OCR Warns of FTP Vulnerabilities in NAS Devices
The Department of Health and Human Services Office for Civil Rights (OCR) has issued a warning to HIPAA covered entities and their business associates of an increase in attacks on network attached storage (NAS) devices. The devices are being attacked using a form of malware called Mal/Miner-C, otherwise known as PhotMiner. The attack exploits File Transfer Protocol (FTP) vulnerabilities in NAS devices. The malware was first identified in June this year and it has been spreading quickly. Following the discovery of the malware, researchers at Sophos identified 1,702,476 instances of the threat, although it would appear that many devices had been infected multiple times. While the threat is not specific to any particular NAS device, Sophos determined that the Seagate Central device was at risk due to the way the device uses public folders which allows attackers to easily install the malware. Up to 70% of the devices had already been infected with the malware – 5,000 of the 7,000 devices currently in use. The malware provides attackers with access to NAS devices, although once access...
Peachtree Orthopedics Discovers Patient Database Was Hacked
Atlanta, GA-based Peachtree Orthopedics, a provider of orthopedic services in Cherokee, Cobb, Forsyth, Fulton and Gwinnett counties and metro Atlanta, has notified 531,000 patients that their protected health information has been compromised. On September 22, 2016, the orthopedic clinic discovered its computer systems had been accessed by an unauthorized individual. That individual managed to gain access to a patient database. Peachtree Orthopedics has confirmed the hacked system contained names, addresses, dates of birth, and email addresses. A number of patients also had their Social Security numbers, prescription records, and treatment codes exposed. The hacked database contained the records of patients that had visited the orthopedic clinic prior to July 2014, although some patients who visited after that date have also potentially been affected. Peachtree Orthopedics said rapid action was taken to contain the breach to prevent further access to patient health data, although the substitute breach notice posted on the company’s website suggests patient data were actually stolen...
Majority of Healthcare Vendors Not Ready to Comply with the HITRUST Data Security Standard
The Department of Health and Human Services’ Office for Civil Rights has stepped up HIPAA enforcement activities in recent years and oversight of covered entities is improving. One area of HIPAA-compliance that has come under increased scrutiny is the effort made by healthcare business associates to ensure protected health information is protected in accordance with HIPAA Rules. Approximately 30% of healthcare data breaches reported to OCR involved a business associate according to a recent analysis conducted by Protenus. Given the number of breaches involving vendors, it is unsurprising that OCR is looking more closely at business associates. The increased scrutiny has prompted many healthcare organizations to conduct a review of the measures employed by their vendors to ensure protected health information is appropriately secured and sufficient controls have been put in place to ensure ePHI remains private. Business associates now need to demonstrate they have implemented appropriate controls and are effectively managing cybersecurity risk. Business associates can demonstrate...
Majority of Companies Lack Confidence in Data Breach Response Plans
Even though an increasing number of organizations now have data breach response plans in place, there is a general lack of confidence that a full recovery will be possible if a data breach is experienced. According to a survey conducted by the Ponemon Institute on behalf of Experian, 86% of organizations now have a data breach response plan in place. When the survey was last conducted in 2013, only 61% of companies had such a plan. While a plan has been developed, 38% of companies have not set a timescale for reviewing and updating their breach response plan. 29% of respondents said they have never updated their plan since it was put in place. Out of the respondents that said there was a data breach response plan in place, only 42% believed the plan was effective or very effective. Only 27% of respondents said they were confident that their organization could minimize the financial impact of a data breach. International data breaches were also a cause for concern. 31% of respondents were not confident they would be able to deal with such an incident. For many companies the breach...
Boxes of Abandoned Veterans Services’ Files Discovered
The Virginia Department of Veterans Services (DVS) has launched an investigation following the discovery of 20-30 boxes of files in an abandoned storage unit. The files contain a range of documents including unfiled claims and veterans’ medical records. The storage unit had previously been leased by a former DVS employee who was employed by the agency from January 2012 until August 25, 2015 when she was fired. The employee worked at the veterans’ benefits office at the McGuire Veterans Affairs Medical Center office in Richmond. She had rented the storage unit while employed by DVS; however rental payments for the unit ceased. The unit was then repossessed and the contents were sold at auction. The new owner of the contents of the unit alerted the Dinwiddle County Sherriff’s Office after checking the contents of the boxes and DVS was notified on September 29. DVS officials visited the storage facility and have now removed and secured the files. According to the agency’s director of benefits, Thomas Herthel, the boxes contain “everything from claims to medical records to...



