Cyberattack on Medical Imaging Provider Affects 1.4 Million Patients
At the start of the month, The HIPAA Journal reported on a cybersecurity incident at Radiology Associates of Richmond, a provider of medical imaging services at seven hospitals in central Virginia and multiple outpatient medical imaging facilities in the state. At the time, the extent to which patient data had been compromised had not been disclosed as the file review and investigation were ongoing. It has now been confirmed that a huge amount of patient data was compromised in the attack. Hackers had access to its network between April 2 and April 6, 2024, and exfiltrated files containing names, dates of birth, email addresses, Social Security numbers, account numbers, routing numbers, medical information, and health insurance information. Complimentary credit monitoring and identity theft protection services have been offered to individuals whose Social Security numbers were involved. The radiology group recently notified the HHS’ Office for Civil Rights that the protected health information of 1,419,091 individuals was compromised in the incident, making this one of the top five...
Texas Enacts Law Governing Security and Storage of Electronic Health Records
The Governor of Texas has added his signature to a bill regulating the storage and security of electronic health records and the use of artificial intelligence in healthcare for diagnostic purposes. The bill also introduces a new definition of “biological sex” and sets rules concerning the amendment of biological sex in electronic health records. S.B. 1188 applies to HIPAA-covered entities and healthcare practitioners. The new law requires the electronic medical records of all Texas patients to be physically maintained in the United States, including if the medical records are stored by a third-party or subcontracted computing facility that provides cloud computing services. In such cases, the data center where the records are stored must be in the United States. The law also applies to electronic health records stored using technology that allows patient information to be electronically retrieved, accessed, or transmitted. Covered entities must implement reasonable and appropriate administrative, physical, and technical safeguards to ensure the confidentiality, integrity, and...
High Severity Vulnerability Identified in Panoramic Dental Imaging Software
A high-severity vulnerability has been identified in Panoramic Dental Imaging Software that could allow a standard user to elevate privileges to NT Authority/SYSTEM. The vulnerability, identified by Damian Semon Jr. of Blue Team Alpha LLC, affects Panoramic Corporation Dental Imaging Software v.9.1.2.7600, and is due to an uncontrolled search path element (CWE-427), which makes the product vulnerable to DLL hijacking. The vulnerability is tracked as CVE-2024-22774 and has been assigned a CVSS v4 base score of 8.5 (CVSS v3.1: 7.8). The vulnerability affects an SDK component owned by Oy Ajat Ltd, which is no longer supported. A patch has not been released by Panoramic to correct the vulnerability, as it does not affect a component owned by Panoramic Corporation. No recommended mitigations have been released. Any users should contact Panoramic Corporation for further information via email at [email protected] The vulnerability has been reported to the U.S. Cybersecurity and Infrastructure Security Agency (CISA) which recommends users take defensive measures, including minimizing...
Data Breaches Up 10% Although Victim Count Falls Sharply
This year is set to become another record-breaking year for data breaches, according to the Identity Theft Resource Center (ITRC). The ITRC H1 2025 Data Breach Report shows an 11% year-over-year increase in reported data breaches, with 1,732 data compromises tracked by ITRC between January 1, 2025, and June 30, 2025. That’s 54.9% of the full year total for 2024. The increase in data breaches has largely been driven by cyberattacks, which account for 77.83% of all confirmed data compromises in H1 – 1,348 incidents. Across those incidents, the personal data of 114,582,621 individuals was compromised – 69.13% of the total number of victims across all data compromise incidents. The second main cause of data breaches was phishing/smishing/BEC attacks, with 251 confirmed incidents, followed by 73 confirmed ransomware attacks. The number of ransomware attacks is likely to be substantially higher, as ransomware is often not mentioned in breach notifications. There were 129 data compromises attributed to system or human error, impacting more than 6 million individuals. In total,...
OSH Act Penalty Reductions Expanded to Support Small Businesses
The Occupational Health and Safety Administration has issued updated guidance on the penalty structure in Section 7 of the Occupational Safety and Health (OSH) Act. The OSH Act was signed into law in 1970 to ensure safe and healthful working conditions for employees in the United States. In addition to setting workplace safety and health standards, it established the Occupational Health and Safety Administration (OSHA). OSHA is authorized to enforce compliance with the OSH Act and can issue penalties for violations. The penalties imposed by OSHA are intended to deter future violations and ensure that employers maintain a safe and healthful working environment. To ease the burden on small businesses and to promote the swift resolution of workplace hazards, OSHA has previously applied a 70% reduction in penalties for very small businesses with 10 or fewer employees. The new policy, detailed in the Penalties and Debt Collection section of OSHA’s Field Operations Manual, expands the penalty reductions for small employers to include businesses that employ up to 25 employees. The aim is...



