PHI Compromised in Email Breaches at Bassford Remele & Scott County, Iowa
Email account breaches have been reported by the law firm Bassford Remele & Scott County in Iowa. Birch Medical has identified unauthorized access to a folder on its network that contained patient data. Email Data Stolen from Bassford Remele The Minneapolis, MN-based law firm, Bassford Remele P.A., recently disclosed a data security incident that was identified on September 4, 2024. The investigation revealed unauthorized emails were sent from a third-party application purporting to be from an employee’s email account. The email account was secured, and third-party digital forensics experts were engaged to investigate the incident. The investigation confirmed there had been unauthorized access to the email account between July 29, 2024, and September 4, 2024, during which time, the unauthorized third party copied the contents of the email account. Bassford Remele provides legal services to certain healthcare organizations, and some of the information in the account included protected health information provided by healthcare clients in connection with those services. The...
Ransomware Attack Surge Continues in 2025
The upward trend in ransomware attacks in 2024 has continued in 2025 with large numbers of new victims added to ransomware groups’ data leak sites in January and February. A recent report from the cybersecurity firm Cyble shows there were at least 599 new additions to data leak sites in the first 27 days of February, an increase from 518 new additions in January, despite February being a shorter month. The majority of the victims are based in the United States, with the victim count up 149% compared to the first 5 weeks of 2024. Over the first five weeks of 2024, 282 new U.S. victims were added to data leak sites, with the victim count rising to 378 in 2025. There has also been a significant increase in attacks on Canadian companies, rising from 14 attacks in the first 5 weeks of 2024 to 46 attacks in 2025. While attacks in North America continue to increase, there has been relatively little change in the numbers of attacks in other countries. Cycle suggests the increase in attacks in North America is most likely due to the belief among ransomware groups that attacks in the region...
New Era Life Insurance Companies Data Breach Impacts 335K Individuals
A major data breach has been announced by New Era Life Insurance Companies that involved the protected health information of more than 335,000 individuals. Data breaches have also been announced by Pacific Rehabilitation Centers, Artistic Family Dental, and DuPage County Health Department. New Era Life Insurance Companies New Era Life Insurance Companies, which include New Era Life Insurance Company, New Era Life Insurance Company of the Midwest, and Philadelphia American Life Insurance Company, have reported a major data breach to the HHS’ Office for Civil Rights that involved the protected health information of 335,506 individuals. Suspicious activity was identified within its computer systems on December 18, 2024, and immediate action was taken to isolate the affected systems to contain the attack. Third party cybersecurity experts were engaged to investigate the activity and confirmed that certain systems had been accessed by an unauthorized third party between December 9, 2024, and December 18, 2024, and during that time, certain files were copied from its systems. A review of...
Is SurveyMonkey HIPAA Compliant?
SurveyMonkey is HIPAA compliant and – when organizations subscribe to an Enterprise Plan and agree to SurveyMonkey’s Business Associate Agreement – Survey Monkey can be used to collect, store, and analyze Protected Health Information (PHI). Organizations that do not wish to subscribe to an Enterprise Plan can still use the service, but not to collect, store, and analyze PHI. SurveyMonkey is an online application that enables subscribers to create and send surveys via email, social media, and messaging services. The application is most often used in the healthcare industry to gain insights into patients’ health habits, track the effectiveness of patient safety programs, and solicit feedback from members of the workforce. Although SurveyMonkey offers a free plan, it is extremely limited. Free subscribers can only ask up to 10 questions per survey, plus accept only 40 responses per survey. Additionally, if PHI is going to be disclosed in any answers or questions, it will be necessary to enter into a Business Associate Agreement – something SurveyMonkey is only prepared to do with...
Vulnerabilities Identified in Dario Health’s Blood Glucose Monitoring Android App
Seven vulnerabilities have been identified in Dario Health’s Android app and Internet-based server infrastructure. If exploited, an attacker could access private personal information, manipulate data, inject code, or achieve cross-site scripting, resulting in full session compromise. The vulnerabilities have CVSS v3.1 base scores ranging from 5.1 to 7.5, and CVSS v4 base scores ranging from 5.1 to 8.7. The vulnerabilities can be exploited remotely with low attack complexity. The vulnerabilities affect the following Dario Health Products: USB-C Blood Glucose Monitoring System Starter Kit Android Application – All versions prior to 5.8.7.0.36 Application Database and Internet-based Server Infrastructure – All versions The vulnerabilities were identified by Noah Cutler and Manuel Del Rio of Accenture, who reported them to the U.S. Cybersecurity and Infrastructure Security Agency (CISA). The vulnerabilities have now been fixed, and users need to update to the latest version of the mobile application, ensuring the update is obtained from a trusted source. Dario Health has also warned...



