Tech

French Health Billing Vendor Almerys Confirms Cyberattack Exposing Social Security Data

Disruption to Third-Party Payment Systems

Almerys plays a critical role in France’s “third-party payment” system, a mechanism that allows patients to receive medical services without paying the full cost upfront. The specific target of the attack was the portal used to issue “prises en charge,” or coverage authorizations, which providers typically require before delivering certain equipment or services. By taking this site offline, Almerys aimed to shut down unauthorized access and limit further data exposure. However, this containment strategy has created significant friction in high-volume approval areas, particularly vision care, dentistry, hearing services, and certain hospital-related authorizations.

With the digital portal unavailable, medical staff are forced to rely on manual workarounds, including additional phone calls, paperwork checks, and alternative approval channels. These stopgaps have led to longer wait times, leaving some patients in a limbo between receiving a quote and securing the necessary authorization. Despite the outage in the front-line approval tool, Almerys stated that other parts of its business remain operational. Administrative processing, database updates, transaction handling, and payment systems are still running, indicating that the financial backend is intact while the front-end interface remains paused for security containment.

Photo by Dan Nelson / Pexels

Scope of Data Exposure

The breach involved administrative identity and coverage information rather than detailed medical records. According to notices relayed by insurers, the compromised data includes a person’s name, date of birth, and their French Social Security number, a national identifier used extensively across the French health system. The exposed records may also contain the name of the individual’s health insurer, a contract number, and the start and end dates of their coverage.

Crucially, the affected platform does not store bank details, medical diagnoses, health reimbursement data, postal addresses, phone numbers, or email addresses. Therefore, these specific categories of information were not impacted by this incident. However, the combination of a national ID number and an insurer name is considered highly valuable to fraudsters. Security experts note that this data allows attackers to craft phishing messages that appear authentic, increasing the likelihood that targets will click on fake portal links or disclose further documents.

Photo by Cedric Fauntleroy / Pexels

Phishing Risks and Industry Response

Although direct contact information was not breached from this specific system, the risk of targeted scams remains elevated. Attackers can pair the leaked identity data with phone numbers or email addresses purchased from other sources to launch convincing campaigns via text, call, or email. Alan, a fast-growing French health insurer known for its digital-first approach, has explicitly warned its members to expect an uptick in fraudulent messages following the May 22 incident.

The incident highlights the vulnerability of centralized digital infrastructure in the health sector. While Almerys moved quickly to identify and shut down the unauthorized access, the secondary effect of the outage has been a tangible slowdown in patient care for non-critical but necessary services. The company is working to regain full control of the portal, but in the interim, providers and patients are navigating a period of increased administrative friction and heightened vigilance against social engineering attacks.

Karen Foster

Karen Foster covers technology news, including artificial intelligence, cybersecurity, software, consumer devices, and developments at major technology companies. She follows product launches, industry announcements, digital policy, and emerging trends while looking beyond promotional claims. Karen focuses on explaining what is new, what is confirmed, and why a technology development may matter to everyday users.

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button