Is Windows 11 HIPAA Compliant?
Windows 11 is HIPAA compliant inasmuch as the operating system has the underlying security and administrative capabilities to support HIPAA compliance. In addition, Microsoft has confirmed that its in-scope cloud platforms and services are covered by the Microsoft Business Associate Agreement when used on a device running Windows 11. With support for many editions of Windows 10 ending in October 2025, organizations using Microsoft services will be required to upgrade their operating systems to Windows 11. For most organizations currently using Windows 10, the upgrade process is straightforward. Provided devices meet minimum system requirements, programs, apps, and settings currently being used on the devices will be migrated automatically to the upgraded operating system. For organizations currently using older Windows operating systems (i.e., Windows 7), the upgrade will not be so straightforward. Depending on the existing configuration, upgrading to Windows 11 may require a clean install – in which case programs, apps, and settings will not be migrated. In some cases, it will be...
Is eFax HIPAA Compliant?
eFax is HIPAA compliant for covered entities and business associates that subscribe to a qualifying eFax account, enter into a Business Associate Agreement, and configure the service to support HIPAA compliance. However, due to concerns about the vendor’s HIPAA knowledge and messaging, this may not be the most suitable electronic fax solution for all organizations. eFax is an electronic fax solution that enables customers to send, receive, and (in certain circumstances) store faxes via email and cloud services. In addition to supporting person-to-person faxes, eFax’s Enterprise Fax API enables customers to integrate fax processes between CRMs, ERPs, and EHRs – potentially eliminating many manual processes and saving healthcare organizations time and money. However, when using eFax to send, receive, and store faxes that contain Protected Health Information, it is necessary for eFax to be HIPAA compliant. This means the software must have technical capabilities to support HIPAA compliance, the location of the vendor’s servers must be protected according to the Security Rule’s...
Arietis Health Settles MOVEit Data Breach Lawsuit for $2.8 Million
A $2.8 million settlement has been agreed to resolve a class action lawsuit against Arietis Health over a 2023 hacking incident that involved the protected health information of 1,975,066 individuals. Arietis Health, a provider of billing services to NorthStar Anesthesia, was one of more than 2,300 organizations to be affected by the mass exploitation of zero day vulnerability in Progress Software’s MOVEit Transfer solution in late May 2023. Arietis Health used the file transfer solution to transfer large files containing patient information. The Clop threat group exploited the vulnerability, gained access to the Arietis Health MOVEit environment between May 28 and May 31, 2024, and copied data from that environment. The Arietis Health data breach involved patient data from at least 54 healthcare organizations linked to NorthStar Anesthesia, with the compromised data including patient names, dates of birth, driver’s license or other state identification card numbers, addresses, Social Security numbers, medical record numbers, patient account numbers, health insurance information,...
Cyberattack on Arizona Business Associates Affects 78,000 Individuals
Data breaches have been announced by Ottawa Family Physicians in Kansas, CPS Solutions in Ohio, Turning Point of Central California, The Phoenix Rehabilitation and Nursing Center in New York, and Primary Health-SMMPP & U.S. HEALTHWORKS-SMMPP in Arizona. Primary Health-SMMPP & U.S. HEALTHWORKS-SMMPP A data breach has recently been reported that has affected the HIPAA business associates Primary Health-SMMPP and U.S. HEALTHWORKS-SMMPP. Both business associates are based in Arizona and provide healthcare-related services, including the distribution of rapid COVID test kits to schools and organizations in Arizona and other states. On or around December 13, 2024, unusual activity was identified in a server operated by Primary Health-SMMPP. A third-party digital forensics company was engaged to investigate the unauthorized activity and confirmed that an unauthorized third party had breached its defenses and may have viewed or copied data stored on the server. The server was reviewed to identify the individuals affected and the types of data involved, and that process was...
China-Based Threat Group Targets Healthcare with Malicious DICOM Installers
Ransomware groups are targeting healthcare organizations for financial gain, infiltrating networks, stealing data, then using ransomware to encrypt files. Cyber threat actors are also infiltrating healthcare networks and stealing data in much quieter attacks, where compromised healthcare organizations are not extorted and hackers remain in their networks indefinitely. Researchers at the cybersecurity firm Forescout have identified a new China-based threat group that is engaged in these quiet attacks, with one campaign involving weaponized installers for DICOM viewers. The installers are used to deliver a remote access trojan to create a backdoor and gain control of victims’ computers. Silver Fox (aka Void Arachne, The Great Thief of the Valley) is a relatively new threat group first identified in June 2024. Initially, the group was focused on Chinese victims, deploying ValleyRAT malware via SEO poisoning, social media, and text message-based attacks, often under the guise of VPN software and AI applications. The group has been highly active since it emerged and its tactics have...



