Illinois Accountancy Firm Sued Over 217,000-Record Data Breach
Legacy Professionals, an Illinois-based certified public accountancy firm, has notified almost 217,000 individuals about an April 2024 security incident involving data theft from its systems. Suspicious activity was identified within its computer network in late April, and a forensic investigation was launched to confirm the nature and scope of the activity. The investigation confirmed that there had been unauthorized access to its network, but client systems were unaffected. The investigation uncovered no evidence of data theft. In November 2024, Legacy Professionals learned that certain files had been exfiltrated from its network by an unauthorized actor. Legacy Professionals initiated a comprehensive review of the files and engaged data review specialists to assist with the time-intensive review. That process was completed in February 2025 and confirmed that the stolen data included employee benefit plan information such as names, Social Security numbers, driver’s license/state ID numbers, medical treatment information, and health insurance information. Legacy Professionals said...
Department of Labor Announces Senior OSHA Appointments
The U.S. Department of Labor has announced leadership changes at the Occupational Safety and Health Administration (OSHA), including Deputy Assistant Secretary Amanda Wood Laihow serving as the new acting Assistant Secretary of Labor for Occupational Safety and Health. Douglas L. Parker previously led the agency under President Biden and President Trump’s nomination to head OSHA, the former UPS and Amazon safety executive David Keeling, is currently with the Senate HELP Committee. Shortly after Lori Chavez-DeRemer was sworn in as Labor Secretary, OSHA updated its organizational chart confirming Amanda Wood Laihow is the new Acting Assistant Secretary of Labor for Occupational Safety and Health. Since February, Wood Laihow has served as Deputy Assistant Secretary alongside Scott Ketcham. Amanda Wood Laihow is a labor lawyer who previously served as a commissioner to the Occupational Safety and Health Review Commission from 2020 to 2023. She has also served as director of labor and employment policy for the National Association of Manufacturers, deputy general counsel on the...
High Severity Vulnerabilities Identified in Philips Intellispace Cardiovascular (ISCV)
Two high-severity vulnerabilities have been identified in Philips Intellispace Cardiovascular (ISCV), a popular multi-modality image and information management solution for healthcare providers. The vulnerabilities are present in ISCV version 4.1 and prior versions and ISCV version 5.1 and prior versions. The vulnerabilities are due to improper authentication and the use of weak credentials. Both vulnerabilities have been assigned a CVSS v3.1 severity score of 7.7 and a CVSS v4 severity score of 8.5. An attacker can exploit the vulnerabilities to replay the session of a logged-in user and gain access to patient records. Vulnerability CVE-2025-2230 is due to improper authentication. The Windows login flow contains a flaw where an AuthContext token can be exploited for replay attacks and authentication bypass. Vulnerability CVE-2025-2229 is due to weak credentials, where a token is created using the username, current date/time, and a fixed AES-128 encryption key, which is the same across all installations. The vulnerabilities have been resolved in previous releases of ISCV; however,...
HIPAA Compliance Plan
A HIPAA compliance plan starts life as a framework for using and disclosing Protected Health Information as required or permitted by the HIPAA Privacy Rule, and as a set of safeguards for protecting the confidentiality, integrity, and availability of electronic Protected Health Information as required by the HIPAA Security Rule. In addition to complying with the Privacy and Security Rules, a HIPAA compliance plan must also take into account the Breach Notification Rule, any applicable General Rules (Part 160), and any applicable Transaction Rules (Part 162) – notwithstanding that some elements of HIPAA compliance may have to be integrated with other federal regulations (i.e. 42 CFR Part 2) or preempted by state regulation with greater privacy protections, increased patient rights, or shorter breach notification periods. Responsibility for Creating a HIPAA Compliance Plan The administrative requirements within the HIPAA Security Rule are quite clear about who has responsibility for creating a HIPAA compliance plan. Section §164.530 of the Security Rule states “A covered entity must...
Healthcare Staff Database with 86,000 Records Exposed Online
A database owned by a New Jersey health technology company has been exposed online, allowing sensitive data to be freely accessed by anyone without the need for any authentication. The non-password-protected database was linked to ESHYFT, which operates in 29 U.S. states and offers a mobile app platform that connects healthcare facilities with healthcare workers such as Licensed Practical Nurses (LPNs), Registered Nurses (RNs), and Certified Nursing Assistants (CNAs). The app is available in the Apple App Store and on Google Play, with the latter showing the app has been downloaded more than 50,000 times. The app can be used by nurses to find shifts that fit their schedules and by healthcare facilities to find vetted nursing staff to fill vacancies. The exposed 108.8 GB database was found by cybersecurity researcher Jeremiah Fowler, who shared his findings with Website Planet. Fowler identified 86,341 records in the database, a sample of which included profile/facial images, monthly work schedules, professional certificates, work assignment agreements, CVs, and resumes. A single...



