The Medical College of Wisconsin, a Milwaukee, Wisconsin-based private medical school, said it experienced a significant cyber security incident that compromised the sensitive personal information of employees and patients.
In a notice of data security incident published on its official website, the Medical College of Wisconsin (MCW) said it used Progress Software’s MOVEit Transfer web application to send and receive files securely and was impacted after cyber criminals exploited a zero-day vulnerability in the application earlier this year.
“Upon being informed of the vulnerability, MCW immediately took actions to mitigate and assess the scope of information potentially compromised, including engaging third-party professionals to assist in the investigation and remediation of the vulnerability.
“As part of our investigation, we engaged leading cybersecurity experts to identify what personal information, if any, was involved,” MCW
said.
The medical school’s internal investigation revealed that around May 27, the threat actors accessed certain files that contained the sensitive personal information of people associated with the medical school.
The compromised data included full names, dates of birth, social security numbers, driver’s license numbers, government identification numbers, financial account information, medical record and patient account numbers, medical diagnosis details, treatment information, medical provider names, lab results, prescription information, and health insurance information.
In a recent filing with the U.S. Department of Health and Human Services Office for Civil Rights, MCW
stated that at least 240,667 individuals were affected by the data security incident.
“MCW has no evidence that any personal information has been or will be misused as a direct result of this incident. However, out of abundance of caution, commencing on November 14, 2023, MCW notified individuals whose information may have been included in the files potentially removed by the unauthorised party,” the medical college added.
MCW said it is offering complimentary credit monitoring services to all affected individuals and details of the same will be included in all personalised notification letters.
More than 2,550 organisations worldwide have so far suffered significant data breaches as a result of the Clop ransomware group exploiting vulnerabilities in Progress Software’s MOVEit Transfer web application.
According to German cybersecurity research firm KonBriefing, as of November 23, at least 2,588 organisations worldwide have suffered security incidents resulting from the exploitation of the software and up to 82.5 million individuals have been impacted so far.