AlohaCare Data Breach Exposes Nearly 13,000 Individuals’ Sensitive Information

Hawaii-based health provider, AlohaCare, has recently experienced a substantial data breach incident, revealing the sensitivity of the technology utilised in the health sector. Impacted were involving 12,982 individuals who were notified of the unauthorised access related to the MOVEit file-transfer program.

According to a notice filed with the Attorney General of Maine on November 3, 2023, the data breach resulted from a vulnerability in the MOVEit program. The incident made patient information accessible to an unauthorized party.

AlohaCare, in the notice, clarified that the breach led to an unauthorised party gaining access to consumers’ highly sensitive information. This data encompassed critical personal details such as their names, Social Security numbers, addresses, and dates of birth.

While data breaches are unfortunately not uncommon in the modern digital world, it underscores the vital importance for businesses, particularly within the health industry, to apply stringent security measures to prevent unauthorised access to sensitive data. Such incidents also raise essential questions about the robustness of some of the software solutions currently in use, such as the MOVEit file-transfer program in this instance.

With a multitude of global data protection regulations, such as GDPR in Europe and CCPA in California, it becomes increasingly imperative for companies to not only protect consumer data but also promptly notify the victims and authorities when breaches occur, as AlohaCare has done.

All corporations, including law firms, must recognise the potential legal consequences of data breaches and continuously invest in stronger encryption, employee training, and various other cybersecurity measures to defend against such vulnerabilities.