Article Details

Scrape Timestamp (UTC): 2024-06-26 01:08:47.765

Source: https://www.theregister.com/2024/06/26/geisinger_nuance_microsoft_worker/

Original Article Text

Click to Toggle View

Microsoft blamed for million-plus patient record theft at US hospital giant. Probe: Worker at speech-recog outfit Nuance wasn't locked out after firing. American healthcare provider Geisinger fears highly personal data on more than a million of its patients has been stolen – and claimed a former employee at a Microsoft subsidiary is the likely culprit. Geisinger on Monday announced the results of a probe into a November computer security breach, placing the blame on Microsoft-owned Nuance Communications for not cutting off one of its employees' access to corporate files after that person was fired. The Pennsylvania-based healthcare giant uses Nuance as an IT provider. We're told that after the Microsoft-owned entity terminated one of its workers, that staffer two days later may have accessed and taken copies of sensitive records on a huge number of Geisinger patients – for reasons as yet unknown. Geisinger – which says it operates 13 hospitals and has more than 600,000 members – said it discovered the improper access on November 29, informed Nuance, and the IT supplier immediately cut off the former employee from the healthcare group's data before involving police. "Because it could have impeded their investigation, law enforcement investigators asked Nuance to delay notifying patients of this incident until now," Geisinger claimed, explaining why only now this is coming to light. "The former Nuance employee has been arrested and is facing federal charges." It's not immediately clear if or what charges have been laid – we've asked Geisinger for details. Speech recognition firm Nuance performed its own probe, according to Geisinger, and determined that the former employee may have stolen information on a million-plus people. That info would include birth dates, addresses, hospital admission and discharge records, demographic information, and other medical data. The ex-employee didn't swipe insurance or other financial information, the multi-billion-dollar healthcare group stated. "We continue to work closely with the authorities on this investigation, and while I am grateful that the perpetrator was caught and is now facing federal charges," Geisinger chief privacy officer Jonathan Friesen alleged, "I am sorry that this happened." Who skipped the termination checklist again? While this snafu doesn't seem to be Geisinger's fault, Nuance has previously been accused of similar failings. According to news sources, in 2018 San Francisco's Department of Public Health experienced a break-in that was made possible by a former Nuance employee accessing patients' personal information. Nuance didn't respond to questions for this story. Given it's been a Microsoft subsidiary for the past three years, this incident is just as likely to reflect poorly on Redmond – especially given the Windows maker has recently been revealed employing lax security practices that led to the compromise of Exchange Online by Chinese spies who used that intrusion to compromise cloud-based email accounts belonging to US officials. Microsoft has also come in for criticism for Exchange break ins by Russian hackers. Microsoft's sub-optimal infosec practices have even seen former White House cyber policy director AJ Grotto tell us Microsoft is a national security threat.

Daily Brief Summary

DATA BREACH // Over One Million Patient Records Stolen in Nuance Security Lapse

Geisinger, a major U.S. healthcare provider, announced that over a million patient records were likely stolen due to a security breach at Microsoft-owned Nuance Communications.

The breach was pinpointed to unauthorized access by a former Nuance employee who wasn't promptly deactivated from the system after termination.

Sensitive data involved included birth dates, addresses, hospital records, and demographic details; financial information was not reported as stolen.

The incident was detected on November 29, and Nuance cut off the ex-employee's access immediately after being alerted by Geisinger.

Law enforcement delayed the notification to patients to not compromise the ongoing investigation, resulting in a delay in public disclosure.

The accused ex-employee has been arrested and is facing federal charges, although specific charges have not been detailed.

This breach is part of a concerning pattern with Nuance, referencing a similar incident in 2018, and raises questions about Microsoft’s overarching security measures given recent related criticisms.