CorrectCare Integrated Health, a third-party health administrator, suffered a healthcare data breach that stemmed from a misconfigured web server.
Patient information contained in two file directories was exposed.
The breach impacted 85,466 individuals at the Louisiana Department of Public Safety and Corrections.
The breach also impacted more than 438,000 individuals at the California Department of Corrections and Rehabilitation (CDCR).
Current and former inmates at the Alaska Department of Corrections and the Georgia Department of Corrections were also impacted by the breach.
TPRM report: https://scoringcyber.rankiteo.com/company/correctcare-integrated-health
"id": "cor152491222",
"linkid": "correctcare-integrated-health",
"type": "Data Leak",
"date": "07/2022",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': 85466,
'industry': 'Corrections',
'location': 'Louisiana',
'name': 'Louisiana Department of Public Safety and '
'Corrections',
'type': 'Government'},
{'customers_affected': 438000,
'industry': 'Corrections',
'location': 'California',
'name': 'California Department of Corrections and '
'Rehabilitation (CDCR)',
'type': 'Government'},
{'industry': 'Corrections',
'location': 'Alaska',
'name': 'Alaska Department of Corrections',
'type': 'Government'},
{'industry': 'Corrections',
'location': 'Georgia',
'name': 'Georgia Department of Corrections',
'type': 'Government'}],
'attack_vector': 'Misconfigured Web Server',
'data_breach': {'number_of_records_exposed': [85466, 438000],
'type_of_data_compromised': 'Patient Information'},
'description': 'CorrectCare Integrated Health, a third-party health '
'administrator, suffered a healthcare data breach that stemmed '
'from a misconfigured web server. Patient information '
'contained in two file directories was exposed. The breach '
'impacted 85,466 individuals at the Louisiana Department of '
'Public Safety and Corrections and more than 438,000 '
'individuals at the California Department of Corrections and '
'Rehabilitation (CDCR). Current and former inmates at the '
'Alaska Department of Corrections and the Georgia Department '
'of Corrections were also impacted by the breach.',
'impact': {'data_compromised': 'Patient Information'},
'title': 'CorrectCare Integrated Health Data Breach',
'type': 'Data Breach',
'vulnerability_exploited': 'Misconfiguration'}