FBI Issues Privacy Industry Notification for Medical/Dental Facilities

Apr 8, 2024
On March 22, 2017, the Federal Bureau of Investigation's Cyber Division issued a Privacy Industry Notification directed at medical and dental facilities regarding cyber criminals targeting FTP servers to compromise protected health information. 

Read the Full Notification

The FBI is aware of criminal actors who are actively targeting File Transfer Protocol (FTP) servers operating in “anonymous” mode and associated with medical and dental facilities to access protected health information (PHI) and personally identifiable information (PII) in order to intimidate, harass, and blackmail business owners.

The FBI recommends medical and dental healthcare entities request their respective IT services personnel to check networks for FTP servers running in anonymous mode. If businesses have a legitimate use for operating a FTP server in anonymous mode, administrators should ensure sensitive PHI or PII is not stored on the server. 

The FBI encourages recipients of this document to report information concerning suspicious or criminal activity to their local FBI field office or the FBI’s 24/7 Cyber Watch (CyWatch).

The FBI field office for the entire state of Kansas is located in Kansas City:

1300 Summit Street
Kansas City, MO 64105
kansascity.fbi.gov
816-512-8200