St. Francis Health System Announces Extortion Attempt
St Francis Health System has announced that a hacker has gained access to a database used to store information of patients of the Warren Clinic; a division of St. Francis that provides primary care and specialty medical services to patients throughout Eastern Oklahoma. On September 7, 2016, a hacker made contact with St. Francis Health System demanding payment in exchange for the return of data that were stolen from one of its servers. Upon receiving the ransom demand St. Francis contacted law enforcement and took steps to block access to the server. A third party security firm was contracted to conduct a thorough investigation of the security breach which revealed a database containing health data of almost 3,000 patients had been compromised. According to the breach notice issued by St. Francis Health System only a limited amount of data was stolen by the attacker. The data were taken from a database with a clinical title; however, the database contained no highly sensitive data such as insurance information, Social Security numbers, or financial information. The breach and data...
Baxter Regional Home Health Alerts Patients to Potential PHI Exposure
Baxter Regional Home Health is alerting patients to a potential breach of their protected health information following a break-in at its facility in Cotter, Arkansas. The break-in occurred during the night and was discovered on August 5, 2016. The thieves did not steal any equipment containing electronic patient health information, but hard copy files were present in the facility. While Baxter Regional Home Health does not believe that any files were taken by the thieves, it is possible that PHI was viewed. The files contained a range of PHI including the names of patients who had previously received treatment from the facility. Baxter Regional Home Health employees were also potentially impacted. The data in the files included patients’ names, phone numbers, addresses, Social Security numbers, dates of birth, government ID numbers, diagnostic information, and insurance details. Employees information included names, phone numbers, addresses, dates of birth, information about past employers, and licensure information. The breach notice posted to the organization’s website does not...
OCR Warns of FTP Vulnerabilities in NAS Devices
The Department of Health and Human Services Office for Civil Rights (OCR) has issued a warning to HIPAA covered entities and their business associates of an increase in attacks on network attached storage (NAS) devices. The devices are being attacked using a form of malware called Mal/Miner-C, otherwise known as PhotMiner. The attack exploits File Transfer Protocol (FTP) vulnerabilities in NAS devices. The malware was first identified in June this year and it has been spreading quickly. Following the discovery of the malware, researchers at Sophos identified 1,702,476 instances of the threat, although it would appear that many devices had been infected multiple times. While the threat is not specific to any particular NAS device, Sophos determined that the Seagate Central device was at risk due to the way the device uses public folders which allows attackers to easily install the malware. Up to 70% of the devices had already been infected with the malware – 5,000 of the 7,000 devices currently in use. The malware provides attackers with access to NAS devices, although once access...
Peachtree Orthopedics Discovers Patient Database Was Hacked
Atlanta, GA-based Peachtree Orthopedics, a provider of orthopedic services in Cherokee, Cobb, Forsyth, Fulton and Gwinnett counties and metro Atlanta, has notified 531,000 patients that their protected health information has been compromised. On September 22, 2016, the orthopedic clinic discovered its computer systems had been accessed by an unauthorized individual. That individual managed to gain access to a patient database. Peachtree Orthopedics has confirmed the hacked system contained names, addresses, dates of birth, and email addresses. A number of patients also had their Social Security numbers, prescription records, and treatment codes exposed. The hacked database contained the records of patients that had visited the orthopedic clinic prior to July 2014, although some patients who visited after that date have also potentially been affected. Peachtree Orthopedics said rapid action was taken to contain the breach to prevent further access to patient health data, although the substitute breach notice posted on the company’s website suggests patient data were actually stolen...
Majority of Healthcare Vendors Not Ready to Comply with the HITRUST Data Security Standard
The Department of Health and Human Services’ Office for Civil Rights has stepped up HIPAA enforcement activities in recent years and oversight of covered entities is improving. One area of HIPAA-compliance that has come under increased scrutiny is the effort made by healthcare business associates to ensure protected health information is protected in accordance with HIPAA Rules. Approximately 30% of healthcare data breaches reported to OCR involved a business associate according to a recent analysis conducted by Protenus. Given the number of breaches involving vendors, it is unsurprising that OCR is looking more closely at business associates. The increased scrutiny has prompted many healthcare organizations to conduct a review of the measures employed by their vendors to ensure protected health information is appropriately secured and sufficient controls have been put in place to ensure ePHI remains private. Business associates now need to demonstrate they have implemented appropriate controls and are effectively managing cybersecurity risk. Business associates can demonstrate...



