OCR Settles Alleged HIPAA Violations with Puerto Rican Healthcare Clearinghouse
The U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) has agreed to settle alleged HIPAA Privacy and Security Rule violations with the Puerto Rican healthcare clearinghouse, Inmediata Health Group. The alleged HIPAA violations were discovered during an investigation of the exposure of individuals’ electronic protected health information (ePHI) via the Internet. OCR received a complaint on November 16, 2018, alleging patients’ ePHI held by Inmediata was accessible over the Internet. OCR’s investigation substantiated the allegations and determined that between May 16, 2016, and January 23, 2019, the ePHI of 1,565,338 individuals was publicly available on the Internet and had been indexed and cached by search engines. Inmediata analyzed the exposed data and determined that names, dates of birth, home addresses, Social Security numbers, claims information, diagnosis/conditions, and other treatment information had been exposed online. OCR determined that the exposure of ePHI violated the HIPAA Privacy Rule, and HIPAA Security Rule violations were...
HealthAlliance Pays $550,000 for Failing to Address a Known Cybersecurity Vulnerability
A New York healthcare provider that experienced a breach of the personal and protected health information of 242,641 New Yorkers has been ordered to pay a financial penalty of $550,000 and take steps to strengthen its data security practices. HealthAlliance serves patients in Ulster and Delaware counties in New York State and operates HealthAlliance Hospital in Kingston, Margaretville Hospital in Margaretville, and Mountainside Residential Care Center in Margaretville. In July 2023, HealthAlliance was notified by its vendor, Citrix, that three vulnerabilities had been identified in its NetScaler networking products, including the critical zero-day vulnerability CVE-2023-3519 that affected two of the NetScaler products deployed on the HealthAlliance network. The cybersecurity advisory explained that threat actors were actively exploiting the vulnerability to deploy a web shell, that gave them remote access to victims’ networks. HealthAlliance attempted to patch the vulnerabilities but was unable to install the patch for the CVE-2023-3519 due to technical issues. HealthAllinace...
Cyberattack on Fort Worth Revenue Cycle Management Firm Affects 77,000 Individuals
Data breaches have been announced by the revenue cycle management company ESHA Inc., the pulmonary rehabilitation provider Citadel of Northbrook, the health IT company Datavant Group, and the Florida dental practice operator Smile Design Management. ESHA, Inc., Texas ESHA, Inc., a Fort Worth, TX-based revenue cycle management company, has notified 76,922 individuals that some of their personal and protected health information was potentially viewed and/or copied in a security incident over the summer. Unauthorized access to its server infrastructure was detected on July 19, 2024, and the servers were immediately taken offline to prevent further unauthorized access. Digital forensics specialists were engaged to investigate the incident and determine the nature and scope of the unauthorized activity. The investigation confirmed that an unauthorized actor accessed its servers from July 13 to July 17, 2024. The file review was completed on or around September 16, 2024, and individual notifications were mailed to the affected individuals on November 15, 2024. Complimentary credit...
Anna Jacques Hospital Notifies 316K Patients About December 2023 Ransomware Attack
Beth Israel Lahey Health’s Anna Jaques Hospital in Newburyport, Massachusetts, has recently notified regulators and patients about a cyberattack and data breach that occurred on Christmas Day in 2023. According to the notification sent to the Maine Attorney General, the personal information of 316,342 individuals was potentially compromised in a cyberattack that caused disruption to some of its systems – a phrase commonly used to describe a ransomware attack, although ransomware was not mentioned in the notification. Anna Jaques Hospital did not state in the notification letters when the attack was detected or when its network was compromised. The Maine Attorney General’s website erroneously states the breach occurred on December 25, 2024, and was discovered on December 22, 2024. At the time of writing, there is no breach listed on the HHS’ Office for Civil Rights website. Data breaches tend to be added to the OCR breach portal up to two weeks after OCR receives the notification. Anna Jaques Hospital explained in the notification letter that when the incident was detected, the...
Californian Hospitals Continue to be Disrupted by Thanksgiving Ransomware Attacks
Over Thanksgiving weekend, Watsonville Community Hospital and PIH Health in California fell victim to ransomware attacks and continue to experience disruption to their computer systems. Jefferson Dental Center in Indiana has confirmed it has recovered from a November 15, 2024, ransomware attack. Watsonville Community Hospital Grappling with November 29 Ransomware Attack Watsonville Community Hospital in California is currently dealing with a cyberattack and is facing continued disruption to its computer systems. The hospital has implemented downtime protocols due to computer systems being unavailable and is recording patient information manually on charts and issuing paper prescriptions while its IT team and third-party IT specialists work to restore its computer systems. The hospital’s emergency department remains open, and the full spectrum of care continues to be provided; however, patients are facing delays. The cyberattack caused network disruption on November 29, 2024, which has continued for more than a week. The last update on the cyberattack on the hospital’s website was...



