Institutions

Parkway Health Network: A Ransomware Attack Exposed 210,000 Patient Records That Encryption Could Have Protected

A ransomware attack on Parkway Health Network exposed the protected health information of 210,000 patients. Federal investigators found the attack succeeded in part because the network had not implemented data encryption at rest or the risk analysis processes that HIPAA required.

Parkway Health Network LLC, a multispecialty physician group network, agreed to pay a HIPAA resolution agreement of $1.4 million after a ransomware attack on its systems exposed the protected health information of approximately 210,000 patients — and federal investigators found that the attack's success in accessing and encrypting patient data was facilitated by the network's failure to implement data encryption for protected health information stored on its servers and by its failure to conduct and act on the risk analysis that HIPAA's Security Rule requires as the foundation for an organization's entire security management program.DOCUMENTED

Ransomware attacks on healthcare organizations encrypt the victim's data and demand payment for the decryption key, disrupting clinical operations and in many cases exposing patient data through exfiltration prior to encryption. The healthcare sector has been among the most heavily targeted by ransomware actors because patient data has high value on criminal markets, healthcare organizations maintain large volumes of sensitive personal and medical information, and the operational criticality of clinical systems creates pressure to pay ransoms quickly to restore access. HIPAA's Security Rule is designed to require organizations to implement safeguards that reduce the attack surface available to ransomware and other threat actors, and failures to implement those safeguards contribute directly to the impact of successful attacks.REVIEWED

Key facts
  • 210,000 patients' protected health information exposed in the ransomware attack
  • Exposed data included names, dates of birth, Social Security numbers, insurance information, and clinical data
  • Investigators found Parkway had not conducted the comprehensive risk analysis required under HIPAA's Security Rule before the breach
  • Protected health information on servers accessed by the ransomware actor was not encrypted at rest
  • Parkway had not implemented a risk management plan to address the vulnerabilities identified in its existing security assessments
  • $1.4 million HIPAA resolution agreement and corrective action plan required

The Risk Analysis Failure

HIPAA's Security Rule requires covered entities and their business associates to conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of all electronic protected health information they hold. This risk analysis is not a one-time exercise — it must be conducted periodically, updated when circumstances change, and used as the basis for an ongoing risk management program that implements security measures sufficient to reduce identified risks to a reasonable level. The risk analysis requirement exists because it is the mechanism by which organizations identify the specific vulnerabilities in their systems that create exposure to threats like ransomware.REVIEWED

Investigators found that Parkway had not conducted the comprehensive risk analysis that HIPAA requires — its existing security assessments were incomplete and had not been updated to reflect the organization's current technology environment, including systems that had been added or modified in the period before the breach. The incomplete risk analysis meant that vulnerabilities in those systems — including the absence of encryption on servers containing patient data — had not been formally identified, assessed, or prioritized for remediation through the risk management process that a completed risk analysis would have driven.DOCUMENTED

Encryption and Its Absence

HIPAA's Security Rule designates encryption of data at rest as an addressable specification — organizations must implement it unless they document a specific reason why it is not reasonable and appropriate and implement an equivalent alternative measure. In practice, for most healthcare organizations holding significant volumes of sensitive patient data on networked servers, encryption at rest is the standard expected safeguard, and regulators treat failure to implement it without documented justification as a Security Rule deficiency.REVIEWED

When patient data is encrypted at rest, a ransomware actor who gains access to the storage medium cannot read the underlying data — the encryption that protects the data from unauthorized access is separate from the ransomware encryption that disrupts operations. The absence of encryption at rest at Parkway meant that the ransomware actor's access to the network also constituted access to readable patient data, enabling the data exfiltration component of the attack that gave the actor leverage beyond simply disrupting operations and that produced the reportable breach of patient information.DOCUMENTED

If Parkway had implemented encryption for protected health information stored on its servers, the ransomware actor's network access would not have constituted a breach of patient data — the data would have been inaccessible without the encryption keys Parkway controlled.

Corrective Action Plan

The HIPAA resolution agreement requires Parkway to implement a comprehensive corrective action plan including a complete risk analysis under a specified methodology, a risk management plan that identifies and prioritizes remediation of the vulnerabilities identified in the risk analysis, implementation of encryption for all electronic protected health information at rest, enhanced access controls and authentication requirements for systems containing patient data, and regular security training for all workforce members with access to protected health information. The plan is subject to HHS monitoring with required progress reporting at specified intervals.DOCUMENTED

Patients whose information was exposed in the Parkway breach should have received breach notification; those who have not received notification but believe they may have been affected should contact Parkway directly. Affected patients should consider placing credit freezes with the three major credit bureaus given the inclusion of Social Security numbers in the exposed data, and should monitor their explanation of benefits statements for unauthorized medical claims that could indicate identity theft or medical identity theft using their exposed insurance information.REVIEWED

Healthcare Cybersecurity Resources

Healthcare organizations that are building or assessing their HIPAA Security Rule compliance programs can access substantial guidance through the HHS Office for Civil Rights, which publishes a Security Risk Assessment tool, guidance documents on each Security Rule safeguard, and model policies and procedures that covered entities and business associates can use as starting points. The HHS 405(d) task group has also published healthcare-specific cybersecurity practices that address the most prevalent threat vectors — including ransomware — with specific guidance calibrated to organizations of different sizes. Small and medium-sized healthcare organizations that lack dedicated security staff should consider working with a qualified HIPAA security consultant who can conduct the risk analysis required by the Security Rule and help prioritize remediation of the most significant vulnerabilities identified. The cost of a thorough security program is substantially lower than the combination of a HIPAA resolution agreement, breach notification obligations, and reputational consequences that follow a significant ransomware event.

Have documents relevant to this story? Reach us through our tips channel.

Every Watchdog Journal investigation is built on primary documents and classified under our evidence standard.

Browse All Investigations →