Zoll defibrillator
(image source: Zoll / AED Superstore, n.d.)
One-sentence summary:
Zoll defibrillator company was hacked in January 2023, breaching the sensitive information of and resulting in a lawsuit over 1 million potential, former, or current users (Freedman, 2023).
Who was involved?
Zoll, an Asahi Kasei company, a threat actor, and 1,004,443 potential, former, or current users (Freedman, 2023; Zoll, 2023; Park, 2023, para. 9).
What was the timeline?
January 28, 2023: Breach starts and Zoll immediately detects it
January 29, 2023: Breach ends
February 2, 2023: Zoll determines PII/PHI has been breached (Zoll, 2023, p. 1)
March 10, 2023: Zoll begins consumer notification
March 15, 2023: Class action lawsuit is filed against Zoll in federal court in the Eastern District of Massachusetts
What occurred?
Zoll suffered a data breach in January 2023, which lasted about a day (Freedman, 2023). Zoll quickly responded and stopped the breach. However, they later discovered 1,004,443 potential, former, or current users implicated in a data breach involving both PII and, potentially, PHI (Freedman, 2023; Zoll, 2023; Park, 2023, para. 9). The breached data includes: “name, address, date of birth, and Social Security number. It may also be inferred that you used or were considered for use of a ZOLL product” (Zoll, 2023, p. 1). This incident resulted in a class action lawsuit being filed five days after consumer notification (Brown, 2023; Smith v. Zoll Medical Corporation, 2023). Press reports indicate that Zoll was and still may be investigating the incident on the day the lawsuit was filed (Park, 2023, para. 3).
Estimated costs:
Associated incident response costs, breach notification costs, “third-party cybersecurity experts,” Experian 24 months IdentityWorks (for only SSN victims), “36 months for current/former employees/dependents,” 7-day a week call center, legal and litigation defense costs
Involved laws:
Federal: HIPAA and HITECH.
Federal Trade Commission Act, 15 U.S.C. § 45 (Smith v. Zoll Medical Corporation, 2023, p. 36)
State laws: Maine: 10 M.R.S.A. § 1346
Root cause:
TBA or N/A (see disclaimer)
Lessons learned:
TBA or N/A (see disclaimer)
Sources:
Brown, C. (2023, March 16). Zoll Medical Hit With Suit Over Data Breach Affecting 1 Million. Bloomberg Law. Retrieved March 19, 2023, from https://news.bloomberglaw.com/litigation/zoll-medical-hit-with-suit-over-data-breach-affecting-1-million
Freedman, L. (2023, March 10). Data Breach Notifications. Office of the Maine AG: Consumer Protection: Privacy, Identity Theft and Data Security Breaches. Retrieved March 19, 2023, from https://apps.web.maine.gov/online/aeviewer/ME/40/ab192c35-667d-4bc9-ad18-fa710bd10b15.shtml
Park, A. (2023, March 15). Zoll alerts 1M wearable defibrillator users to data breach that exposed Social Security numbers. Fierce Biotech. Retrieved March 19, 2023, from https://www.fiercebiotech.com/medtech/zoll-alerts-1m-wearable-defibrillator-users-data-breach-may-have-exposed-social-security
Smith v. Zoll Medical Corporation, Docket No. 1:23-cv-10575 (E.D. Mass. 2023). https://www.bloomberglaw.com/public/desktop/document/SmithvZollMedicalCorporationDocketNo123cv10575DMassMar152023Court/1?doc_id=X1Q6OIUBC782
Zoll. (2023). Copy of notice to affected Maine residents: P2.pdf. In Office of the Maine Attorney General: Data Breach Notifications (J1341_L02). Office of the Maine Attorney General. Retrieved March 19, 2023, from https://apps.web.maine.gov/online/aeviewer/ME/40/ab192c35-667d-4bc9-ad18-fa710bd10b15/62e89cd4-2f01-4ef1-be2a-6a453a3938ce/document.html
Zoll / AED Superstore. (n.d.). 8513-001103-01%20ZOLL%20AED%20-%20front%201000×1000.jpg. AED Superstore. https://www.aedsuperstore.com/assets/images/8513-001103-01%20ZOLL%20AED%20-%20front%201000×1000.jpg
Commentary:
This was an above-average incident response and customer turnaround time (per what I have been reporting lately). Good job Zoll. Zoll also told the press that the incident does not affect their defibrillator products (Park, 2023, para. 2). After learning Zoll was still investigating the incident, I was hoping Zoll could release more details on the root cause and lessons learned to better other companies and the cyber community– but given there is active litigation, this is unlikely.
