Fishers dental office reports ransomware attack on patient records

I have taught classes on ransomware to tax professionals for Indiana University. I have seen how much damage one of these attacks can do to a business and to the people who trust it with their personal information. Now a ransomware attack has hit a health care office here in Fishers.

Bright Smile Dental Care, Ltd., 9931 Eller Road, has posted a notice online saying it found ransomware on its server Aug. 3. The notice says the attack affected the practice’s patient records and practice management software, along with its dental imaging software.

The practice says it brought in cybersecurity consultants right away to look into the attack and limit the damage.

According to the notice, the information that may have been involved includes patients’ names, dates of birth, addresses, email addresses, phone numbers, insurance information, information about dependents, health information and, in some cases, Social Security numbers. Bright Smile says patients’ financial information was not affected.

The practice believes the risk to patients is low. It says all data on the server was encrypted and there is “no indication that the threat actor possessed the encryption keys necessary to view the underlying data.”

“While we have no evidence that any of our patients’ information was misused, we are providing this notice to explain the incident,” the practice said.

That is good news if it holds up. In my experience teaching this subject, though, many ransomware groups now copy data before they lock it up, then threaten to release it unless they get paid. Bright Smile’s investigation found no sign of that here, but staying alert costs patients nothing.

Bright Smile is mailing letters to all affected patients it has contact information for. It is also notifying the national consumer reporting agencies and reviewing its security policies.

Patients whose Social Security numbers may have been involved can get free credit monitoring through TransUnion. Instructions for signing up will be in the letter.

What patients can do

  • Check bank statements and credit reports for anything unusual.
  • Get free credit reports at annualcreditreport.com or by calling 1-877-322-8228.
  • Place a fraud alert or credit freeze with Experian (1-888-397-3742), Equifax (1-800-525-6285) or TransUnion (1-800-680-7289).
  • Contact the Federal Trade Commission’s identity theft hotline at 877-438-4338 (TTY: 1-866-653-4261), or visit ftc.gov/idtheft.
  • Report any suspicious activity to Bright Smile.

The notice does not say how many patients were affected or whether the attackers asked for a ransom.