ADVERTISEMENT

Ransomware attack forces PhilHealth to shift to manual operations; eyes full restoration of systems 'soon'

Published Sep 26, 2023 08:24 am

The Philippine Health Insurance Corporation (PhilHealth) eyes the full restoration of its system in the coming days after the ransomware attack last week forced it to shift to manual operations.

243339350_227622406059523_227920107253711955_n.jpg
Photo from PhilHealth Facebook page

"For now, PhilHealth has shifted to manual operations since Friday, Sept. 22, and we are expecting that today or tomorrow, we will be able to bring some of these systems back online for use," said PhilHealth Health Finance Policy Sector Senior Vice President Dr. Israel Francis Pargas in a televised interview on Tuesday, Sept. 26.

Despite the challenges posed by the ransomware attack and the shift to manual operations, Pargas said PhilHealth remains committed to ensuring that its members continue to receive benefits.

"If members or employers plan to pay premium contributions, they can still do so at PhilHealth offices over the counter since there is no online facility available at the moment," he added.

Containment measures enforced

In the wake of a recent ransomware attack, PhilHealth said it has taken swift action to implement containment measures aimed at mitigating the impact of the cyberattack.

Based on PhilHealth's preliminary investigation into the incident, Pargas revealed that approximately 72 workstations were affected by the ransomware attack

Pargas noted that the attack specifically targeted critical systems and operations, including PhilHealth's website, e-claim system, member portal, and collection system.

"We deemed it necessary to shut down all our systems first to assess the extent of the information security incident and to reconfigure our systems," Pargas said.

He also explained that this proactive approach was taken to safeguard the security and integrity of their data.

Timeline for restoration  

Pargas noted that while an exact timeline for the full restoration of systems remains uncertain, PhilHealth is diligently working to expedite the process, and testing is underway to ensure the systems function seamlessly, with hopes of resuming normal operations in the coming days.

He also assured PhilHealth members that they will continue to receive benefits despite the ongoing challenges.

"We apologize for this incident, and PhilHealth's operations are still ongoing despite the manual process," he added.

The Medusa Ransomware and alleged ransom demand

Pargas explained that PhilHealth is collaborating with the Department of Information and Communications Technology (DICT) to understand the nature of the Medusa ransomware and its impact on their systems.

He explained that Medusa is an international ransomware syndicate known for encrypting data and then demanding a ransom for decryption.

However, according to PhilHealth's initial investigation, "no personal information leaks or medical data compromises have occurred,” Pargas said.

While there have been reports of a ransom demand, Pargas noted that PhilHealth has not received a direct demand from the attackers.

"So far, there hasn't been a direct demand from PhilHealth, but reports suggest they are demanding around $300,000, or approximately 17 million pesos," he said.

Pargas noted that such demands are typical of ransomware attacks, where data is held hostage until a ransom is paid.  

However, he explained that PhilHealth adheres to government policy and “refuses to pay” any ransom demand.

“As soon as we learned about this on Sept. 22, we immediately reported it to the DICT and have been coordinating with them every step of the way to contain this incident and reconfigure our system," Pargas said.

He also said that the National Privacy Commission, the Cybercrime Units of the Philippine National Police (PNP), and the National Bureau of Investigation (NBI) are actively cooperating with this matter.

Pargas added that a hearing with the National Privacy Commission (NPC) is also scheduled to provide further clarity on the incident. (Zekinah Elize Espina)

Related Tags

PhilHealth DOH
ADVERTISEMENT
.most-popular .layout-ratio{ padding-bottom: 79.13%; } @media (min-width: 768px) and (max-width: 1024px) { .widget-title { font-size: 15px !important; } }

{{ articles_filter_1561_widget.title }}

.most-popular .layout-ratio{ padding-bottom: 79.13%; } @media (min-width: 768px) and (max-width: 1024px) { .widget-title { font-size: 15px !important; } }

{{ articles_filter_1562_widget.title }}

.most-popular .layout-ratio{ padding-bottom: 79.13%; } @media (min-width: 768px) and (max-width: 1024px) { .widget-title { font-size: 15px !important; } }

{{ articles_filter_1563_widget.title }}

{{ articles_filter_1564_widget.title }}

.mb-article-details { position: relative; } .mb-article-details .article-body-preview, .mb-article-details .article-body-summary{ font-size: 17px; line-height: 30px; font-family: "Libre Caslon Text", serif; color: #000; } .mb-article-details .article-body-preview iframe , .mb-article-details .article-body-summary iframe{ width: 100%; margin: auto; } .read-more-background { background: linear-gradient(180deg, color(display-p3 1.000 1.000 1.000 / 0) 13.75%, color(display-p3 1.000 1.000 1.000 / 0.8) 30.79%, color(display-p3 1.000 1.000 1.000) 72.5%); position: absolute; height: 200px; width: 100%; bottom: 0; display: flex; justify-content: center; align-items: center; padding: 0; } .read-more-background a{ color: #000; } .read-more-btn { padding: 17px 45px; font-family: Inter; font-weight: 700; font-size: 18px; line-height: 16px; text-align: center; vertical-align: middle; border: 1px solid black; background-color: white; } .hidden { display: none; }
function initializeAllSwipers() { // Get all hidden inputs with cms_article_id document.querySelectorAll('[id^="cms_article_id_"]').forEach(function (input) { const cmsArticleId = input.value; const articleSelector = '#article-' + cmsArticleId + ' .body_images'; const swiperElement = document.querySelector(articleSelector); if (swiperElement && !swiperElement.classList.contains('swiper-initialized')) { new Swiper(articleSelector, { loop: true, pagination: false, navigation: { nextEl: '#article-' + cmsArticleId + ' .swiper-button-next', prevEl: '#article-' + cmsArticleId + ' .swiper-button-prev', }, }); } }); } setTimeout(initializeAllSwipers, 3000); const intersectionObserver = new IntersectionObserver( (entries) => { entries.forEach((entry) => { if (entry.isIntersecting) { const newUrl = entry.target.getAttribute("data-url"); if (newUrl) { history.pushState(null, null, newUrl); let article = entry.target; // Extract metadata const author = article.querySelector('.author-section').textContent.replace('By', '').trim(); const section = article.querySelector('.section-info ').textContent.replace(' ', ' '); const title = article.querySelector('.article-title h1').textContent; // Parse URL for Chartbeat path format const parsedUrl = new URL(newUrl, window.location.origin); const cleanUrl = parsedUrl.host + parsedUrl.pathname; // Update Chartbeat configuration if (typeof window._sf_async_config !== 'undefined') { window._sf_async_config.path = cleanUrl; window._sf_async_config.sections = section; window._sf_async_config.authors = author; } // Track virtual page view with Chartbeat if (typeof pSUPERFLY !== 'undefined' && typeof pSUPERFLY.virtualPage === 'function') { try { pSUPERFLY.virtualPage({ path: cleanUrl, title: title, sections: section, authors: author }); } catch (error) { console.error('ping error', error); } } // Optional: Update document title if (title && title !== document.title) { document.title = title; } } } }); }, { threshold: 0.1 } ); function showArticleBody(button) { const article = button.closest("article"); const summary = article.querySelector(".article-body-summary"); const body = article.querySelector(".article-body-preview"); const readMoreSection = article.querySelector(".read-more-background"); // Hide summary and read-more section summary.style.display = "none"; readMoreSection.style.display = "none"; // Show the full article body body.classList.remove("hidden"); } document.addEventListener("DOMContentLoaded", () => { let loadCount = 0; // Track how many times articles are loaded const offset = [1, 2, 3, 4, 5, 6, 7, 8, 9, 10]; // Offset values const currentUrl = window.location.pathname.substring(1); let isLoading = false; // Prevent multiple calls if (!currentUrl) { console.log("Current URL is invalid."); return; } const sentinel = document.getElementById("load-more-sentinel"); if (!sentinel) { console.log("Sentinel element not found."); return; } function isSentinelVisible() { const rect = sentinel.getBoundingClientRect(); return ( rect.top < window.innerHeight && rect.bottom >= 0 ); } function onScroll() { if (isLoading) return; if (isSentinelVisible()) { if (loadCount >= offset.length) { console.log("Maximum load attempts reached."); window.removeEventListener("scroll", onScroll); return; } isLoading = true; const currentOffset = offset[loadCount]; window.loadMoreItems().then(() => { let article = document.querySelector('#widget_1690 > div:nth-last-of-type(2) article'); intersectionObserver.observe(article) loadCount++; }).catch(error => { console.error("Error loading more items:", error); }).finally(() => { isLoading = false; }); } } window.addEventListener("scroll", onScroll); });

Sign up by email to receive news.