Security Affairs reports that U.S.-based healthcare management services firm QualDerm Partners was noted by the Department of Health and Human Services to have had data from more than 3.1 million individuals stolen following a December data breach.
Infiltration of certain QualDerm systems between Dec. 23 and 24 allowed threat actors to exfiltrate patients' sensitive information, including names, birthdates, medical records, treatments and diagnoses, health insurance details, and government IDs, said the health provider in its breach notice.
QualDerm has moved to immediately contain the breach, as well as sought the assistance of an external cybersecurity forensics company to investigate the incident. Despite the lack of any evidence suggesting misuse of compromised data, impacted individuals who were given complimentary identity theft and credit monitoring services for a year have been advised to closely track their Explanation of Benefits forms and account statements and report suspicious activity.
Infiltration of certain QualDerm systems between Dec. 23 and 24 allowed threat actors to exfiltrate patients' sensitive information, including names, birthdates, medical records, treatments and diagnoses, health insurance details, and government IDs, said the health provider in its breach notice.
QualDerm has moved to immediately contain the breach, as well as sought the assistance of an external cybersecurity forensics company to investigate the incident. Despite the lack of any evidence suggesting misuse of compromised data, impacted individuals who were given complimentary identity theft and credit monitoring services for a year have been advised to closely track their Explanation of Benefits forms and account statements and report suspicious activity.





