Article Details

Scrape Timestamp (UTC): 2024-06-26 00:48:09.958

Source: https://www.theregister.com/2024/06/26/geisinger_nuance_microsoft/

Original Article Text

Click to Toggle View

Microsoft blamed for million-plus patient record theft at US hospital giant. Probe: Worker at speech-recog outfit Nuance wasn't locked out after firing. American healthcare provider Geisinger fears highly personal data on more than a million of its patients has been stolen – and claimed a former employee at a Microsoft subsidiary is the likely culprit. Geisinger on Monday announced the results of a probe into a November computer security breach, placing the blame on Microsoft-owned Nuance Communications for not cutting off one of its employees' access to corporate files after that person was fired. The Pennsylvania-based healthcare giant uses Nuance as an IT provider. We're told that after the Microsoft-owned entity terminated one of its workers, that staffer two days later may have accessed and taken copies of sensitive records on a huge number of Geisinger patients – for reasons as yet unknown. Geisinger – which says it operates 13 hospitals and has more than 600,000 members – said it discovered the improper access on November 29, informed Nuance, and the IT supplier immediately cut off the former employee from the healthcare group's data before involving police. "Because it could have impeded their investigation, law enforcement investigators asked Nuance to delay notifying patients of this incident until now," Geisinger claimed, explaining why only now this is coming to light. "The former Nuance employee has been arrested and is facing federal charges." It's not immediately clear if or what charges have been laid – we've asked Geisinger for details. Speech recognition firm Nuance performed its own probe, according to Geisinger, and determined that the former employee may have stolen information on a million-plus people. That info would include birth dates, addresses, hospital admission and discharge records, demographic information, and other medical data. The ex-employee didn't swipe insurance or other financial information, the multi-billion-dollar healthcare group stated. "We continue to work closely with the authorities on this investigation, and while I am grateful that the perpetrator was caught and is now facing federal charges, I am sorry that this happened," declared Geisinger chief privacy officer Jonathan Friesen. Who skipped the termination checklist again? While this snafu doesn't seem to be Geisinger's fault, Nuance has previously been accused of similar failings. According to news sources, in 2018 San Francisco's Department of Public Health experienced a break-in that was made possible by a former Nuance employee accessing patients' personal information. Nuance didn't respond to questions for this story. Given it's been a Microsoft subsidiary for the past three years, this incident is just as likely to reflect poorly on Redmond – especially given the Windows maker has recently been revealed employing lax security practices that led to the compromise of Exchange Online by Chinese spies who used that intrusion to compromise cloud-based email accounts belonging to US officials. Microsoft has also come in for criticism for Exchange break ins by Russian hackers. Microsoft's sub-optimal infosec practices have even seen former White House cyber policy director AJ Grotto tell us Microsoft is a national security threat.

Daily Brief Summary

DATA BREACH // Massive Patient Data Theft Linked to Lax Subsidiary Security Practices

Geisinger, a major US healthcare provider, announced that over a million patient records may have been stolen following a security breach tied to Microsoft-owned Nuance Communications.

The breach was attributed to a former Nuance employee who retained access to sensitive files after being terminated, leading to unauthorized data extraction two days post-dismissal.

The compromised data included birth dates, addresses, hospital admission and discharge records, and other personal medical details, although no financial information was reportedly taken.

Nuance and Geisinger collaborated with law enforcement, leading to the arrest of the ex-employee facing federal charges, although specific charges are still not disclosed.

This incident surfaces amid previous accusations against Nuance for similar security failings, including an incident in 2018 involving the San Francisco Department of Public Health.

Jonathan Friesen, Geisinger's chief privacy officer, expressed regret over the incident and reassured ongoing cooperation with authorities to address the data breach.

The incident casts a negative light on Microsoft, reflecting broader criticisms regarding its subsidiary's lax security measures and raising concerns about national security implications.