68% of Healthcare Organizations Have Compromised Email Accounts
Evolve IP has published the results of a new study that has revealed the extent to which healthcare email credentials are being compromised and sold on the dark web. The FBI has also recently warned about Business Email Compromise (BEC). Email credentials are highly valuable to cybercriminals. A compromised email account can be plundered to obtain highly sensitive data and an email account can be used to gain access to healthcare networks. 63% of data breaches in the United States occur as a result of compromised email credentials and healthcare email credentials are being sold freely on the dark web. Evolve used its Dark Web ID analysis technology for the study and reviewed 1,000 HIPAA-covered entities and business associates. Evolve discovered 68% of those organizations have employees with visibly compromised email accounts. 76% of those compromised accounts included actionable password information and that information was freely available on the dark web. Depending on the industry segment, between 55.6% and 80.4% of organizations had compromised email accounts. Medical billing...
Redington-Fairview General Hospital Targeted with New Telephone Phishing Scam
Patients who have previously received medical services at Redington-Fairview General Hospital in Skowhegan, Maine have been targeted with a new telephone phishing scam. The criminals behind the phishing scam are attempting to get patients to reveal sensitive financial information and credit card numbers over the telephone by impersonating the hospital. Two patients have complained to hospital officials about receiving automated calls offering help paying their hospital bills. To date, no one is believed to have fallen for the scam although it is possible that other patients could similarly be targeted. The calls appear to be coming from a local telephone number owned by the hospital, although that number is not an active extension. A statement from the hospital confirmed that the number has not been configured on the hospital’s communication system. The number appears to have been spoofed. It is unclear how the scammers obtained patients’ telephone numbers and spoofed a hospital telephone number, although the hospital does not believe this is an inside job. The hospital has...
Email Error Impacts 6,500 Saliba’s Extended Care Pharmacy Patients
Saliba’s Extended Care Pharmacy in Phoenix, Arizona is alerting more than 6,500 patients to an accidental disclosure of some of their protected health information (PHI). Copies of invoices for December 2016 were sent via Saliba’s Pharmacy’s encrypted email platform to the wrong patients in January. While there is no chance that the emails could have been intercepted by unauthorized individuals, the emails were opened by three patients or their representatives. The incident occurred on January 12, 2017, and Saliba’s Pharmacy discovered the error four days later on January 16. Since HIPAA Rules and patient privacy were accidentally violated, breach notification letters were sent to patients on March 3 to alert them to the incident. Patients have been advised to exercise caution and check their explanation of benefits statements and Saliba’s Pharmacy statements for signs of misuse. However, no reports of any misuse of the information have been received by Saliba’s Pharmacy and the risk of PHI misuse as a result of this impermissible disclosure is believed to be very low. Patients...
Security Analytics Solutions Can Improve Security Posture, But There Are Challenges
A recent Ponemon Institute study has delved into the use and effectiveness of security analytics solutions. The study shows that while security analytics solutions can help organizations improve their security posture, there are many challenges with both deployment and day to day use. The purpose of the study was to find out how – and how much – these solutions are helping organizations and where they are failing. The study, which was sponsored by analytics firm SAS, was conducted on 621 IT and IT security professionals in the United States that are involved with security analytics in their respective organizations. 87% of respondents said they personally used security analytics solutions in their organization, while 80% of respondents said those solutions were fully deployed. Most commonly, security analytics solutions are deployed after a cyberattack has been suffered. 68% of organizations said an attack was the main driver for implementing an analytics solution. 53% said it was fear of a cyberattack or a successful intrusion that spurred them to start using an analytics...
Updated HIPAA Compliance Audit Toolkit Issued by AHIMA
Phase 2 of the Department of Health and Human Services’ Office for Civil Rights HIPAA compliance audits are now well underway. Late last year, covered entities were selected for desk audits and the first round of audits have now been completed. Now OCR has moved on to auditing business associates of covered entities. At HIMSS17, OCR’s Deven McGraw explained that the full compliance audits, which were initially penciled in for Q1, 2017, are to be delayed. This gives covered entities more time to prepare. The phase 2 HIPAA compliance desk audits were more detailed than the first phase of audits conducted in 2011/2012. The desk audits covered a broad range of requirements of the HIPAA Privacy, Security, and Breach Notification Rules, although they only consisted of a documentation check to demonstrate compliance. The onsite audits will be much more thorough and will look much deeper into organizations’ compliance programs. Not only will covered entities be required to show auditors documentation demonstrating compliance with HIPAA Rules, OCR will be looking for evidence of HIPAA in...



