Is Acuity HIPAA Compliant?
Acuity is HIPAA compliant for covered entities and business associates that subscribe to a HIPAA-enabled Powerhouse or Enterprise account, configure the account to support HIPAA compliance, and disable non-compliant integrations and services. Depending on if and how payments are accepted via Acuity, it may also be necessary to change payment processors. Acuity is a versatile online scheduling solution that was acquired by Squarespace in 2019. Acuity Scheduling can be used with – or independently of – Squarespace websites to schedule appointments, send automated text and email reminders, and process payments. It also integrates with many client engagement, video conferencing, and accounting solutions to increase productivity and efficiency. When using Acuity to create, receive, store, or transmit personal information that is considered Protected Health Information (PHI) under HIPAA, it is necessary for Acuity to be HIPAA compliant. Acuity states it supports HIPAA compliance, but only under certain conditions. These conditions include subscribing to a Powerhouse or...
Eskenazi Health Pays $2.5 Million to Resolve Class Action Data Breach Lawsuit
Eskenazi Health has agreed to settle litigation stemming from an August 2021 ransomware attack in which the protected health information of more than 1.5 million patients was compromised. The ransomware attack was detected on or around August 4, 2024, when files were encrypted on its systems. The forensic investigation confirmed that a ransomware group first accessed its systems on May 19, 2021, and disabled its security systems, allowing them to remain in its network undetected. The initial investigation found no evidence of data theft; however, data exfiltration was later identified. Data stolen in the attack included names, addresses, telephone numbers, email addresses, dates of birth, medical record numbers, patient account numbers, diagnoses, clinical information, insurance information, prescriptions, driver’s license numbers, passport numbers, face photographs, Social Security numbers, and credit card information. Patients were notified about the data breach in November 2021 and were offered complimentary credit monitoring services. Eskenazi Health was able to recover the...
BayMark Health Services Notifies Patients About October Ransomware Attack
Texas-based BayMark Health Services, North America’s largest provider of substance use disorder treatment and recovery services and a provider of administrative services to BAART Programs, Healthcare Resource Centers, and MedMark Treatment Centers, has started notifying patients that some of their protected health information was compromised in a recent cyberattack. According to the patient notification letters, BayMark Health Services discovered the cyberattack on October 11, 2024, when its IT systems were disrupted. The forensic investigation confirmed that an unauthorized third party had access to its network for almost 3 weeks between September 24, 2024, and October 14, 2024. During that time, the threat actor accessed and acquired files containing patient data. BayMark Health Services has reviewed the affected files and confirmed that they contained information such as patient names, dates of birth, services received, dates of service, Social Security numbers, driver’s license numbers, health insurance information, diagnostic and treatment information, and treating provider...
Patch Warning: Critical Ivanti Connect Secure Zero-day Exploited
Ivanti has released patches for two Connect Secure vulnerabilities including a critical zero-day remote code execution vulnerability that is being actively exploited in the wild to install malware. The first instances of exploitation are believed to have occurred in mid-December. The vulnerability was identified by Ivanti after the Ivanti Integrity Checker Tool (ICT) revealed the presence of malware on users’ appliances. The malware was installed after a threat actor exploited a previously unknown remote code execution flaw, which is being tracked as CVE-2025-0282 and has a CVSS severity score of 9.0. The critical stack buffer overflow flaw affects all Ivanti Connect Secure (Pulse Secure) VPN appliances running versions 22.7R2 through 22.7R2.5, Ivanti Policy Secure versions 22.7R1 through 22.7R1.2, and Ivanti Neurons for ZTA Gateways versions 22.7R2 through 22.7R2.3, although to date, the flaw only appears to have been exploited to compromise Ivanti Connect Secure appliances. A second stack buffer overflow flaw has also been patched, although it is not currently being exploited....
Eastern Idaho Public Health Discovers Insider Data Breach
Eastern Idaho Public Health has discovered an insider data breach, Pacific Pulmonary Medical Group has identified unauthorized access to its scheduling software, and Ingham County Medical Care Facility (Dobie Road) said patient data was accessed in a security incident at its electronic health records portal manager. Eastern Idaho Public Health Discovers Insider Data Breach Eastern Idaho Public Health has started notifying certain patients that one of its former employees has accessed their medical records without authorization. When unauthorized access to medical records was suspected, a review was conducted of the employee’s access logs and interviews were conducted with staff members. The employee was discovered to have viewed patient records, specifically patient clinic notes. The information potentially viewed included health screening information, patient histories, assessments, orders, and test results. Eastern Idaho Public Health was able to confirm that copies of the records had not been made and Eastern Idaho Public Health is confident that the information in the medical...



