Directions for Living (DFL) in Florida experienced a ransomware attack on July 5, 2021 after an unauthorized third party had gained access to its systems “via a firewall vulnerability” and encrypted some of its systems.
The attack exposed the first and last names, addresses, dates of birth, social security numbers, diagnostic codes used for billing purposes, claims and insurance information, name of health care provider, date of health care services, and certain other health information of 19,494 patients.
The healcare offered a single-bureau credit monitoring to all those affected by the incident.
TPRM report: https://scoringcyber.rankiteo.com/company/directions-for-living
"id": "dir22525123",
"linkid": "directions-for-living",
"type": "Ransomware",
"date": "07/2021",
"severity": "75",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': 19494,
'industry': 'Healthcare',
'location': 'Florida',
'name': 'Directions for Living',
'type': 'Healthcare Provider'}],
'attack_vector': 'Firewall Vulnerability',
'customer_advisories': 'Single-bureau credit monitoring offered to all '
'affected',
'data_breach': {'data_encryption': 'Yes',
'number_of_records_exposed': 19494,
'personally_identifiable_information': 'Yes',
'sensitivity_of_data': 'High',
'type_of_data_compromised': ['Personally Identifiable '
'Information (PII)',
'Protected Health Information '
'(PHI)']},
'date_detected': '2021-07-05',
'description': 'Directions for Living (DFL) in Florida experienced a '
'ransomware attack on July 5, 2021 after an unauthorized third '
"party had gained access to its systems 'via a firewall "
"vulnerability' and encrypted some of its systems.",
'impact': {'data_compromised': ['First and last names',
'Addresses',
'Dates of birth',
'Social security numbers',
'Diagnostic codes used for billing purposes',
'Claims and insurance information',
'Name of health care provider',
'Date of health care services',
'Certain other health information'],
'systems_affected': 'Some of its systems'},
'initial_access_broker': {'entry_point': 'Firewall Vulnerability'},
'ransomware': {'data_encryption': 'Yes'},
'threat_actor': 'Unauthorized third party',
'title': 'Ransomware Attack on Directions for Living',
'type': 'Ransomware Attack',
'vulnerability_exploited': 'Firewall Vulnerability'}