BAS Blog

Hackers Accessed Server and Stole PHI of Medical Supply Company

Written by BAS | Jan 23, 2014 11:30:00 AM

A medical supply company based in Ohio had its servers compromised earlier this year. Hackers gained access to protected health information of approximately 4,200 individuals stored on its servers. This information included names, date of birth, medical diagnosis, order history, telephone number. Credit card information was accessed for a small number of these individuals.

It is reported that the hackers gained access to the servers through an Adobe software product. Malware was installed on the servers which was able to access users’ login information.

The company contacted individuals and reset user IDs and passwords.

BAS employs sophisticated anti-virus software, along with the Tripwire change-management product which would have prevented such breach. BAS has a full-time employee dedicated to watching BAS servers and identifying any changes to BAS systems. This dedication to security change-management protects the personal information of clients’ employees and avoids breaches like the one experienced by the medical supply company.

For more information about BAS’ security practices, contact security@BASusa.com.