Survey Confirms Majority of Healthcare Orgs Plan to Increase Cybersecurity Investment
An annual survey of healthcare leaders by the Healthcare Information and Management Systems Society (HIMSS) has revealed that more than half of healthcare organizations (55%) plan to increase cybersecurity spending in 2025. Twenty-one percent say budgets are largely unchanged year over year, and four percent plan to spend less on cybersecurity than in 2024. This year’s HIMSS Healthcare Cybersecurity Survey was conducted on 273 healthcare cybersecurity professionals, 50% of whom were in executive management, 37% in non-executive management, and 13% in non-management roles. 46% of respondents had primary responsibility for cybersecurity, 30% had some responsibility, and 24% sometimes had responsibility, as needed. The survey was conducted between November 6, 2024, and December 16, 2024, and asked questions about cybersecurity spending and cybersecurity experiences over the previous 12 months. Historically, healthcare organizations have invested 6% or less of their IT budgets in cybersecurity; however, more money is now being spent on cybersecurity improvements, with 30% of...
Rite Aid Settles Data Breach Lawsuit for $6.8 Million
Rite Aid has agreed to settle a class action lawsuit over a June 2024 data breach that involved the personal information of approximately 2.2 million customers. Class members can claim up to $10,000 as reimbursement for documented expenses incurred as a result of the data breach. On June 6, 2024, the RansomHub ransomware group gained access to some of its computer systems, exfiltrated sensitive data, and encrypted files. According to Rite Aid, the breach was identified within 12 hours, but not in time to prevent the theft of customer data. The stolen data related to customers who made purchases between June 6, 2017, and July 30, 2017, and included names, addresses, dates of birth, driver’s license numbers, and other ID documents. The affected individuals were offered complimentary credit monitoring and identity theft protection services for 12 months. Several lawsuits were filed in response to the data breach that asserted similar claims. The lawsuits were consolidated into a single action – Margaret Bianucci v. Rite Aid Corporation – in the U.S. District Court for the Eastern...
Supreme Court Declines Petition to Take on Data Breach Case Against South Carolina FQHC
The Supreme Court has declined to hear a case about whether a Federally Qualified Health Center (FQHC) is immune from liability over data breach that exposed the personally identifiable information of patients. Sandhills Medical Foundation is an FQHC that serves patients in the Chesterfield, Kershaw, Lancaster, and Sumter Counties in South Carolina. Sandhills used a vendor (Netgain Technologies) for electronic storage of its scheduling, billing, and reporting systems. The vendor notified Sandhills on January 8, 2021, about a ransomware attack on November 15, 2020. The ransomware group used compromised credentials to access its systems and steal sensitive data. Ransomware was deployed on December 3, 2020. According to Sandhills, the breach involved the information of 39,602 patients. Health information was not compromised, although claims information may have allowed an attacker to determine diagnoses and conditions. The information stolen in the attack included names, dates of birth, mailing and email addresses, driver’s licenses, and Social Security numbers. One of the affected...
PHI Compromised in Email Breaches at Bassford Remele & Scott County, Iowa
Email account breaches have been reported by the law firm Bassford Remele & Scott County in Iowa. Birch Medical has identified unauthorized access to a folder on its network that contained patient data. Email Data Stolen from Bassford Remele The Minneapolis, MN-based law firm, Bassford Remele P.A., recently disclosed a data security incident that was identified on September 4, 2024. The investigation revealed unauthorized emails were sent from a third-party application purporting to be from an employee’s email account. The email account was secured, and third-party digital forensics experts were engaged to investigate the incident. The investigation confirmed there had been unauthorized access to the email account between July 29, 2024, and September 4, 2024, during which time, the unauthorized third party copied the contents of the email account. Bassford Remele provides legal services to certain healthcare organizations, and some of the information in the account included protected health information provided by healthcare clients in connection with those services. The...
Ransomware Attack Surge Continues in 2025
The upward trend in ransomware attacks in 2024 has continued in 2025 with large numbers of new victims added to ransomware groups’ data leak sites in January and February. A recent report from the cybersecurity firm Cyble shows there were at least 599 new additions to data leak sites in the first 27 days of February, an increase from 518 new additions in January, despite February being a shorter month. The majority of the victims are based in the United States, with the victim count up 149% compared to the first 5 weeks of 2024. Over the first five weeks of 2024, 282 new U.S. victims were added to data leak sites, with the victim count rising to 378 in 2025. There has also been a significant increase in attacks on Canadian companies, rising from 14 attacks in the first 5 weeks of 2024 to 46 attacks in 2025. While attacks in North America continue to increase, there has been relatively little change in the numbers of attacks in other countries. Cycle suggests the increase in attacks in North America is most likely due to the belief among ransomware groups that attacks in the region...



