Sandhills Medical Foundation has posted a observation of a data certificate incident on their web site, reproduced below. Based on the dates and description, it appears that this is the Netgain Technology LLC data transgress that has previously been noted on DataBreaches.net as affecting Ramsey County and Woodcreek provider Services. as reported this week, Woodcreek is notifying more than 200,000 patients, but their report is not yet listed on HHS’s public breach tool. Sandhills medical Foundation’s report is also not yet on HHS’s breach cock and we have no numbers for them as yet. It’s possible that we may insure i report from Netgain Technology LLC to HHS as the business colligate or vendor, but in any event, it seems clear that details about the impact of this incident are allay emerging. This transgress is a useful example, though, of what can happen and at how many points the entity might make been able to thwart or avoid the biggest voice of the breach. Had employee email not been compromised in September… had the attackers not been able to access the system in November.. had the attackers exfiltrating data been detected and blocked… had the attackers been kicked out before they could deploy ransomware on December 3…. This is another one of those “if only” breaches…. mark of data breach at Sandhills Medical Foundation, Inc., we measure our patients and their privacy.�This note is to inform our patients about an incident that involved their personal information. What Happened Sandhills medical Foundation, Inc. (Sandhills) uses an outside vendor to provide electronic data memory for some of its scheduling, billing, and reporting systems. On january 8, 2021, the vendor informed Sandhills that the vendor experienced a ransomware attack that affected Sandhills systems and the data stored in them. The vendors investigation showed that the attackers used compromised credentials to access their system on september 23, 2020. The attackers accessed Sandhills systems on november 15, 2020, and exfiltrated (took) Sandhills data before the ransomware attempt was launched on december 3, 2020. What Information Was Involved Sandhills determined that patient medical records, lab results, medications, citation card numbers and bank account numbers were�NOT�affected. The affected data included patient names, dates of birth, mailing and email addresses, drivers licenses, and social Security numbers. It also included claims information which could be used to determine patient diagnoses/conditions. What We are Doing The vendor reported the assail to law enforcement and hired a cybersecurity firm to investigate and answer to the attack. The vendor paid the attackers to payoff the data and received assurances that copies of the data were deleted/destroyed. Since the attack, the vendor has implemented additional certificate measures. Sandhills reported the breach to the U.S. Department of Health and human Services, Office for Civil Rights; to the South Carolina department of Consumer Affairs; and to the national credit reporting agencies. Sandhills sent a letter to each affected patient describing the incident and offering one year of loose citation monitoring and identity theft protection. Learn More For questions about how to enrol in the free citation monitoring and identity theft tribute services, affected patients should telephone 1-888-236-0854. To speak directly with Sandhills Compliance Officer about this incident, patients should telephone 1-800-688-5525.