Planned Parenthood Investigating Cyberattack; RansomHub Group Takes Credit

The RansomHub threat group, a ransomware-as-a-service operation behind several recent attacks on healthcare organizations, has added Planned Parenthood to its dark web data leak site and claims to have stolen 93 GB of data in the attack.

There is no reason to doubt that RansomHub was behind the attack on Planned Parenthood. RansomHub is known to engage in double extortion tactics, stealing data, encrypting files, and leaking the data if the ransom is not paid. The group’s dark web data leak site includes many listings where data has been leaked following nonpayment of the ransom. Planned Parenthood has not confirmed the authenticity of RansomHub’s claims but Planned Parenthood of Montana has issued a statement confirming a cybersecurity incident was identified on August 28, 2024, and that its incident response protocols were implemented, which included taking portions of its network offline as a precaution.

An investigation is underway and its IT staff are working round the clock to securely restore the affected systems. Martha Fuller, president and CEO of Planned Parenthood of Montana, confirmed that she is aware of the listing on RansomHub’s dark web data leak site and has reported the incident to federal law enforcement. What is unclear at present is the extent of any data breach and how much patient data, if any, has been stolen in the attack. RansomHub has uploaded screenshots to its data leak site, but none include any patient data.

This is not the first ransomware attack to hit a Planned Parenthood center, as Planned Parenthood of Los Angeles fell victim to a ransomware attack in 2021 that involved the protected health information of around 400,000 individuals. An attack on a healthcare provider that provides reproductive and sexual health services is a new low for the ransomware group, as the exposure of highly sensitive data could be especially harmful to patients due to the sensitivity of data stored, especially considering the current restrictions on abortion procedures in many U.S. states.

According to a recent cybersecurity alert from the Cybersecurity and Infrastructure Security Agency (CISA), Federal Bureau of Investigation (FBI), Multi-State Information Sharing and Analysis Center (MS-ISAC), and the Department of Health and Human Services (HHS), RansomHub has conducted at least 210 attacks since the group appeared in February 2024, and the group also attempted to extort Change Healthcare after obtaining the data stolen in its February 2024 Blackcat ransomware attack.

About Liam Johnson

Liam Johnson has produced articles about HIPAA for several years. He has extensive experience in healthcare privacy and security. With a deep understanding of the complex legal and regulatory landscape surrounding patient data protection, Liam has dedicated his career to helping organizations navigate the intricacies of HIPAA compliance. Liam focusses on the challenges faced by healthcare providers, insurance companies, and business associates in complying with HIPAA regulations. Liam has been published in leading healthcare publications, including The HIPAA Journal. Liam was appointed Editor-in-Chief of The HIPAA Guide in 2023. Contact Liam via LinkedIn: https://www.linkedin.com/in/liamhipaa/