Health-ISAC Warns of Increasing ShinyHunters Healthcare Data Theft Attacks
Health sector organizations have been warned about an increase in successful attacks by the ShinyHunters threat group. In contrast to ransomware actors, ShinyHunters conducts supply chain and identity attacks, targeting cloud SaaS and storage platforms. The group is focused on cloud-scale data exfiltration, with initial access typically achieved by voice-based social engineering (vishing) to reset passwords, MFA, or enroll new devices, according to a recent Health-ISAC cybersecurity alert. Once account access is gained, they log in to the organization’s Okta, Microsoft Entra, or Google SSO dashboard, which lists all applications the account holder has access to, such as Microsoft 365, Salesforce, Dropbox, Google Drive, and other third-party platforms. Data is rapidly exfiltrated, and victims are advised about the data theft. ShinyHunters demands a ransom payment to prevent the stolen data from being leaked on the group’s dark web data leak site. In recent months, ShinyHunters has conducted successful attacks on several healthcare and medtech companies, including the medical device...
OSF Healthcare System Pays $552,250 to Settle OCR HIPAA Investigation
OSF Healthcare System and its Affiliated Covered Entities (OSF Healthcare) have agreed to pay a penalty of $552,250 to resolve alleged violations of the HIPAA Privacy, Security, and Breach Notification Rules. OSF Healthcare is a Peoria, Illinois-based integrated health system that serves patients at 174 locations in Illinois and Michigan, including 16 hospitals. On April 23, 2021, OSF Healthcare discovered that ransomware had been used to encrypt files on its network. The threat group deployed a variant of Nephilim ransomware to encrypt files and demanded payment to prevent a data leak and to obtain the keys to unlock the encrypted files. The forensic investigation determined on August 24, 2021, that the protected health information (PHI) of 53,907 patients was exfiltrated from its network, including names, driver’s license numbers, diagnosis and treatment information, prescription information, medical record numbers, provider names, dates of services, financial account information, and health insurance information. OCR was notified about the attack on October 1, 2021, and...
Free Webinar: HIPAA Compliant Email – What you Actually Need (Without an IT Team)
Small healthcare practices often assume their emails are HIPAA-compliant; however, security gaps are often found to exist that threaten patient privacy and put practices at risk of regulatory penalties. The security gaps in email are easy for small practices to miss, as they are focused on running their practices and often lack in-house IT staff with email security expertise. Addressing these gaps is vital to ensure the privacy of patient information and compliance with the HIPAA Rules; however, implementing secure and HIPAA-compliant email systems can be technically challenging without an IT department, and secure email solutions can make accessing emails burdensome for patients. In this free webinar on August 7, 2026, small healthcare practices will learn how to make their emails HIPAA-compliant without an IT team, while ensuring that patients can read securely transmitted emails without first logging into a secure portal. The 1-hour webinar will cover what HIPAA demands for email for small practices, why free Gmail and Microsoft 365 email are not sufficient for HIPAA compliance,...
How to Become HIPAA Compliant
When considering how to become HIPAA compliant, one of the simplest approaches is to adopt HHS’s “Seven Fundamental Elements of an Effective Compliance Program.” This will help you address compliance challenges identified in a HIPAA risk assessment. It can also be beneficial to take advantage of HIPAA compliance software that is built around The Seven Fundamentals in order to maintain a compliant workplace. 7 Steps for HIPAA Compliance In 2011, HHS published “The Seven Fundamental Elements Of An Effective Compliance Program”. We have slightly amended it to be more relevant to HIPAA compliance in 2026. Here is a summary of the elements, which we outline in more detail in this guide. Develop policies and procedures so that day-to-day activities comply with the HIPAA Privacy Rule. Designate a privacy officer and a security officer. Implement effective training programs. Ensure channels of communication exist to report violations and breaches. Monitor compliance at floor level so poor compliance practices can be nipped in the bud. Enforce sanctions policies fairly and equally. Respond...
Free Webinar: Inside 250 HIPAA Investigations – What You Need to Know
Learn exactly what happens during a HIPAA investigation. Understand where organizations fail so you can avoid government fines and drawn-out investigations. Based on real experience from over 250 actual OCR investigations. When it comes to HIPAA investigations, many organizations lean on the hope that they will never be implicated. But, with the rise of ransomware breaches and patient complaints, your organization is much more likely to end up in the crosshairs of the Office for Civil Rights (OCR) than you might expect. While you can’t always prevent breaches from occurring, you can control your preparedness for everything that follows when it comes to your HIPAA compliance posture. Join Jake Dewberry, Chief Legal Officer, and Ryan Boudreau, Senior Vice President of Operations from Abyde, as they walk through the details of what an investigation actually looks like and where organizations fail based on their experience in over 250 OCR investigations. They will be sharing real (redacted) examples from past investigations, detailing what the OCR asks for, how to respond safely, and...



