Breach reported in the US and the UK
Healthcare financial services provider Craneware has reported itself to the FBI in the US, and to the Information Commissioner’s Office (ICO) in the UK, over a cyberattack.
Craneware doesn’t directly provide health care such as nursing, doctoring, and actual treatment; instead it offers:
[A]pplications and [an] industry-leading team of experts [that] contextualize operational, financial, and clinical data, providing insights that clearly demonstrate realistic revenue integrity and 340B compliance opportunities for our customers.
In a document submitted to the London Stock Exchange (LSE), the company offers the curious admission that “a significant volume of file names were viewed and exfiltrated,” which at first reading makes it sound as though file contents (the data in the files themselves) were not stolen in the breach.
But the admission continues by saying that “a large element of the data involved is non-sensitive or already public regulatory data.”
This suggests that, in the breach, the attackers not only created a list of available file names, but also stole all the files on that list.
Remember that even non-sensitive data retained by a company for its own commercial benefit or regulatory compliance isn’t supposed to be accessible to outsiders at will.
And the disclosure statement continues by noting that “a percentage of Craneware employee data as well as a subset of customer and partner records have been accessed and exfiltrated.”
Simply put, although some of the stolen data might be considered “harmless” even though it’s now in the hands of cybercriminals, some of it sounds very personal and private indeed.
In this context, the words percentage and subset aren’t helpful, given that the percentage could be 100%, and in mathematical parlance, a set in its entirety is considered to be a subset of itself.
What to do?
- As an individual, you may not know which providers of actual health care (such as doctors’ surgeries you have visited, hospitals that have treated you, or pharmacies that have supplied you with medication) share data about you with Craneware. If in doubt, check with the organizations or healthcare professionals you’ve dealt with recently.
- If you are a user of Craneware products or services, keep your eyes open for forthcoming notifications that might affect you. Be prepared to pass on any bad news, your own findings, and your proposed response to any affected patients.
- Whether you’re in healthcare or not, make sure you’ve planned for any disclosures you may be in the uncomfortable position of needing to publish in the future. Preparing for failure is not an admission that you intend to fail, and is much better than failing to prepare.
- When penning a breach response, resist the temptation to invite your readers to infer that absence of evidence from the investigation you have done so far is evidence of absence of harm or risk.
Don’t forget, when talking about cyberattacks, that a breach of N critical records of personal information isn’t somehow mitigated just because 10N or even 100N non-personal and apparently “harmless” records were stolen at the same time.
After all, the cumulative damage caused by a breach can’t get smaller as the breach itself gets bigger!
Why not ask how SolCyber can help you do cybersecurity in the most human-friendly way? Don’t get stuck behind an ever-expanding convoy of security tools that leave you at the whim of policies and procedures that are dictated by the tools, even though they don’t suit your IT team, your colleagues, or your customers!
More About Duck
Paul Ducklin is a respected expert with more than 30 years of experience as a programmer, reverser, researcher and educator in the cybersecurity industry. Duck, as he is known, is also a globally respected writer, presenter and podcaster with an unmatched knack for explaining even the most complex technical issues in plain English. Read, learn, enjoy!