Remotely Exploitable Critical Vulnerability Identified in Santesoft Sante PACS Server
Five vulnerabilities have been identified in the Santesoft Sante PACS Server medical image archiving and communication system, including a critical vulnerability that allows credentials to be intercepted. The vulnerabilities affect all versions of Sante PACS Server prior to 4.2.3 and have been patched in version 4.2.3 and later versions. The three most serious vulnerabilities can be exploited remotely by an attacker in a low complexity attack. Successful exploitation of the vulnerabilities could allow an attacker to create arbitrary files, obtain sensitive data, steal users’ session cookies, and cause a denial-of-service condition. CVE-2025-54156 – A critical vulnerability that can be exploited by a remote attacker to steal credentials. The vulnerability is due to Sante PACS Server sending credential information in cleartext. The vulnerability has been assigned a CVSS v4 score of 9.1 (CVSS v3.1: 7.4). CVE-2025-53948 – A high-severity vulnerability that can be exploited by a remote attacker to crash the main thread by sending a specially crafted HL7 message, triggering a...
Companies Ordered to Pay $145 Million for Alleged Deceptive Health Insurance Marketing
The Federal Trade Commission (FTC) has announced settlements with two healthcare companies to resolve claims that they misled consumers seeking health insurance. In both cases, the companies were alleged to have deceived consumers seeking comprehensive health insurance into purchasing plans that did not provide the claimed level of coverage. The companies will pay a total of $145 million to the FTC to resolve the two complaints. The biggest financial penalty was imposed on Assurance IQ, LLC, a Seattle-based company that sells short-term medical (STM) plans, limited benefit indemnity (LBI) plans, and supplemental healthcare plans, including vision and dental discount plans. According to the FTC complaint, Assurance’s telemarketers overstated the coverage provided by its policies. Most of the plans were sold on behalf of Benefytt Technologies, which was a third-party distributor of healthcare products for various carriers. Assurance received over $100 million in commissions for selling the policies on behalf of Benefytt. The FTC previously filed a complaint against Benefytt alleging...
Crisis Pregnancy Centers’ Websites Edited After Scrutiny of HIPAA Claims
Back in February, The HIPAA Journal reported on the efforts of the non-profit watchdog organizations the Campaign for Accountability and the Electronic Frontier Foundation (EFF) to prevent crisis pregnancy centers (CPCs) from claiming or implying they are bound by the Health Insurance Portability and Accountability Act (HIPAA) on their websites and intake forms, when they are not HIPAA-regulated entities. Most CPCs are not licensed healthcare providers and are therefore not bound by the HIPAA Rules, yet CPCs have been identified by the Campaign for Accountability and EFF that imply that they are bound by the HIPAA Rules. Regardless of personal opinions about abortion procedures and reproductive healthcare, implying that personal data is protected by HIPAA when it is not is a deceptive business practice. Under HIPAA, regulated entities are healthcare providers, health plans, healthcare clearinghouses, and business associates of those entities, and all are required to comply with the HIPAA Rules. One of the requirements of HIPAA is to have a notice of privacy practices, which should...
Heartland Alliance Agrees to Data Breach Settlement
A Chicago anti-poverty organization and associated companies have agreed to a $300,000 settlement to resolve a class action lawsuit filed in response to a 2022 data breach. On or around December 15, 2022, Heartland Alliance disclosed a data security incident and mailed notification letters on or around December 21, 2022. An unauthorized third party had access to its network, where files containing sensitive data were stored. Those files contained names, dates of birth, Social Security numbers, driver’s license numbers, bank account numbers, and medical/health information. While the data breach was announced in December 2022, the hackers gained access to the network on January 26, 2022. Heartland Alliance reported the data breach to the HHS’ Office for Civil Rights as involving the protected health information of 46,694 individuals. A lawsuit was filed against the several Heartland entities – Wittmeyer et al. v. Heartland Alliance for Human Needs & Human Rights, Heartland Alliance Health, Heartland Alliance International, LLC, Heartland Housing, Inc., and Heartland Human...
Washington Children’s Hospital Fires 15 Nurses for Alleged HIPAA Violations
Fifteen nurses at Providence Sacred Heart Medical Center & Children’s Hospital in Spokane, Washington, have been terminated for alleged HIPAA violations. The nurses allegedly accessed the medical records of a 12-year-old patient, Sarah June Niyimbona, who committed suicide at the children’s hospital on April 13, 2024, when there was no direct treatment relationship. Starting in early 2024, the patient had been repeatedly admitted to the emergency department of the hospital after several self-harm incidents and suicide attempts. Overnight on April 13, 2024, the patient left her room alone and walked a quarter of a mile to a parking facility on the hospital campus and jumped from a 4th-floor parking garage. She died in the hospital emergency room two hours later. While the patient previously had two sitters, including one sitter monitoring via video, the camera had allegedly been removed from her room weeks earlier, and the sole sitter had been cancelled days before the patient left her room and exited the facility undetected. The story was covered by InvestigateWest, which...



