Exploit: Hacking
ARcare: Medical Clinics
Risk to Business: 1.711 = Severe
ARcare, a medical services company that operates clinics for underserved communities in Arkansas, Kentucky and Mississippi, disclosed a data breach impacting an estimated 345,000 patients in a filing with The U.S. Department of Health and Human Services (HSS). After a disruptive incident on February 24, 2022, an investigation turned up the unwelcome news that a malicious hacker had access to ARcare’s network over a five-week period between January 18 and February 24.
Risk to Business: 1.814 = Severe
Potentially exposed patient data includes names, Social Security numbers, drivers’ license or state identification numbers, dates of birth, financial account information, medical treatment information, prescription information, medical diagnosis or condition information and health insurance information.
How It Could Affect Your Customers’ Business: This is going to be a very expensive problem once regulators get finished with it.
Source: portswigger