In 2023, NASCO, a healthcare technology provider, experienced a data breach. The incident originated via the third-party MOVEit Transfer by Progress Software, which was exploited by the Clop ransomware group. NASCO learned of the breach on July 12, 2023, and began notifying affected individuals by October 27, 2023.
The breach affected 1,744,655 individuals in Georgia. The exposed data included names, addresses, phone numbers, genders, dates of birth, health insurance numbers, claim information, medical IDs, dates of service, medical information (including diagnoses), medical devices/products, caregiver names, and Social Security Numbers. NASCO is a business associate for health plans, meaning the breach had a downstream impact on its health plan customers.
Details can continue to emerge as investigations proceed, and notification timelines may vary.