Cybercrime Losses Increased by 33% in 2024 to $16.6bn
The Federal Bureau of Investigation’s Internet Crime Complaint Center (IC3) has released its 2024 Internet Crime Complaint Report, which shows record-breaking losses to cybercrime in 2024. While the number of complaints fell slightly year-over-year, losses to cybercrime increased by a staggering 33% to $16.6 billion, smashing the previous record set in 2023. The bulk of those losses (83%) were the result of cyber-related fraud, which accounted for 38% of complaints. In total, IC3 received 859,532 cybercrime complaints in 2024, of which 256,256 complaints involved actual losses. The average loss was $19,372. The most common reason for complaints was phishing/spoofing, with 193,407 complaints, followed by extortion (86,415), and personal data breaches (64,882). In terms of losses, investment fraud topped the list with reported losses of $6.57 billion, up from $6.5 billion in 2023, followed by business email compromise losses of $2.77 billion, which fell slightly from the $2.9 billion in reported losses in 2023. At least $1.46 billion was lost to tech support scams in 2024, and $4.45...
What is the Definition of HIPAA?
The definition of HIPAA is that the Health Insurance Portability and Accountability Act 1996 was passed by Congress to reform the health insurance industry and ensure workers could maintain health coverage when they change or lose their jobs. “Healthcare HIPAA” resulted from efforts to mitigate the cost of the reforms and prevent a decline in tax revenues. To best understand the definition of HIPAA, it is helpful to understand the background to HIPAA and what its original objectives were. The background to HIPAA is that, in the early 1990s, around 86% of Americans were covered by private health insurance, public health insurance (i.e., Medicare), or a combination of both. Of those covered by private health insurance, around 60% of Americans were covered by an employer’s health plan. However, because of the way in which many employer health plans worked, when a worker changed jobs there was a “wait period” and a gap in coverage before the new health plan took effect. It was also the case that if a worker developed a health condition while in one job and then changed jobs, they may...
Phishing Attack and Late Breach Notifications Lead to $600K HIPAA Fine for PIH Health
The HHS’ Office for Civil Rights (OCR) has announced its 6th financial penalty of the year to resolve alleged violations of the HIPAA Rules. PIH Health, a California health care network, agreed to settle the alleged HIPAA violations and paid a $600,000 financial penalty. The data breach that triggered the investigation occurred in June 2019, but was not reported to OCR until January 10, 2020, 7 months after the breach occurred. Hackers gained access to 45 employee email accounts between June 11 and June 21, 2019, in a targeted phishing campaign. The email accounts contained the electronic protected health information of 189,763 individuals, including names, addresses, dates of birth, driver’s license numbers, Social Security numbers, diagnoses, lab results, medications, treatment and claims information, and financial information. The breach stands out due to the number of email accounts compromised in the attack and the time taken to issue notifications to the HHS and the affected individuals. OCR’s investigation identified violations of multiple provisions of the HIPAA Rules,...
Blue Shield of California Announces Impermissible Disclosure of PHI to Google Ads: 4.7 Million Affected
On April 9, 2025, the health insurance plan provider Blue Shield of California disclosed a web tracking-related privacy breach involving user data being shared with Google’s advertising product, Google Ads. The breach was recently reported to the HHS’ Office for Civil Rights (OCR) as affecting up to 4.7 million individuals, making it the second-largest healthcare data breach to be reported so far in 2024 behind the 5.5 million-record data breach at Yale New Haven Health System. Blue Shield of California explained that, like many other health plans, Google Analytics was installed to track how visitors used certain Blue Shield websites. Google Analytics is extensively used by website owners to collect information about website visitors, such as how they arrive on a website and the web pages they visit. The information can be used to improve the website and user experience. On February 11, 2025, Blue Shield of California learned that Google Analytics had been configured in a way that resulted in member data being shared with Google Ads for almost 3 years. Between April 2021 and...
March 2025 Healthcare Data Breach Report
Breach reporting data from the HHS’ Office for Civil Rights (OCR) is starting to show a reduction in healthcare data breaches. In 2024, an average of 61 large healthcare data breaches were reported each month (median: 60), and over the past two months, an average of 51 breaches have been reported each month. Excluding January, which includes breach reporting from Thanksgiving weekend, a busy time for cybercriminals, the average is the same. In March, 53 data breaches affecting 500 or more individuals were reported to OCR by HIPAA-regulated entities. That’s the lowest March total since 2022 and a 46% reduction from the 98 data breaches reported in March 2023. There has also been a considerable decrease in the number of individuals affected by healthcare data breaches, which fell for the third straight month to the lowest monthly total since January 2023. In March 2025, 1,754,097 individuals had their protected health information exposed, stolen, or impermissibly disclosed in a healthcare data breach, a 23% reduction from the 2,277,555 individuals affected in February 2025 and a...



