Norwegian's Healthcare Breach Affecting More Than Half Of The Nation's Population

Cybercriminals have managed to breach Norway's Helse Sør-Øst (Health South-East, or RHF), and reportedly stolen personal information and health records of about 2.9 million people out of the total 5.2 million Norwegians inhabitants.

This is more than half of the nation's population.

RHF is a healthcare organization that manages hospitals in the Norway's southeast region, including Østfold, Akershus, Oslo, Hedmark, Oppland, Buskerud, Vestfold, Telemark, Aust-Agder and Vest-Agder.

The healthcare organization announced the data breach on Monday after it had been alerted by HelseCERT, the Norwegian CERT department for its healthcare sector, about an "abnormal activity" that happened on the computer systems in the region.

But here, the healthcare authorities have failed the General Data Protection Regulation requirements for notifying those that were affected by waiting a week before disclosing a breach discovered on 8 January 2018

The culprit behind the data breach are "advanced and professional" hackers. However, the healthcare organization assured that security "measures had been taken to limit the damage caused by the burglary."

"We are in a phase where we try to get an overview. It's far too early to say how big the attack is. We are working to acquire knowledge of all aspects, " NorCERT director Kjetil Nilsen said. "Everything indicates that it is an advanced player who has the tools and ability to perform such an attack. It can be advanced criminals. There is a wide range of possibilities."

Digital healthcare has been growing to satisfy the demands of connected healthcare technology that provides better treatment and improved patient care.

But since the healthcare sector is part of the critical national infrastructure, alongside water, electricity and transport, it becomes an attractive target for hackers. What's more, health data can be more expensive if compared to data from stolen credit cards on the dark web markets.

This is because healthcare data that holds information about names, birth dates, policy numbers, diagnosis codes, social security number and billing information - has a longer lifespan than financial data, and is rich enough in information for identity theft.