Is iCloud HIPAA Compliant?
iCloud is not HIPAA compliant and cannot be used to store, sync, or share media containing Protected Health Information (PHI) as – in its Terms of Service – Apple prohibits any use of iCloud services that would make it a business associate of a covered entity. However, covered entities can still use iCloud for other purposes than storing, syncing, or sharing media containing PHI. Cloud storage services are a convenient way of sharing and storing data. Since files uploaded to the cloud can be accessed from multiple devices in any location with an Internet connection, information is always at hand when it is needed. There are many cloud storage services to choose from, many of which are suitable for use by healthcare providers for storing and sharing ePHI. They include robust access and authentication controls and data uploaded to and stored in the cloud is encrypted. Logs are also maintained so it is possible to tell who accessed data, when access occurred, and what users did with the data once access was granted. iCloud is a cloud storage service that owners of Apple devices...
Republicans Form Working Group to Develop Federal Data Privacy Law
House Republicans have formed a working group to draft privacy legislation that will set federal privacy standards to replace the current patchwork of state laws. All previous efforts to introduce comprehensive federal privacy legislation have failed, and the absence of a federal privacy law has led to around 20 states introducing their own comprehensive data privacy laws. In 2022, the American Data Privacy and Protection Act (ADPPA) was billed as the best opportunity so far to set federal data privacy standards. While the ADPPA had strong bipartisan support, several elements of the bill proved problematic, including the preemption of state laws. The failure of ADPPA to get sufficient support led to the introduction of the American Privacy Rights Act of 2024, which eliminated some of the more problematic requirements of its predecessor. While both of these bills would have seen privacy protections greatly improved in many states, states such as California would have seen their privacy protections watered down. Neither bill made it to a House vote. Last month, more than three dozen...
Hackers Breach Systems of HIPAA-Regulated Entities in Missouri, Nevada, Texas & Wisconsin
Kansas City Hospice & Palliative Care in Missouri, Apex Custom Software in Texas, ARC Community Services in Wisconsin, and REMSA Health in Nevada have experienced hacking incidents that potentially involved unauthorized access to patient data. Kansas City Hospice Falls Victim to Black Suit Ransomware Attack Kansas City Hospice & Palliative Care in Missouri is notifying 3,621 individuals about a 2024 ransomware attack. Kansas City Hospice confirmed that third-party digital forensics experts were engaged to investigate the incident and determine the extent and scope of the unauthorized activity. While the attack disrupted certain IT systems, services continued to be provided to patients throughout the attack and recovery. The recovery process has now been completed, and steps are being taken to improve security. It is unclear exactly when the attack occurred, when it was detected, or the exact types of data compromised in the incident. On October 19, 2024, the Black Suit ransomware group added Kansas City Hospice to its data leak site, claiming 600+GB of data was stolen in...
Judge Approves $7 Million Brightline Data Breach Settlement
A $7 million settlement has been agreed to resolve a lawsuit filed against the virtual mental health provider Brightline over a hacking incident by the Clop threat group in 2023 that resulted in the theft of the protected health information of up to 1 million individuals. Brightline was one of 130 companies to have data stolen by the Clop threat group in January 2023, after the mass exploitation of a critical remote code execution vulnerability in Fortra’s GoAnywhere MFT file transfer solution. The vulnerability was exploited between January 18, 2023, and January 30, 2023. The Clop actors created unauthorized user accounts after exploiting the vulnerability and leveraged those accounts to download files from victims’ hosted MFTaaS environments. Brightline said the information of 964,300 individuals was potentially stolen in the attack including names, addresses, dates of birth, member identification numbers, health plan coverage start and end dates, employer names, and Social Security numbers. Notifications were issued in May 2023. Four lawsuits were filed against Brightline...
Insights into the Current Healthcare Threat Landscape
Two recent reports provide insights into the current threat landscape and the evolving tactics, techniques, and procedures of the growing number of ransomware groups and other threat actors targeting healthcare and other critical infrastructure entities in the United States. According to the Information Technology – Information Sharing and Analysis Center (IT-ISAC), 57% of ransomware attacks tracked by IT-ISAC in 2024 were conducted on entities in the United States, with the UK the next most targeted country, accounting for just 4.6% of attacks. The IT-ISAC report – Exploring the Depths: Analysis of the 2024 Ransomware Landscape and Insights for 2025 – is based on threat intelligence gathered from approximately 3,500 ransomware attacks in 2024, a significant increase from the 3,000 ransomware attacks identified in 2023. The increase is due to an improved ability to track ransomware attacks and threat actors conducting attacks in increasing volume, in part due to the increased reluctance of victims to pay ransom demands. A report by Chainalysis earlier this month shows a 35%...



