Survey Raises Concerns About Cybersecurity Performance Goals (CPG) Awareness
One of the objectives of the HIPAA Journal 2024/25 Annual Survey was to obtain insights into HIPAA compliance best practices. This was so that organizations experiencing compliance challenges could use the information to resolve the challenges and better support compliance activities. However, the responses to one particular question demonstrate a lack of awareness about HHS’ Cybersecurity Performance Goals (CPGs). In December 2023, the Department of Health and Human Services (HHS) published its strategy for Healthcare Sector Cybersecurity. The following month, the agency published voluntary healthcare-specific Cybersecurity Performance Goals (CPGs) to help organizations in the Healthcare and Public Health (HPH) sector address common vulnerabilities (Essential Goals) and mature their cybersecurity capabilities (Enhanced Goals). At the time HHS published its strategy, the agency noted “voluntary goals alone will not drive the cyber-related behavioral change needed across the healthcare sector” and that the HHS’ Office for Civil Rights would work on an update to the HIPAA Security...
BakerHostetler: Ransomware in Decline with Fewer Attacks and Lower Payments
Healthcare continues to be the sector most targeted by ransomware groups, according to the BakerHostetler 2025 Data Security Incident Response Report. Out of the ransomware incidents the law firm was involved with last year, 36% were on healthcare organizations, and those attacks typically disrupted patient care and resulted in revenue loss. There are signs, however, that ransomware is in decline, with fewer attacks and lower payments last year. BakerHostetler has identified an increase in fraudulent wire transfers, suggesting threat actors are responding to the falling profitability of ransomware attacks by making money in other ways. Fraudulent transfers increased by 302% year over year, with an average transfer of $1,256,797 and a median transfer of $130,000. While that may have been true for 2024, reports published earlier this month by cybersecurity firms suggest ransomware groups are conducting more attacks due to the increased reluctance of victims to pay ransoms. Several firms reported that Q1 2025 was a record-breaking quarter for ransomware attacks. In 2024, based on the...
Retina Group of Washington Agrees to $3.6 Million Settlement to Resolve Data Breach Lawsuit
A settlement has been agreed to resolve a class action lawsuit against Retina Group of Washington over a March 2023 data breach that involved unauthorized access to the protected health information of 455,935 individuals. Under the terms of the settlement, a $3.6 million fund will be created to cover claims, attorneys’ fees, and legal costs and expenses. On December 22, 2023, Retina Group of Washington, a healthcare provider with eye care clinics in Maryland and Virginia, issued notifications about a ransomware attack on March 26, 2023. The hackers encrypted files and stole data such as names, addresses, telephone numbers, email addresses, dates of birth, demographic information, Social Security numbers, driver’s license numbers, medical record numbers, health information, payment information, and health insurance information. Seven lawsuits were filed in response to the data breach, which were consolidated into a single lawsuit – In re: Retina Group of Washington Data Security Incident Litigation – in the United States District Court for the District of Maryland. The...
Medical Express Ambulance Service Data Breach Affects 118K Individuals
Medical Express Ambulance Service has announced a March 2024 data breach that has affected more than 118,000 individuals. Data breaches have also been announced by Vitenas Cosmetic Surgery, Newport Harbor Pathology Medical Group, Rhea Medical Center, and Alabama Ophthalmology Associates. Medical Express Ambulance Service Medical Express Ambulance Service in Skokie, Illinois, has recently issued notification letters to individuals affected by a cybersecurity incident that was detected more than a year ago. While not specifically mentioned, the language used indicates this was a ransomware attack. The security breach was identified on March 18, 2024, when network disruption was experienced that affected the functionality of certain systems. Third party cybersecurity experts were engaged to investigate and confirmed that the threat actor had access to systems where patient data was stored and could therefore have acquired patient information. Legal counsel for Medical Express confirmed that the data mining process was completed on January 30, 2025, and a mailing vendor was engaged on...
Ransomware Attack Announced by True Dental Care for Kids and Adults
Data breaches have recently been announced by True Dental Care for Kids and Adults in Pennsylvania, North Hudson Community Action Corporation in New Jersey, and California Correctional Health Care Services. True Dental Care for Kids and Adults, Pennsylvania True Dental Care for Kids and Adults LLC in Pennsylvania has started notifying 17,640 individuals about a recent ransomware attack. A hacker gained access to its network on February 3, 2025, and downloaded ransomware, which was used to encrypt files on its network. The forensic investigation of the incident identified unauthorized access to patient data prior to file encryption. A ransom demand was issued; however, it was not paid, and files were successfully restored from backups. True Dental said it is unaware of any misuse of patient data at the time of issuing the notification. The types of information involved vary from individual to individual and include names, dates of birth, addresses, phone numbers, and patient dental/medical records. True Dental said additional safeguards are being implemented to prevent similar...



