$20 Million Settlement Agreed to Resolve Fortra GoAnywhere Data Breach Multidistrict Litigation
A $20 million settlement has received preliminary approval from a Federal judge to resolve multidistrict litigation against the software provider Fortra, its clients, and their customers over a 2023 hacking incident involving the Fortra GoAnywhere managed file transfer (MFT) solution. The Clop ransomware group exploited a zero-day vulnerability in the solution to gain access to customer data. Several class action lawsuits were filed against Fortra in response to the data breach, with the settlement covering eight of nine class action lawsuits against Fortra and its healthcare clients. The lawsuits were consolidated in multidistrict litigation in February 2024 in the Southern District of Florida – In re: Fortra File Transfer Software Data Security Breach Litigation – and include claims against Fortra, NationsBenefits LLC, NationsBenefits Holdings LLC, Aetna Inc., Aetna Life Insurance Co., Santa Clara Family Health Plan, Anthem Insurance Companies Inc., Elevance Health Inc., Community Health Systems Inc., CHSPC LLC, Brightline, Imagine360, and Intellihartx LLC. The...
Arizona Arthritis and Rheumatology Associates & Mon Health Report Phishing Incidents
Arizona Arthritis and Rheumatology Associates and Monongalia Health System have had email accounts compromised as a result of phishing attempts on their employees. Phishing typically involves the impersonation of trusted entities and social engineering to trick individuals into clicking a link in an email and disclosing their account credentials. Phishing is a leading cause of healthcare data breaches, including two of the top three healthcare data breaches in Q1, 2025. Arizona Arthritis and Rheumatology Associates Arizona Arthritis and Rheumatology Associates (AARA) was affected by a phishing attack that saw several employee Office 365 accounts accessed by unauthorized individuals on March 3, 2025. The compromised accounts were detected within hours of the unauthorized access and secured by changing the compromised passwords. AARA said employees were notified about the phishing attempts to prevent further account compromises, additional phishing awareness training has also been provided to the workforce to help the staff identify phishing attempts, and new software has been...
HIPAA Compliance for Software Development
HIPAA compliance for software development is an important consideration for vendors and service providers who intend to develop or provide software for the healthcare and health insurance industries that will be used to create, receive, store, or transmit Protected Health Information. However, software HIPAA compliance is rarely the only consideration. When software is developed or provided for use in the healthcare and health insurance industries, there are two factors that determine whether HIPAA compliance for software development is necessary. Will the software be used by a HIPAA covered entity or business associate? If so, will the software be used to create, receive, store, or transmit Protected Health Information (PHI)? If the answer to both of these questions is “yes”, it is then necessary to determine the degree of software HIPAA compliance. For example, if the software has transient access to PHI, it will only be necessary for it to have capabilities that protect the confidentiality, integrity, and availability of PHI in transit, and that support end user compliance with...
City of Oakland Agrees Settlement to Resolve Class Action Data Breach Lawsuit
The City of Oakland in California has agreed to settle litigation stemming from a ransomware attack and data breach that affected more than 13,000 current and former employees. The attack was detected in February 2023, and notification letters were sent to the affected employees in early March 2023. The Play ransomware group claimed responsibility for the attack, which forced the city to shut down its IT systems, resulting in a state of emergency being declared in the city. The ransomware group released the stolen data on its data leak site when the city refused to pay the ransom. Among the leaked data was the personal information of individuals employed by the city between July 2010 and January 2022. The ransomware group gained access to the network after employees responded to phishing emails. Several lawsuits were filed in response to the breach, alleging the city was negligent by failing to implement appropriate safeguards to protect its network and data. The city maintains there was no wrongdoing; however, it agreed to settle the litigation to prevent further legal costs and...
OSHA to Hold Public Hearing on Proposed Heat Injury and Illness Standard
The U.S. Department of Labor’s Occupational Safety and Health Administration (OSHA) is hosting a virtual public hearing on June 16, 2025, on its Notice of Proposed Rulemaking (NPRM) on Health Injury and Illness Prevention in Outdoor and Indoor Work Settings. The heat injury and illness NPRM was published in the Federal Register on August 30, 2024, and requires employers in all general industry, construction, maritime, and agriculture sectors to create a plan to evaluate and control heat hazards in the workplace and ensure that workers are adequately protected from hazardous heat levels in indoor and outdoor work settings. In the United States, heat is the leading cause of death out of all weather-related phenomena, yet prior to the heat injury and illness NPRM, there was no federal OSHA standard regulating heat stress hazards in the workplace, only guidance from governmental and non-governmental organizations on measures to protect workers. Exposure to excessive heat poses a significant risk of illness and injury. In many industries, workers are required to work through shifts with...



