MCNA Dental Settles LockBit Breach Affecting 8.9 Million Patients
The government-sponsored dental provider will pay millions in legal fees after a ransomware attack exfiltrated 700 GB of sensitive patient data.
Managed Care of North America (MCNA) Dental has reached a multi-million dollar settlement to resolve litigation following a massive data breach. The agreement follows a ransomware attack that compromised the sensitive personal and medical information of 8,923,662 patients.
According to court documents and reports from the HIPAA Journal, the settlement includes payments for litigation costs up to $1,313,000 and attorneys' fees reaching up to $6,400,000. The scale of the exposure makes it one of the larger healthcare-related data breaches in recent years.
The LockBit Attack
The breach was perpetrated by the LockBit ransomware group, a notorious cybercriminal collective. Between February 6 and March 7, 2023, the group successfully exfiltrated approximately 700 GB of data from MCNA's systems. The stolen information included highly sensitive records, such as Social Security numbers, insurance claims, and detailed records of patient care.
MCNA operates as one of the largest providers of government-sponsored dental care in the United States, primarily serving Medicaid and the Children's Health Insurance Program (CHIP). Because the provider handles data for vulnerable populations under government contracts, the exposure of such a vast volume of personal identifiers creates a significant security risk for the affected patients.
Industry Implications
This settlement underscores the escalating financial and legal liabilities facing healthcare providers that fail to secure patient data. The healthcare sector has become a primary target for ransomware groups due to the critical nature of the services provided and the high black-market value of medical records.
Javvad Malik, Lead Security Awareness Advocate at KnowBe4, noted that the information stolen in this breach represents a "treasure trove" for criminals, who can leverage the data to execute sophisticated identity theft or social engineering attacks against the victims.
Looking Ahead
As healthcare entities continue to digitize records and integrate with government systems, the attack surface for ransomware groups expands. The MCNA case serves as a warning that the cost of settlement and litigation can be staggering when millions of records are compromised.
Industry observers will be watching for further regulatory actions or potential fines from health oversight bodies. While the settlement resolves private litigation, it does not necessarily preclude government penalties for HIPAA violations or failures in safeguarding government-sponsored health data.