NovoCure was hit by a cyberattack that led to the exposure of patient, employee and healthcare provider data.
The cancer treatment company said there was unauthorized access to some of its information systems, which led to the data exposure. NovoCure disclosed the attack Tuesday in a filing with the Securities and Exchange Commission, writing that the incident was discovered in mid-August.
Based on its investigation, NovoCure determined that the exposed data included internal company patient ID numbers for more than 1,400 U.S. patient records. Patient ID numbers are only used internally, and the patients’ names or other identifying data were not exposed, according to the filing.
Along with the ID numbers, patient data for fewer than 50 other patients in the western U.S. were exposed, including additional identifying information, as were general contact information for healthcare companies that NovoCure works with and general contact information for NovoCure employees, like job titles and phone numbers.
The company stated that no operations have been affected by the attack.
“No access to any of our medical treatment devices was obtained, our ability to operate has not been compromised and all of our systems are fully functional,” NovoCure said in the filing.
At this time, NovoCure does not believe that the cyberattack will have a material impact. However, the company is still determining the extent of the attack.
NovoCure initiated its cybersecurity response plan upon detection of the unauthorized access, implemented containment measures and launched an internal investigation. The company is also working with independent cybersecurity forensic experts to assist with the investigation, including reviewing the exposed data.
The company did not respond to MedTech Dive’s request for comment by publishing time.
Novocure has developed tumor treating field technology that uses alternating electric fields to disrupt rapid cell division characteristic of cancer cells, while minimizing damage to healthy tissue. In February, the company received Food and Drug Administration approval for its technology to treat pancreatic cancer.
The list of medtech companies hit by cyberattacks this year continues to grow. NovoCure’s incident follows attacks on companies like Stryker, Medtronic, Intuitive and Abbott, among others.
Boston Scientific is one of the most recent companies to be affected. The medical device maker disclosed last week that an attack has disrupted product manufacturing, as well as its ability to receive and ship orders. The company is still working to restore operations.