Editions:

Stolen ChipSoft patient data destroyed following cyberattack

The European healthcare sector faces another major cybersecurity incident. ChipSoft, a leading Dutch medical software provider, has confirmed the deletion of patient data stolen during an early April ransomware attack.

  • The ChipSoft cyberattack is a major event for the industry. -

ChipSoft had no choice but to admit it. The statements come weeks after the incident was detected, which has affected sensitive patient information and put hospitals and medical centers on alert.

A delayed detected attack

The incident came to light on April 7, when company employees identified anomalous activity in their systems.

Initially, the company avoided classifying the event as a serious attack and described it as a data-related issue.

However, as days passed, it was confirmed that a medical information exfiltration had occurred, one of the most delicate scenarios in terms of privacy and security.

The compromised data included medical records and other highly sensitive personal information, increasing the risk of fraud, extortion, or misuse of the information.

This type of attack has a particularly high impact in the healthcare field, where data protection is critical for both legal and ethical reasons.

The role of ransomware and how cybercriminals acted

The attack was attributed to the ransomware group known as Embargo, which allegedly accessed the company's systems and stole the data before encrypting or threatening to publish it.

This attack model, known as double extortion, has become one of the most used in recent years.

In these cases, cybercriminals not only block access to systems but also steal information to pressure victims.

The threat of publishing medical data adds an additional level of severity, as it can directly affect the privacy of thousands of people.

ChipSoft has not clarified whether it ultimately agreed to pay a ransom. The company has acknowledged that conversations with the attackers took place, but has not confirmed the outcome of those negotiations.

The destruction of the data: an unusual confirmation

One of the most striking elements of the case is the company's claim about the deletion of the stolen data.

According to the company, the destruction has been verified in a way they consider technically correct, although they have not detailed the procedure used.

This type of confirmation is not common in ransomware incidents. In most cases, organizations cannot guarantee with certainty that the data has been deleted, even if a payment has been made.

Therefore, the lack of transparency about the method used raises doubts among cybersecurity experts.

Authorities and specialized agencies usually warn that trusting the word of attackers does not eliminate the risk of future leaks.

Impact on the healthcare system

The relevance of this incident is amplified by ChipSoft's weight in the Dutch healthcare ecosystem.

The company has a market share of over 70% in hospitals, meaning a large part of the country's digital infrastructure depends on its solutions.

Among the affected systems are key platforms like HiX in its various versions, as well as patient portals and mobile applications used in the daily management of healthcare.

As a preventive measure, the company decided to disconnect several of these applications, forcing medical centers to resort to alternative procedures for several days.

Such interruptions can directly affect hospital operations, from appointment management to access to medical records.

Progressive recovery, indeed

The company has indicated that the recovery process is progressing without major incidents, although it requires time and constant supervision. The restoration of systems in healthcare environments is especially complex, as any error can have critical consequences.

Meanwhile, the forensic investigation remains open. The exact entry point of the attackers has not yet been determined, leaving open the possibility that there were previous vulnerabilities in the infrastructure or failures in security protocols.

ChipSoft is collaborating with different organizations, including entities specialized in healthcare cybersecurity and data protection authorities. This type of cooperation is key to understanding the real scope of the incident and preventing future attacks.

ChipSoft had no choice but to admit it. The statements come weeks after the incident was detected, which has affected sensitive patient information and put hospitals and medical centers on alert.

A delayed detected attack

The incident came to light on April 7, when company employees identified anomalous activity in their systems.

Initially, the company avoided classifying the event as a serious attack and described it as a data-related issue.

However, as days passed, it was confirmed that a medical information exfiltration had occurred, one of the most delicate scenarios in terms of privacy and security.

The compromised data included medical records and other highly sensitive personal information, increasing the risk of fraud, extortion, or misuse of the information.

This type of attack has a particularly high impact in the healthcare field, where data protection is critical for both legal and ethical reasons.

The role of ransomware and how cybercriminals acted

The attack was attributed to the ransomware group known as Embargo, which allegedly accessed the company's systems and stole the data before encrypting or threatening to publish it.

This attack model, known as double extortion, has become one of the most used in recent years.

In these cases, cybercriminals not only block access to systems but also steal information to pressure victims.

The threat of publishing medical data adds an additional level of severity, as it can directly affect the privacy of thousands of people.

ChipSoft has not clarified whether it ultimately agreed to pay a ransom. The company has acknowledged that conversations with the attackers took place, but has not confirmed the outcome of those negotiations.

The destruction of the data: an unusual confirmation

One of the most striking elements of the case is the company's claim about the deletion of the stolen data.

According to the company, the destruction has been verified in a way they consider technically correct, although they have not detailed the procedure used.

This type of confirmation is not common in ransomware incidents. In most cases, organizations cannot guarantee with certainty that the data has been deleted, even if a payment has been made.

Therefore, the lack of transparency about the method used raises doubts among cybersecurity experts.

Authorities and specialized agencies usually warn that trusting the word of attackers does not eliminate the risk of future leaks.

Impact on the healthcare system

The relevance of this incident is amplified by ChipSoft's weight in the Dutch healthcare ecosystem.

The company has a market share of over 70% in hospitals, meaning a large part of the country's digital infrastructure depends on its solutions.

Among the affected systems are key platforms like HiX in its various versions, as well as patient portals and mobile applications used in the daily management of healthcare.

As a preventive measure, the company decided to disconnect several of these applications, forcing medical centers to resort to alternative procedures for several days.

Such interruptions can directly affect hospital operations, from appointment management to access to medical records.

Progressive recovery, indeed

The company has indicated that the recovery process is progressing without major incidents, although it requires time and constant supervision. The restoration of systems in healthcare environments is especially complex, as any error can have critical consequences.

Meanwhile, the forensic investigation remains open. The exact entry point of the attackers has not yet been determined, leaving open the possibility that there were previous vulnerabilities in the infrastructure or failures in security protocols.

ChipSoft is collaborating with different organizations, including entities specialized in healthcare cybersecurity and data protection authorities. This type of cooperation is key to understanding the real scope of the incident and preventing future attacks.