Girl in crowd

4/12/2023

Notice of Cyber Security Incident

Nandan Rao

We have become aware of a data security Incident that may have resulted in unauthorized access to some of our members’ sensitive personal information. We have engaged a specialized cybersecurity firm to conduct a forensic investigation and, while that investigation is still ongoing, we believe it is appropriate to notify our members of the potential breach.

What happened?

On March 13, 2023, Kannact discovered that an unauthorized user had gained access to its network. Upon discovery of this Incident, Kannact promptly engaged a specialized cybersecurity firm to conduct a forensic investigation to determine the nature and scope of the Incident. The investigation is still ongoing, however, out of full transparency, Kannact is providing notice about the potential for acquisition of sensitive information by an unauthorized actor. Kannact has not received any reports of fraudulent misuse of the information. Kannact is working to identify all the specific individuals and the type of data that was impacted in order to provide sufficient notice to individuals.

What Information Was Involved?

The types of information involved varied by individual. The investigation is still ongoing, however, the preliminary investigation revealed that the information potentially exposed during the unauthorized access may have included an individual’s name, date of birth, address, phone number, Social Security Number, and protected health information, including, but not limited to, medical diagnosis, treatment, pharmaceutical records, and Kannact ID.

What We Are Doing

Kannact is committed to ensuring the privacy and security of all personal information in our care. Since the discovery of the Incident, Kannact has taken and will continue to take steps to mitigate the risk of future issues. Specifically, Kannact engaged a specialized cybersecurity firm to conduct a forensic investigation to determine the nature and scope of the Incident. Kannact also disabled access to a third party managed file transfer software, deactivated all related API keys, and is improving our patient data ingestion process. Kannact will be offering complimentary credit monitoring and identity theft protection services to individuals whose social security and driver’s license number was impacted. Notification letters will be sent to those impacted individuals with the information to enroll in the credit monitoring services. Kannact strongly encourages all identified individuals to register for this free service.

What You Can Do

Kannact encourages all members to remain vigilant against incidents of identity theft and fraud, to review account statements, and to monitor credit reports for suspicious or unauthorized activity. Additionally, security experts suggest that individuals contact his/her financial institution and all major credit bureaus to inform them of such a breach and take the recommended steps to protect his/her interests, including the possible placement of a fraud alert on the credit file. For more information, please see the Additional Important Information below.

For More Information. Kannact recognizes that our members may have questions not addressed in this notice. For more information, please call (888) 566-0890 (toll free) between the hours of 8:00 am to 8:00 pm Central Time, Monday through Friday (excluding U.S. national holidays).

You can read about more steps you can take to protect yourself and additional notice information in this notice.