The Register Home Page

back to article Kidney dialysis giant DaVita tells 2.4M people they were snared in ransomware data theft nightmare

Ransomware scum breached kidney dialysis firm Davita's labs database in April and stole about 2.4 million people's personal and health-related information. In a filing with the US Department of Health and Human Services, the global healthcare provider, which operates 2,661 dialysis centers in America, reported that the breach …

  1. Doctor Syntax Silver badge

    Do these organisations just sit there thinking "it can't happen to us" and then when it does claim that security is important to them?

    1. m4r35n357 Silver badge

      More like "nothing will happen to us" IMO.

      1. Anonymous Coward
        Anonymous Coward

        More like I can't see the return on security in my spreadsheets.

    2. Anonymous Coward
      Anonymous Coward

      That's a question you can ask any organisation using Microsoft products without a metric boatload of extra protective measures. Nobody seems to ask why that particular colander after literally decades of patches (which must be well into the Terabytes per year now) is still incapable of holding any water.

      1. GNU Enjoyer
        Facepalm

        >without a metric boatload of extra protective measures.

        Attempting to make microsoft software secure is like seeing the vulnerability of wide open windows you're not allowed to close and opting to painstakingly put plastic wrap over the windows - attackers at best might be slowed down for a few seconds (only for however long it takes to punch a hole through the wrap).

        The only way to mitigate the vulnerability of microsoft software is to close the windows by not using microsoft's bugware.

      2. David Hicklin Silver badge

        > nobody seems to ask why that particular colander after literally decades of patches

        Simples - they have a higher priority for producing new stuff and redesigning older stuff like notepad etc over fixing anything.

        AI generated code is going to make that much worse**

        ** moment for thought: If people start using AI to write code, will the AI remember that code , and then will a bad actor be able to query the AI for that code for that program to find any flaws??

    3. David Hicklin Silver badge

      I think modern operating systems and software has reached the point where it is so bloated, patched and bodged together to get it out of the door that it is almost inevitable that any organisation will get breached at some point.

      Sadly once inside an organisation it is far to easily to traverse sideways to just about anywhere, its is well past the time when they should be making that harder (and yes it makes working harder if you have to 2FA everywhere but operating something like a ubikey is not much of a burden) and also not having *everything* immediately on-line - had everyone forgotten about off-line archiving ??

  2. Antron Argaiv Silver badge

    More to the point, why is this information stored unencrypted?

    1. An_Old_Dog Silver badge

      More to the Point ...

      ... why are they capturing and storing photos of cheques?! They have no legitimate business capturing and storing that data!

      1. Anonymous Coward
        Anonymous Coward

        Re: More to the Point ...

        Not saying this is a good idea, but could they be imaging the cheques to submit to the bank electronically? A scaled up version of how I bank a cheque using the bank's phone app.

        1. jdiebdhidbsusbvwbsidnsoskebid Silver badge

          Re: More to the Point ...

          Only until the cheque is cashed, then they should be deleted.

          More to the point, why are poeople still using cheques today?

      2. Anonymous Coward
        Anonymous Coward

        Re: More to the Point ...

        Cheques have signatures. That's the only info that they wouldn't have anyway. So, why do they want signatures ...

      3. hoola Silver badge

        Re: More to the Point ...

        It is probably needed for a short period until the cheque is actually paid.

        The does not mean they should be kept for years.

  3. Anonymous Coward
    Anonymous Coward

    Common?

    I get the impression big attacks on healthcare organisations is very common and increasing. Yet, we are expected to provide evermore personal data which gets splashed around even before the hackers get to work. The way things are going with the surveillance state and their ever growing appetite for our data and id, the only people that wont have access to our data is the good guys; i.e., us, the owners.

  4. may_i Silver badge

    If only the USA had the GDPR

    Then it would be illegal to hold personal data any longer than it is actually needed. The reason for needing it would actually have a proper definition and there would also be legal requirement that personal data held by companies is encrypted at rest so that a network intrusion would not be able to steal the data.

    The only way to stop this story being played over and over again is to have a proper legal framework and to back that up with criminal penalties against the highest management in companies who flout the legal requirements to treat their customer's data like the digital gold that it is.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon

Other stories you might like