Ransomware Groups Claim 13% More Healthcare Victims in 2024
International law enforcement operations against the prolific ransomware-as-a-service (RaaS) groups LockBit and ALPHV/BlackCat resulted in infrastructure seizures and caused significant disruption to their operations; however, the threat from ransomware continues largely unabated. While law enforcement agencies deny any involvement in the shutdown of the ALPHV/BlackCat group, its disappearance and the ongoing disruption caused to the LockBit group by Operation Cronos in early 2024 has left a gap that other ransomware groups have expanded to fill. Past affiliates of those groups have jumped ship, joining other ransomware groups such as RansomHub, which increased its attacks last year to take the top spot as the most prolific ransomware group. The difficulty in taking down RaaS groups has been highlighted in the annual Ransomware and Cyber Threat Report from GuidePoint Security’s Research and Intelligence Team (GRIT). As the researchers explained, despite these largely successful law enforcement operations, ransomware attacks continue to be conducted in large numbers. It is possible...
HHS-OIG Settles Alleged EMTALA Violations with Tennessee and Missouri Health Systems
Two investigations by the Department of Health and Human Services Office of Inspector General (HHS-OIG) of potential violations of the Emergency Medical Treatment and Labor Act (EMTALA) have been settled with penalties of $97,500 and $258,464 to resolve the alleged EMTALA violations. Under EMTALA, hospitals that accept Medicare payments are required to provide a medical screening examination (MSE) appropriate for the patient’s condition to any patient presenting at the hospital, regardless of their legal status, citizenship, or ability to pay. The patient must be provided with stabilizing treatment, except with informed consent, and the patient may not be transferred without stabilizing treatment unless the patient’s condition requires a transfer to a hospital that is better equipped to administer the stabilizing treatment. The first case concerned a patient who presented at Memorial Health Care System in Chattanooga, Tennessee, in December 2021. According to HHS-OIG, a known diabetic patient presented at Memorial’s Emergency Room seeking treatment; however, had a verbal...
Enzo Biochem Settles Ransomware Data Breach Class Action for $7.5 Million
The Farmingdale, NY-based life sciences and diagnostics company Enzo Biochem has agreed to pay $7.5 million to settle a consolidated class action lawsuit stemming from a 2023 ransomware attack and data breach. Hackers breached its network and used ransomware to encrypt files on April 6, 2024. According to regulatory filings, Enzo Biochem determined on April 11, 2023, that there had been unauthorized access to the clinical test information of 2,470,000 individuals. The compromised data was mostly limited to names and clinical test information, although approximately one-quarter of those individuals – around 600,000 – also had their Social Security numbers compromised in the incident. The Enzo Biochem data breach was one of the largest healthcare data breaches reported in 2023. Several Enzo Biochem class action lawsuits were proposed in response to the data breach alleging Enzo Biochem data security was substandard and Enzo Biochem was negligent by failing to implement reasonable and appropriate safeguards to protect the sensitive personal and health data it collected and stored. The...
December 2024 Healthcare Data Breach Report
It was a relatively quiet end to the year in terms of healthcare data breaches, with only 46 data breaches of 500 or more healthcare records reported to the Department of Health and Human Services (HHS) Office for Civil Rights (OCR) in December. The low December total meant that for only the second time since 2009, there was a year-over-year reduction in healthcare data breaches. The OCR data breach portal currently shows 721 reports of large data breaches in 2024, down 3.48% from 2023’s record-breaking total of 747 large healthcare data breaches. December saw the third-lowest monthly breach total of 2024, with large data breaches falling by 34.3% month-over-month to the second-lowest December total in the past 5 years, with 33 fewer large data breaches than December 2023. December was also a relatively good month in terms of breached healthcare records, with 3,938,375 healthcare records reported as exposed, impermissibly disclosed, or stolen – the second-lowest monthly total of 2024, although that does represent a 14.5% month-over-month increase in breached records. Compared...
Morrison Community Hospital Agrees to $675K Settlement to Resolve Ransomware Lawsuit
Morrison Community Hospital, a critical access hospital in Illinois, has agreed to a $675,000 settlement to resolve a lawsuit filed in response to a 2023 ransomware and data breach. On September 24, 2023, the BlackCat/ALPHV ransomware group used ransomware to encrypt files on its network after exfiltrating sensitive data. When the ransom was not paid, the BlackCat/ALPHV group leaked the stolen data on its data leak site. The data breach was reported to the HHS’ Office for Civil Rights on November 23, 2023, as involving the protected health information of 122,488 current and former patients. The compromised data included names, birth dates, addresses, Social Security numbers, and medical information. Affected patients took legal action against the hospital – In re: Morrison Community Hospital Data Breach Litigation – in the Circuit Court for the 14th Judicial District in Whiteside County, Illinois. The lawsuit alleged insufficient safeguards had been implemented to prevent cyberattacks which amounted to negligence, and as a result of that failure, a hacker was able to breach...



