News, Analysis, Trends, Management Innovations for
Clinical Laboratories and Pathology Groups

Hosted by Robert Michel

News, Analysis, Trends, Management Innovations for
Clinical Laboratories and Pathology Groups

Hosted by Robert Michel
Sign In

American Associated Pharmacies Struck by Ransomware Attack

Clinical laboratories and anatomic pathology groups should consider these cyberattacks on major healthcare entities as reminders that they should tighten their cybersecurity protections

Hackers continue to gain access to public health records—including clinical laboratory testing data—putting thousands of patients’ protected health information (PHI) at risk of being exposed. The latest important healthcare entity to become the victim of a ransomware attack is American Associated Pharmacies (AAP). According to The Register, AAP announced a ransomware operation called Embargo had stolen over 1.4 terabytes (TB) of data, encrypted those files, and demanded $1.3 million to decrypt the data.

Embargo claims that Scottsboro, Ala.-based AAP paid $1.3 million to have its systems restored. They are now demanding an additional $1.3 million to keep the stolen data private, the HIPAA Journal reported, adding, “The attack follows ransomware attacks on Memorial Hospital and Manor, an 80-bed community hospital and 107 long-term care facility in Georgia, and Weiser Memorial Hospital, a critical access hospital in Idaho.”

AAP has not publicly confirmed the ransomware attack, nor has it made an official statement regarding the breach. But it did post an “Important Notice” on its website reporting, “limited ordering capabilities for API Warehouse have been restored at APIRx.com.”

API Warehouse is a subsidiary of AAP that helps subscribers save on brand name and generic prescriptions via wholesale purchasing plans. It oversees more than 2,000 independent pharmacies across the US and has over 2,500 stock keeping units (SKUs) in its inventory.

The message further states “All user passwords associated with both APIRx.com and RxAAP.com have been reset, so existing credentials will no longer be valid to access the sites. Please click ‘forgot password’ on the log in screen and follow the prompts accordingly to reset your password.”

“Embargo seems to have international and multi-sector victims and is not focusing on a specific victim profile. They seem opportunistic,” Mike Hamilton (above), founder and chief information security officer (CISO) of cybersecurity firm Critical Insight, told HealthcareInfoSecurity. “However, as they do have multiple victims in healthcare, and their tooling to disable detection is sophisticated, they should not be discounted. If indeed they operate through affiliates, we can expect others to use their infrastructure and tools, and Embargo may emerge as a top threat to healthcare.” Since 80% of all medical records are made up of clinical laboratory testing data, laboratory patients are particularly vulnerable. (Photo copyright: Critical Insight.)

Embargo on the Hunt for PHI

Due to the large amount of data Embargo stole from the AAP servers, it’s likely the hackers were able to procure medical records and account details from all customers of the pharmacies involved in the attack. 

Researchers at ESET, an internet security company, first noticed the ransomware organization known as Embargo in June of this year. In a news release, ESET stated that Embargo used an endpoint detection and response (EDR) killer toolkit to steal AAP’s data. 

“Based on its modus operandi, Embargo seems to be a well-resourced group. It sets up its own infrastructure to communicate with victims. Moreover, the group pressures victims into paying by using double extortion: the operators exfiltrate victims’ sensitive data and threaten to publish it on a leak site, in addition to encrypting it,” ESET wrote in a news release.

Embargo recently attacked other organizations within the healthcare industry as well. In November, it claimed responsibility for breaching the security of Memorial Hospital and Manor in Bainbridge, Ga. The cyberattack affected Memorial’s email and electronic medical record (EHR) systems, which caused the facility to pivot to a paper-based system, The Cyber Express reported. 

Embargo’s attack on Weiser Memorial Hospital in Weiser, Idaho, involved the theft of approximately 200 gigabytes (GB) of sensitive data and caused a four-week-long outage of its computer systems.  

Other Cyberattacks on Healthcare Organizations

Dark Daily has covered many cyberattacks on hospital health systems in multiple ebriefs over the past few years.

In “Cyberattack Renders Healthcare Providers across Ascension’s Hospital Network Unable to Access Medical Records Endangering Patients,” we summarized how Ascension’s inability to access medical records during the attack caused major disruptions to patient healthcare. It took more than a month for Ascension’s electronic health record system to be fully restored.

In “Change Healthcare Cyberattack Disrupts Pharmacy Order Processing for Healthcare Providers Nationwide,” Dark Daily outlined how a February cyberattack on Change Healthcare caused its parent organization UnitedHealth Group to file a Material Cybersecurity Incidents Report (form 8-K) with the US Securities and Exchange Commission (SEC) in which it stated it had “identified a suspected nation-state associated cybersecurity threat actor [that] had gained access to some of the Change Healthcare information technology systems.”

A few days later the real identity of the threat actor was revealed to be a ransomware group known as BlackCat (aka, ALPHV), according to Reuters.

And in, “Continued Cyberattacks on Hospitals, Clinical Laboratories, and Other Providers Cause Closures as Hackers Grow in Sophistication,” we reported how hospitals of all sizes continue to be prime targets for sophisticated cyberattacks, where hackers remotely disable a healthcare network’s computer systems—including its clinical laboratory information system (LIS)—and extort ransomware payments.

Safeguarding patient data is critical, and more healthcare organizations are discovering the hard way that they are vulnerable to hackers. This situation serves as another reminder to clinical laboratory and pathology group managers that they need to be proactive and serious about protecting their information systems, and in upgrading their digital security at regular intervals.

Hackers are working hard to obtain access to protected health information, which puts patients at continuous risk of having their private records stolen.

—JP Schlingman

Related Information:

Ransomware Fiends Boast They’ve Stolen 1.4TB from US Pharmacy Network

Another Major US Healthcare Organization Has Been Hacked, with Potentially Major Consequences

Gang Shaking Down Pharmacy Group for Second Ransom Payment

US Pharmacy Network Loses 1.4 Terabytes of Data to Boasting Hackers

New Ransomware Group Embargo Uses Toolkit That Disables Security Solutions, ESET Research Discovers

Embargo Ransomware Group Claims Attack on American Associated Pharmacies

American Associated Pharmacies Resets All User Passwords after Ransomware Gang Claims Responsibility for Cyberattack

Ransomware Attack Disrupts Memorial Hospital’s EHR System, Temporarily Slows Operations

Weiser Memorial Hospital Investigating Cyberattack

Hospital Deals with IT Outage for 4 Weeks

Healthcare Cyberattacks at Two Hospitals Prompt Tough Decisions as Their Clinical Laboratories Are Forced to Switch to Paper Documentation

Three Federal Agencies Warn Healthcare Providers of Pending Ransomware Attacks; Clinical Laboratories Advised to Assess Their Cyberdefenses

Ex-Theranos Founder and CEO Elizabeth Holmes Reduced Her Prison Sentence by Nearly Two Years

Good behavior in federal prison by the disgraced founder of the now-defunct clinical laboratory company earned her the reduction in her original sentence of 11 years

Elizabeth Holmes, founder of failed clinical laboratory blood analysis company Theranos, continues to serve a lengthy term in prison after being convicted of multiple counts of fraud in 2022. However, now comes news that good behavior at her federal prison has shortened her sentence by nearly two years, according to NBC News.

The latest reduction took Holmes’ release from December 2032 to August 2032 in her “11-plus-year (135 month) prison sentence for wire fraud and conspiracy,” NBC reported, adding that Holmes, though Theranos, “defrauded investors out of hundreds of millions of dollars.”

Holmes entered FPC Bryan, a federal prison camp in Bryan, Texas, to begin serving her term in May 2023.

“Holmes had her sentence computation done within the first 30 days of arriving at Bryan,” Forbes reported. Given Good Conduct Time (GCT), Holmes was given 608 days off calculated from the start of her sentence. “If she were to incur a disciplinary infraction, some of those days can be taken away. Most all prisoners receive 54 days per year of GCT based on the sentence imposed,” Forbes added.

The Federal Bureau of Prisons (BOP) can additionally shave off up to a year through its Residential Drug Abuse Program (RDAP). “To qualify, the prisoner must not have a disqualifying offense, such as terrorism or gun charge, and voluntarily provided information that they had a drug or alcohol problem prior to their arrest. This disclosure has to be done prior to sentencing during the pre-sentence interview and must be also documented in the Presentence Report, a detailed report used by the BOP to determine things like classification and programming for the prisoner,” Forbes noted.

Additionally, the federal First Step Act, which President Trump signed into law in 2018, enables Holmes to “earn up to 365 days off any imposed sentence by participating in prison programming such as a self-improvement classes, a job, or religious activities,” Forbes reported.

Given the opportunities to shave time off her sentence, Holmes may ultimately serve just 66 months of her original 135 month sentence in federal prison.

Elizabeth Holmes (above) taken backstage at TechCrunch Disrupt San Francisco 2014 when Holmes was at the height of her fame and popularity. At this point, Theranos’ Edison blood testing device had not yet been shown to be a fake. But evidence was mounting as clinical laboratory scientists and anatomic pathologists became aware of the technology’s shortcomings. (Photo copyright: Max Morse/Wikimedia Commons.)

Fall of a Silicon Valley Darling

Theranos boasted breakthrough technology and became an almost overnight sensation in Silicon Valley when it burst onto the scene in 2003. Holmes, a then 19-year-old Stanford University dropout, claimed Theranos would “revolutionize the world of blood testing by reducing sample sizes to a single pin prick,” Quartz reported.

The height of the company saw Theranos valued at $9 billion, which came crashing down when the Wall Street Journal reported in 2015 that questionable accuracy and procedures were being followed by the company, CNN reported.

In “After AACC Presentation, Elizabeth Holmes and Theranos Failed to Convince Clinical Laboratory Scientists and the News Media about Quality of Its Technology,” Dark Daily’s Editor-in-Chief Robert Michel reported on Holmes’ presentation at the American Association of Clinical Chemistry (AACC) annual meeting in 2016, after which the clinical laboratory scientists in attendance were highly skeptical of Holmes’ claims.

“From the moment Holmes concluded her presentation and stepped off the podium on Monday afternoon, she, her company, and her comments became the number one subject discussed by attendees in the halls between sessions and in the AACC exhibit hall,” Michel wrote, adding, “The executive team and the investors at Theranos have burned through their credibility with the media, the medical laboratory profession, and the public. In the future, the company’s claims will only be accepted if presented with scientific data developed according to accepted standards and reviewed by credible third parties. Much of this data also needs to be published in peer-reviewed medical journals held in highest esteem.”

A follow-up Dark Daily ebriefing concerning Theranos covered a fraud settlement with the Securities and Exchange Commission (SEC), sanctions from the Centers for Medicare and Medicaid Services (CMS), investor lawsuits, consumer lawsuits, and a settlement with Walgreens over claims about Theranos’ Edison portable blood analyzer. Theranos’ web of lies was unraveling.

Theranos Saga Continues

Ultimately, investors who had jumped in early with financial support for Theranos were defrauded of hundreds of millions of dollars and Holmes was sentenced to 11 years/three months behind bars. 

“Theranos had only ever performed roughly a dozen of the hundreds of tests it offered using its proprietary technology, and with questionable accuracy. It also came to light that Theranos was relying on third-party manufactured devices from traditional blood testing companies rather than its own technology,” CNN added.

The company shut down in 2018.

And so, the Elizabeth Holmes saga continues with reductions in her prison sentence for “good behavior.” The irony will likely not be lost on the anatomic pathologists, clinical laboratory scientists, and lab managers who followed the federal trials.

—Kristin Althea O’Connor

Related Information:

Elizabeth Holmes Sees More Months Trimmed from Prison Release Date

Theranos Founder Elizabeth Holmes’ Prison Sentence Keeps Getting Shorter

Hot Startup Theranos Has Struggled with Its Blood-Test Technology

Elizabeth Holmes Shaves More Time Off Her Sentence

The Infatuation with Elizabeth Holmes’ Prison Term

After AACC Presentation, Elizabeth Holmes and Theranos Failed to Convince Clinical Laboratory Scientists and the News Media about Quality of Its Technology

Previously High-Flying Theranos Provides Clinical Laboratories and Pathology Groups with Valuable Lesson on How Quickly Consumer Trust Can Be Lost

;