'Only a Bluff': Did PhilHealth Officials Mismanage the Ransomware Attack?
After a 10-day standoff with cyber attackers, the Philippine Health Insurance Corporation (PhilHealth) stated on Tuesday, October 3, that hackers have begun releasing the insurer's pertinent information—the extent of which is yet to be determined.
The unfortunate Medusa ransomware attack is the latest brouhaha in the agency's recent shaky history. Reports, nonetheless, seem to indicate a somewhat dismissive attitude Philhealth officials had toward the hackers.
The PhilHealth website and online application portal were attacked on September 22. This led to the insurer conducting services and transactions offline for a few days. The group behind the data breach asked for a $300,000 (approximately P17 million) ransom, or else it would release valuable PhilHealth data on the dark web. Early on, the insurer stated that this was "clearly a bluff." Its website was down for a few days before it was restored on September 29.
As promised by the group if its demands weren't met, Philhealth information was, of course, compromised and released. However, conflicting reports on the extent of the breach have clouded the whole ordeal, leaving some questioning just how transparent the agency was during the attack.
ALSO READ:
PhilHealth Update: 92 Percent of 'Missing' P15 Billion Liquidated, But...
How Powerful Is PhilHealth Mafia? It Ousted Presidents, Enjoyed Lap Dances
So How Worried Should Members Be?
Philhealth application servers and workstations were said to be affected. Files in the hard drive of these infected workstations have likely been compromised. That much, the public knows.
In an initial analysis of the published information, Department of Information and Communications Technology (DICT) Undersecretary Jeffrey Dy said that only Philhealth employees' identification cards were in trouble. These include their payroll data, as well as information about the agency's regional offices, directives, operational costs, and the like.
The member database, on the other hand, was said to be "intact." Membership data, financial data, and claims data were marked safe.
Meanwhile, PhilHealth Senior Vice President and Spokesman Israel Pargas claims that the ransomware attack did not affect servers with members' private information. "PhilHealth’s membership database, claims, contribution and accreditation information which are stored in a separate database are intact and completely unaffected by the said cyberattack," a statement insisted.
But it could be argued that reading between the lines of PhilHealth's own statements partly suggests that information on members may well have been affected, as well.
Another report from Inquirer says that user data was, indeed, compromised, based on the insurer's statement and subsequent apology. “The number of data subjects or records involved is still undetermined, but we are working relentlessly to gather all relevant information,” it said in a statement. It was also noted that PhilHealth would "notify all affected individuals directly.”
Names, addresses, dates of birth, sex, phone numbers, and PhilHealth identification numbers are potentially at risk here. Affected individuals were asked to monitor credit card reports and to change passwords on online accounts.
“If you have not received a notification from us, you may not have been affected," it said in a statement. “We sincerely apologize for any inconvenience this incident caused. We are committed to protecting your data by continuously working to enhance our security measures.”
A More Thorough Investigation Is in Order
PhilHealth officials like Eli Santos said that the public can pinpoint the attack on new government procurement rules. The executive vice president and chief operating officer of the agency noted that PhilHealth had failed to renew its antivirus software licenses last year.
The Government Procurement Policy Board had revised one of its rules for procurement involving online subscriptions, including computer software and applications. In Resolution No. 05-2022, agencies could purchase online items via credit card only if the subscription value does not exceed P1 million. Chances are, the price for the renewal of the antivirus software went beyond that amount.
This means that the computer system is outdated and is left vulnerable to attacks. Santos, nevertheless, stated that “incident response” and antivirus systems should fix the data breach problem.
At the very least, the primary database was said to not have been affected. Apart from investigations by PhilHealth and the DICT, the National Privacy Commission (NPC) is doing a separate investigation to dig deeper into the root cause. It also hopes to hold accountable any official on the insurer's side found to have been negligent in the debacle.
Likewise, Gabriela party-list Rep. Arlene Brosas expressed that an "urgent investigation" by the House is in order. She chastised the agency for the belated admission of the data breach.
“The implications of this cyber attack might be worse in magnitude, considering the belated admission of PhilHealth and the pendency of investigations of concerned agencies such as the (NPC),” Brosas explained.
Malacañang has yet to issue a statement on the cyberattack as of this writing. The implications of all this will be concluded in due time.