iRhythm data breach exposes info of 360,000+ patients

iRhythm data breach exposes info of 360,000+ patients

Medical device maker iRhythm has confirmed that a June cyberattack exposed the personal data of at least 360,000 people. Hackers reached company data by tricking their way into business applications hosted by a third party.

The company started filing breach notifications with several US states this week. In those notices, it told regulators and affected people that the incident took place on June 8 and involved unauthorized access to third-party systems.

iRhythm is best known for the Zio Patch, a sensor worn on the chest that continuously monitors a patient's heart over long periods and detects arrhythmias.

Texas and South Carolina hit hardest

The state filings give a partial picture of the scale. According to iRhythm, 298,647 people in Texas had their information stolen, along with 69,526 people in South Carolina. The company also submitted breach notices in California.

A spokesperson declined to share the total number of victims when asked by Recorded Future News. Instead, the spokesperson said iRhythm "responded promptly after detecting the unauthorized access and, once the scope was verified, notified affected individuals and applicable regulators."

The real total may therefore be higher than the figures disclosed so far.

Five days of access through social engineering

iRhythm's investigation found that the attackers were inside company systems from June 3 to June 8. They gained entry to unnamed business applications hosted by a third party, and they did so through a social engineering attack. The company has not said which provider or applications were involved.

The attackers accessed and downloaded the following data:

  • names
  • addresses
  • phone numbers
  • dates of birth
  • iRhythm patient account numbers
  • iRhythm device serial numbers
  • patient insurance numbers
  • dates of service

iRhythm said it has "no evidence that any personal information has been or will be used to commit identity theft." No hacking group has publicly claimed responsibility for the attack.

An extortion demand, disclosed to the SEC

More details appeared in an 8-K filing that iRhythm submitted to the US Securities and Exchange Commission (SEC) in June. Publicly traded companies use the 8-K form to report major events to investors.

In that filing, the company said it "received communications from a threat actor claiming to have obtained sensitive information, including proprietary data, patient protected health information and other personal information."

"The communications from the threat actor demanded payment in exchange for not publicly disclosing this information," the company wrote. It added that it had since "confirmed that certain data was exfiltrated from those applications."

The filing does not say whether iRhythm responded to the demand.

Devices and operations unaffected

iRhythm stressed that the breach stayed away from its medical products. "The incident did not affect iRhythm clinical systems or medical devices and did not result in a loss of service or disruption to operations," the spokesperson said.

According to the company, its products, devices, manufacturing process and distribution operations were not affected, and its finances were not disrupted either. iRhythm reported $224.2 million in revenue for the second quarter.

A sector under pressure

The iRhythm incident is the latest in a long run of attacks on medical device makers. Over the past two years, dozens of companies in the sector have dealt with cybersecurity incidents that hit important business and manufacturing systems.

Medtronic, Boston Scientific, Stryker, UFP, Masimo, Surmodics, Artivion and Zoll have all been targeted. Those attacks leaked sensitive medical data belonging to millions of people and caused supply chain problems.

Why It Matters

For patients, the stolen data set is a concern even without medical records in the list. Names, birth dates, insurance numbers, device serial numbers and dates of service are enough to make phishing messages look convincing. Someone posing as iRhythm or an insurer could cite a real device or appointment. Affected people should treat unexpected calls and emails about their heart monitor or billing with caution.

For defenders, the attack path stands out. The attackers did not need to break into clinical systems or devices. Social engineering against a third-party-hosted business application appears to have been enough. This fits a wider pattern of data theft from the vendors that hospitals and health firms rely on, as seen in the Oracle Health breach and the Clover Health and AngMar incidents.

It is worth watching whether more state filings push the victim count higher. Another open question is whether the extortion group eventually leaks the data. The incident also adds weight to the healthcare cybersecurity bill now headed to the US House.