事公司方面,可能都不会长期保持这一排名。

图片:boonchai wedmakawand,Getty Images

原文2,003 字符

Health tech vendor

Unlimited Technology Systems disclosed a data breach affecting about 3.8 million patients.

The Ohio-based revenue cycle management vendor processes billing for more than 4,500 oncology practices and 6,500 specialty providers. It said hackers accessed its commercial data center between October 5-10. Notification letters began going out to affected patients last month.

The incident marks the second-largest healthcare data breach reported to HHS this year, outranked by an attack on business process outsourcer Conduent Business Services, which exposed the data of more than 62 million people.

Both incidents demonstrate just how much a single compromised vendor can expose patients who have never directly interacted with the company at all — given most of the thousands of provider organizations that rely on Unlimited for billing and claims processing had no role in the breach itself.

Unlimited confirmed the attack was ransomware, but no group has claimed responsibility for the attack. The exposed data varied by patient but included Social Security numbers, medical records, diagnosis and treatment details and scanned insurance cards.

The company has not said whether it paid a ransom or how the attackers initially gained access to its systems. With the investigation still open, security researchers say the total number of affected individuals could climb further, as it often does in the case of vendor breaches.

The attack is part of a broader trend. Vendors that process claims, billing and records on providers’ behalf have accounted for six of this year’s ten largest healthcare breaches — which has prompted HHS to propose tightening the HIPAA Security Rule’s requirements for vendor oversight, though the rule has yet to be finalized.

The incident’s timing also lines up with industry data. Ransomware attacks on healthcare companies rose 46% in July alone, according to monthly tracking from Comparitech, which also showed that attacks on providers specifically are up 20% year-over-date compared to the same period in 2025.

In a separate July incident, hackers claimed to have stolen nearly a terabyte of file data from Craneware Group, another medical billing software vendor.

If 2026’s pattern holds, Unlimited’s breach may not hold its rank for long, either in scale or in company.

Photo: boonchai wedmakawand, Getty Images

原始信源MedCity News