September VA Information Security Report Shows Increase in Privacy Incidents
Each month the Department of Veteran Affairs issues an Information Security Report to congress, in which it details the privacy and security incidents that have affected U.S veterans during the month. The past two months have seen privacy incidents fall, with the August figures the lowest since January. However, the report for September has seen the trend reversed, with a substantial increase in both incidents and the number of individuals affected. In total, 455 separate privacy/security incidents were reported during the month. The VA reported 1,135 veterans were affected by security breaches in the month of September, which resulted in 739 breach notification letters being issued and 396 individuals placed at a high enough level of risk of identity theft and fraud to warrant the provision of credit protection services. In August, only 431 individuals were affected by privacy and security incidents. In fact, September was the second worst month so far this year, with only June seeing more veterans affected (2076). This is only the fourth month that has seen the number of affected...
Aspire Home Care and Hospice Cyberattack Announced
Aspire Home Care and Hospice Cyberattack Exposes 4,278 Patient Records. One of Oklahoma’s largest providers of home health services has announced it has become the victim of a cyberattack, after being targeted by criminals looking to take advantage of the terminally ill. The Aspire Home Care and Hospice cyberattack has resulted in the perpetrators obtaining highly sensitive Protected Health Information of 4,278 patients; information that used to steal identities and rack up debts in the victims’ names. Aspire Home Care and Hospice, the new name for Indian Territory Home Health and Hospice, provides a range of home health and hospice services to state residents. The organization’s nurses, therapists, and social workers are committed to helping patients live with dignity and independence in their own homes. Hackers First Gained Access to Email Accounts in July 2015 The perpetrator of the attack first gained access to email accounts in late July, and potentially obtained patient names, dates of birth, Social Security numbers and insurance information, placing the victims at a...
Unencrypted Device Theft Continues to Plague HIPAA CEs
Device theft continues to expose the PHI of healthcare patients, and the past three months have seen a high volume of security incidents reported to the Office for Civil Rights which have involved the loss and theft of portable devices used to store the confidential Protected Health Information (PHI) of patients. The latest case involves Johns Hopkins Medicine, where the theft of an unencrypted laptop computer has exposed the PHI of 571 patients and 267 research subjects. Johns Hopkins Hospital Data Breach A physician from Johns Hopkins Medicine is reported to have had a suitcase stolen at an airport on August 10, 2015. In that suitcase was the physician’s laptop computer, which contained a limited amount of data relating to patients and research subjects. The laptop was unencrypted, therefore the theft potentially exposed the PHI of a number of individuals, although it is probable that the theft was an opportunistic crime, rather than the physician being targeted by a thief seeking medical data and Social Security numbers. In this case, the laptop did not contain highly...
Baptist Health Data Breach Announced: 6500 Records Exposed
On October 1, 2015, a Baptist Health data breach was added to the Department of Health and Human Services’ Office for Civil Rights breach portal. The breach report indicated the Arkansas-based healthcare provider had suffered a security breach which resulted in the Protected Health Information of 6,500 patients being improperly disclosed to a third party. Breach notification letters were sent to patients on October 1, alerting them to the privacy breach. This was within the time frame required by the HIPAA Breach Notification Rule, although it has taken some time for further information about the data breach to emerge. According to a HIPAA breach notification posted on the Baptist Health website, the security incident has been tied to a former Baptist Health provider, who allegedly exported data while employed at Baptist Health and sent that information to Bray Family Medicine, where the individual is now employed. The security breach first came to light on August 6, 2015 when a Baptist Health patient complained about a letter that had been received from Bray Family Medicine, which...
New Adobe Flash “Critical” Zero Day Security Flaw Patched
A critical Adobe Flash security flaw discovered by Google’s Project Zero and Trend Micro’s Peter Pi, has now been patched by Adobe; days ahead of schedule. The new patch also fixes two other security vulnerabilities discovered in Adobe Flash earlier this month. The patch was originally scheduled to be released this week; however, Adobe released the emergency patch on Friday last week, just three days after it issued another patch to address 13 other critical security vulnerabilities. An announcement made by Adobe earlier this week explained the seriousness of the 13 vulnerabilities, indicating “could potentially allow an attacker to take control of the affected system.” The same is true of the latest vulnerability, although in the latest case, it is not a case of “could” but “has already been.” The exploit has not been reported to have been used to target healthcare providers, but Pawn Storm has used the exploit to target government ministries according to TrendMicro. The hackers devised spear phishing campaigns which directed their targets to web pages that hosted the...



