{"id":25663,"date":"2025-01-10T09:10:13","date_gmt":"2025-01-10T17:10:13","guid":{"rendered":"https:\/\/www.palada.net\/index.php\/2025\/01\/10\/news-19386\/"},"modified":"2025-01-10T09:10:13","modified_gmt":"2025-01-10T17:10:13","slug":"news-19386","status":"publish","type":"post","link":"https:\/\/www.palada.net\/index.php\/2025\/01\/10\/news-19386\/","title":{"rendered":"BayMark Health Services sends breach notifications after ransomware attack"},"content":{"rendered":"\n<p>BayMark Health Services, Inc. (BayMark) notified an unknown number of patients that attackers stole their personal and health information.<\/p>\n<p>BayMark profiles itself as North America\u2019s largest provider of medication-assisted treatment (MAT) for substance use disorders helping tens of thousands of individuals with recovery.<\/p>\n<p>In a <a href=\"https:\/\/ago.vermont.gov\/sites\/ago\/files\/documents\/2025-01-08%20BayMark%20Health%20Services%20Data%20Breach%20Notice%20to%20Consumers.pdf\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">breach notification<\/a>, the company disclosed that on October 11, 2024 it learned about an incident that disrupted the operations of some of its IT systems. This incident consisted of an unauthorized party accessing some of the files on BayMark\u2019s systems between September 24 and October 14 of last year.<\/p>\n<p>An investigation showed that the exposed files contained information that varied per patient but could have included the patient\u2019s name and one or more of the following:<\/p>\n<ul>\n<li>Social Security number (SSN)<\/li>\n<li>Driver\u2019s license number<\/li>\n<li>Date of birth<\/li>\n<li>The services received and the dates of service<\/li>\n<li>Insurance information<\/li>\n<li>Treating provider<\/li>\n<li>Treatment and\/or diagnostic information<\/li>\n<\/ul>\n<p>While BayMark did not provide any information about the number of victims or the nature of the accident, it has been separately <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/largest-us-addiction-treatment-provider-notifies-patients-of-data-breach\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">reported<\/a> that the RansomHub ransomware group has BayMark listed on their leak site.<\/p>\n<p>The RansomHub ransomware group claims to have exfiltrated an enormous 1.5 terabytes of sensitive data from BayMark Health Services.<\/p>\n<figure class=\"wp-block-image aligncenter size-full\"><img decoding=\"async\" loading=\"lazy\" width=\"412\" height=\"321\" src=\"https:\/\/www.malwarebytes.com\/wp-content\/uploads\/sites\/2\/2025\/01\/RansomHub_leak_site.jpg\" alt=\"BayMark\u2019s listing on RansomHub leak site\" class=\"wp-image-147400\" \/><figcaption class=\"wp-element-caption\">BayMark\u2019s listing on RansomHub leak site<\/figcaption><\/figure>\n<p>The date on the dark web site matches the date published in the breach notification. Further, the fact that the data are listed as \u201cpublished\u201d means that BayMark did not pay the ransom, which is confirmed by the cybercriminals you click through on the company&#8217;s tile.<\/p>\n<figure class=\"wp-block-image aligncenter size-full\"><img decoding=\"async\" loading=\"lazy\" width=\"766\" height=\"498\" src=\"https:\/\/www.malwarebytes.com\/wp-content\/uploads\/sites\/2\/2025\/01\/RansomHub_leak_site2.jpg\" alt=\"BayMark\u2019s expanded listing on RansomHub leak site\" class=\"wp-image-147401\" \/><\/figure>\n<p>Here, the ransomware group lays blame on the company itself. This isn&#8217;t rare for a ransomware group, as the tactics and vernacular are often based around shame, guilt, and a pre-teen-like arrogance. As claimed in the dark web site:<\/p>\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p>One of the few companies from Texas that does not value its data. For a nominal fee, they could have not worried about anything, improved their network and protected themselves. But they chose the path of destroying their reputation, publishing sensitive data and publicizing it in the media.<\/p>\n<p>{names}<\/p>\n<p>These people decided to do other things than their company. BayMark Health Services is dedicated to providing treatment tailored to meet each person regardless of where they are in their recovery journey. BayMark provides a full continuum of care, integrating evidence-based practices, clinical counseling, recovery support, and medical services.<\/p>\n<\/blockquote>\n<h2 class=\"wp-block-heading\" id=\"h-protecting-yourself-after-a-data-breach\">Protecting yourself after a data breach<\/h2>\n<p>There are some actions you can take if you are, or suspect you may have been, the&nbsp;<a href=\"https:\/\/www.malwarebytes.com\/blog\/personal\/2023\/09\/involved-in-a-data-breach-heres-what-you-need-to-know\">victim of a data breach<\/a>.<\/p>\n<ul>\n<li><strong>Check the vendor\u2019s advice.<\/strong>&nbsp;Every breach is different, so check with the vendor to find out what\u2019s happened, and follow any specific advice they offer.<\/li>\n<li><strong>Change your password.<\/strong>&nbsp;You can make a stolen password useless to thieves by changing it. Choose a&nbsp;<a href=\"https:\/\/www.malwarebytes.com\/computer\/how-to-create-a-strong-password\" target=\"_blank\" rel=\"noreferrer noopener\">strong password<\/a>&nbsp;that you don\u2019t use for anything else. Better yet, let a&nbsp;<a href=\"https:\/\/www.malwarebytes.com\/what-is-password-manager\" target=\"_blank\" rel=\"noreferrer noopener\">password manager<\/a>&nbsp;choose one for you.<\/li>\n<li><strong>Enable two-factor authentication (2FA).<\/strong>&nbsp;If you can, use a FIDO2-compliant hardware key, laptop or phone as your second factor. Some forms of&nbsp;<a href=\"https:\/\/www.malwarebytes.com\/glossary\/multi-factor-authentication-mfa\" target=\"_blank\" rel=\"noreferrer noopener\">two-factor authentication (2FA)<\/a>&nbsp;can be phished just as easily as a password. 2FA that relies on a FIDO2 device can\u2019t be phished.<\/li>\n<li><strong>Watch out for fake vendors.<\/strong>&nbsp;The thieves may contact you posing as the vendor. Check the vendor website to see if they are contacting victims, and verify the&nbsp;identity of anyone who contacts you&nbsp;using a different communication channel.<\/li>\n<li><strong>Take your time.<\/strong>&nbsp;Phishing attacks often impersonate people or brands you know, and use themes that require urgent attention, such as missed deliveries, account suspensions, and security alerts.<\/li>\n<li><strong>Consider not storing your card details<\/strong>. It\u2019s definitely more convenient to get sites to remember your card details for you, but we highly recommend not storing that information on websites.<\/li>\n<li><strong>Set up identity monitoring.<\/strong>&nbsp;<a href=\"https:\/\/go.cyrus.app\/MN4j\/fkkekmw9\" target=\"_blank\" rel=\"noreferrer noopener\">Identity monitoring<\/a>&nbsp;alerts you if your personal information is found being traded illegally online, and helps you recover after.<\/li>\n<\/ul>\n<p><a href=\"https:\/\/www.malwarebytes.com\/blog\/news\/2025\/01\/baymark-health-services-sends-breach-notifications-after-ransomware-attack\" target=\"bwo\" >https:\/\/blog.malwarebytes.com\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p> BayMark Health Services, Inc. notified an unknown number of patients that attackers stole their personal and health information. <\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10488,10378],"tags":[32287,11172,32,5897,31304,3765],"class_list":["post-25663","post","type-post","status-publish","format-standard","hentry","category-malwarebytes","category-security","tag-baymark","tag-data-breach","tag-news","tag-privacy","tag-ransomhub","tag-ransomware"],"_links":{"self":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/25663","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=25663"}],"version-history":[{"count":0,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/25663\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=25663"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=25663"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=25663"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}