PHI of 6,000 Patients Unlawfully Accessed
6,000 patients of Susanville, CA-based physician Hal Meadows M.D., have been notified that some of their protected health information was accessed by an unauthorized individual who unlawfully gained access to a computer used by Dr. Meadows. The information on the computer included the names, telephone numbers and addresses of patients, along with their dates of birth, insurance numbers, treatment codes, and billing information. The breach was discovered on July 27, 2016 and patients were notified by mail in September. The matter was reported to the FBI which retained the computer for analysis. Dr. Meadows reports he now “has heightened procedures, safeguards, and staff training to prevent a recurrence of this situation.” KidsPeace Reports Loss of Files Containing PHI KidsPeace, a private charity offering support and assistance to children with behavioral and mental health issues, has reported a potential breach of confidential information. A box of paperwork containing the protected health information of 1,456 individuals was discovered to be missing from its Schnecksville, PA head...
Healthcare Vendor Pays Ransom After Backup System Failure
A key vendor of California’s Marin Healthcare District has discovered that having a backup of critical data does not necessarily mean ransomware payments can be avoided. After files were locked by crypto-ransomware, data restoration failed, leaving no alternative but to pay the attackers for a decryption key. Marin Medical Practices Concepts, Inc., (MMPC) provides a range of business and health care system services for Marin Healthcare District. On July 26, 2016 MMPC discovered that ransomware had been installed on its system preventing access to critical files. Files encrypted by the ransomware included clinical data, physician’s notes, documentation of physical examinations, vital signs, and clinical histories of patients. The encrypted data had been collected from nine healthcare centers in the Marin Healthcare District between July 11 and July 26, 2016 and corresponded to approximately 5,000 patients. While other data could be recovered, the restoration of those data failed. The only option for recovering the data was to pay the ransom demand and obtain a decryption key from...
HHS Awards Grants to Improve Cyber Information Sharing Ecosystem
The Department of Health and Human Services (HHS) has announced that cooperative agreements totaling $350,000 have been awarded to The National Health Information Sharing and Analysis Center (NH-ISAC) in Florida. NH-ISAC will serve as an information sharing and analysis organization (ISAO) for the health care and public health sector. The funding has been provided as part of the HHS effort to improve the sharing of cyber threat information and is intended to better protect the healthcare industry against cyberattacks. NH-ISAC was awarded cooperative agreements by the Office of the National Coordinator for Health Information Technology (ONC) and the HHS’ Office of the Assistant Secretary for Preparedness and Response (ASPR). Under the cooperative agreement from the ONC, NH-ISAC is required to share threat information bi-directionally with the Health and Public Health sector and the HHS. NH-ISAC has been tasked with providing cybersecurity information and education on the latest cyber threats to all healthcare industry stakeholders. Threat information will be sent by the HHS to the...
Johnson & Johnson Alerts Patients to Insulin Pump Vulnerability
Johnson & Johnson has issued a warning to patients about security vulnerabilities present in one of its insulin pumps. The vulnerabilities affect the company’s Animas OneTouch Ping device which is used to deliver doses of Insulin to diabetic patients. Two of the vulnerabilities could be exploited by a malicious actor to deliver dangerously high doses of Insulin. Such a move could cause hypoglycemia with potentially life-threatening consequences for the patient. The vulnerabilities were discovered by medical device researcher Jay Radcliffe from security firm Rapid7. Animas Corporation, which is owned by J&J, was informed of the vulnerabilities and has been working with Radcliffe to develop mitigations to prevent the devices being hijacked by malicious actors. The Animas OneTouch Ping device includes a wireless remote control that patients can use to administer insulin without having to touch the device itself. The insulin pump and remote control are paired to ensure that only a pump’s accompanying remote control can be used to trigger a dose of insulin. Radcliffe discovered...
Surgeon General Warns Employees of Personal Information Breach
Another federal agency has experienced a breach of personal information. This time, the data of current, former, and retired members of the United States Public Health Service Commissioned Corps has been compromised. The Commissioned Corps is tasked with providing medical services to underserved populations as well as promoting, protecting, and advancing the health and safety of the nation, including disease control, and ensuring drugs and medical devices are safe and effective. The Commissioned Corps., includes around 6,600 medical professionals including physicians, surgeons, therapists, pharmacists, dentists, and nurses. At this stage it is unclear exactly how many of those individuals – and former and returned members – have been affected by the breach. The security incident is currently under investigation, although employees have been notified by email of the breach by Surgeon General Vice Adm. Vivek H. Murthy. “Based on our investigation, affected individuals are those served by this website-based system: current, retired, and former Commissioned Corps officers...



