Tumor treating fields (TTFields) developer Novocure disclosed this week that a recent cybersecurity incident exposed patient and employee information.
According to an SEC Form 8-K dated Sept. 1, Novocure, through a subsidiary, became aware of unauthorized access to some of its information systems in mid-August. In response, it implemented containment measures, launched an internal investigation, and engaged independent cybersecurity forensic experts.
Baar, Switzerland–based Novocure says exposed data included:
- Internal company patient ID numbers for over 1,400 U.S. patient records (The company says the ID numbers are only used internally and no patient names or other identifying data for these was exposed);
- Patient data for fewer than 50 other patients in the western U.S. that included additional identifying information;
- General contact information for healthcare providers that work with the company;
- General contact information for Novocure employees, such as their job titles and phone numbers.
According to Novocure, no access to any medical treatment devices was obtained, no compromise of operations occurred, and there was no effect on company systems.
Novocure said in the SEC form: “The company takes its obligation to safeguard privacy and security of its patients’ data very seriously. The company continues to evaluate applicable regulatory and legal notification requirements and will make all required notifications based on its findings, including to impacted patients. At this time, we do not believe that this cybersecurity incident will have a material impact or reasonably likely material impact on our financial condition and results of operations; however, at the time of this filing we are continuing to ascertain additional information regarding this incident.”
Novocure media relations could not be immediately reached for comment.
The Novocure data breach is the latest in a string of cybersecurity incidents that medical device companies have disclosed this year. Last week, news broke of a cybersecurity incident that caused a global network communications outage at Boston Scientific. Earlier this year, an Iran-backed cyberattack effectively wiped out data on Stryker’s Microsoft-based IT system. Medtronic, Intuitive, and iRhythm have also reported cybersecurity incidents.
