Softtek Softtek
  • Our experience
  • Overview
  • Insights
  • Blog
  • Newsroom
  • Careers
  • Contact us
    • Softtek GenAI
    • FRIDA AI for Software Engineering
    • Service Transformation
    • Portfolio Transformation
    • Digital Acceleration
    • Our Work
    • Agribusiness
    • Airlines
    • Automotive
    • Banking & Financial Services
    • Consumer Packaged Goods
    • Energy & Utilities
    • Fitness & Wellness
    • Gaming
    • Government & Public Sector
    • Higher Education
    • Healthcare
    • Industrial
    • Insurance
    • Media & Entertainment
    • Oil & Gas
    • Pharma & Beauty
    • Professional Sports
    • Restaurant & Hospitality
    • Retail
    • Technology
    • Telecommunications
    • Transportation & Logistics
    • Data and AI
    • Software Engineering
    • Quality Engineering
    • DevOps
    • Cloud
      • AWS
      • Azure
    • Cybersecurity
    • Digital IT Operations
      • Application Management
      • IT Infrastructure
      • Observability
    • Enterprise Platforms
      • SAP
      • Microsoft
      • Salesforce
      • ServiceNow
      • Atlassian
      • BlueYonder
    • Softtek Digital Enablers
    • Digital Solutions
      • Digital Optimization
      • Digital Sales
      • Data Masking Solution
      • IT Cost Optimization
      • Fan Engagement Ecosystem
      • FRIDA
  • SUSTAINABILITY
Softtek Blog

Sacred Heart Health Services, down with 14,000 PHI records

Author:
Author Miguel Perez Milicua
Published on:
Mar 26, 2015
Reading time:
Mar 2015
|
SHARE
Share on LinkedIn
Share on X
Share on Facebook
SHARE
Share on LinkedIn
Share on X
Share on Facebook

The ink is barely dry on the Premera Blue Cross security breach and we’re at it again - analyzing another brazen healthcare industry hack. This time it was against Sacred Heart Health Services, a provider in Florida that counts about 700 primary care and specialty physicians on its roster.

This attack differs from the Anthem and Premera attacks of the last 6 weeks, where Advanced Persistent Threats (APT) were identified infecting their networks for months before the breach was detected. Two main things stand out in this incident:

1)     This attack doesn’t seem to be that sophisticated. There was no cutting-edge technology, no zero-day exploits, no APTs or State-sponsored complex attack vectors to their applications or infrastructure layers. This was an attack on the weakest of the computer system layers not typically listed in the technology books, but tremendously important: the human layer.

2)     The deceived employee who caused the breach was not part of the Sacred Hearth Health Services organization, but was part of an organization Sacred Heart hired to help with the client billing process.

SacredheartdatabreachWe can’t tell if Sacred Heart is implementing the correct security measures in their infrastructure and processes. What we do know now is that this vendor was not paying enough attention to their social engineering prevention practices, which led to a breach of their client’s data.

What’s the lesson here?

a)  Personnel training should be prioritized, and it should be a continuous effort.

b)  Your company and your clients’ information are not secure if the third parties with whom you share information are not doing their part.

This time there were “only” 14,000 compromised records (not millions as in previous breaches). However, we cannot forget the potential financial penalty that could be imposed by the Centers for Medicare & Medicaid Services (CMS) if this data in fact contained personal healthcare information (PHI), and the loss was deemed a negligent act.  In addition, as most of you know, breaches that affect over 500 patients are publicly reported by the Office for Civil Rights (OCR), and I doubt any company wants to end up on that list.

Against this risk there is a process commonly known as Vendor Management that deals with performing security audits and ensuring that all parties handling confidential information follow the correct security standards and procedures. It also ensures they are in compliance with applicable laws and regulations. You must ensure your service providers treat the information you share with the same care you do, at the very least.

Related posts

Mar 23, 2015
The Premera Blue Cross Hack – An Analysis
Jul 20, 2014
6 Proven Practices for Organizations to Avoid a Security Breach
Jun 19, 2020
Health Organizations: How to Proactively Retain Members

Let’s stay in touch!

Get Insights from our experts delivered right to your inbox!

Follow us:
Softtek LinkedIn
Softtek Twitter
Softtek Facebook
Softtek Instagram
Softtek Instagram
Follow us:
Softtek LinkedIn
Softtek Twitter
Softtek Facebook
Softtek Instagram
Softtek Instagram

© Valores Corporativos Softtek S.A. de C.V. 2026.
privacy notice
legal disclaimer
code of ethics
our policies
webmaster@softtek.com