Southeast Series of Lockton Companies to Pay $9.9 Million to Settle Data Breach Litigation
Southeast Series of Lockton Companies, LLC, a provider of insurance services, has agreed to pay up to $9,900,000 to settle a class action lawsuit stemming from a major data breach in November 2024. While many cyberattacks involve broad access being gained to computer networks, in this case a hacker accessed a single account and computer within its environment; however, despite the access being limited, the hacker was able to access files containing the protected health information of 1,124,727 individuals, including names, addresses, phone numbers, email addresses, dates of birth, Social Security numbers, and financial information. The affected individuals were notified about the data breach in March 2025 and were offered complimentary credit monitoring services for 24 months. Multiple class action lawsuits were filed in response to the data breach, which were consolidated into a single complaint – Penny Beasley, et al. v. Southeast Series of Lockton Companies, LLC, et al. – in the Circuit Court of Jackson County, Missouri. The defendants maintain there was no wrongdoing and...
Accendo Insurance Company Affected by Business Associate Data Breach
Data breaches have recently been announced by Accendo Insurance Company, Menorah Life, Humboldt Independent Practice Association, and Samaritan Counseling Center of the Fox Valley. Accendo Insurance Company Accendo Insurance Company, a CVS Health Medicare supplement insurance provider, has been affected by a data breach at one of its business associates. Landmark Admin is a third-party administrator for insurance carriers, and in its capacity as a business associate, was provided with the personal information of individuals who purchased insurance through Accendo. On or around May 13, 2024, Landmark identified suspicious activity within its computer network. A third-party cybersecurity firm was engaged to investigate the activity and the investigation concluded on July 24, 2024. Landmark confirmed that a ransomware group had access to its network between May 13, 2024, and June 17, 2024, and exfiltrated data from its systems and encrypted files. According to Accendo’s January 22, 2025, notice to the South Carolina Attorney General, Landmark has been issuing notifications to the...
District of Columbia Health Benefit Exchange Authority Agrees to $1.45M Data Breach Settlement
The District of Columbia Health Benefit Exchange Authority (HBX) has agreed to settle a class action lawsuit stemming from a 2023 data breach. HBX operates the Affordable Care Act online health insurance marketplace, DC Health Link, which residents and small businesses in the District use to obtain affordable health coverage. In March 2023, HBX confirmed that the data of some DC Health Link customers had been accessed by an unauthorized individual and released on a public forum. The data related to residents of the Washington DC area, including members of Congress and their families. HCX confirmed that 56,415 customers had their data stolen and published online, although in total, up to 170,000 individuals may have been affected. The remaining individuals were notified out of an abundance of caution. The data compromised in the incident included name, Social Security number, date of birth, gender, health plan information, employer information, and enrollee information. Legal action was taken by victims of the data breach claiming HCX failed to implement reasonable and appropriate...
What is a HIPAA Security Incident?
A HIPAA security incident is an event that threatens the confidentiality, integrity, or availability of electronic Protected Health Information (PHI) regardless of whether the event is successful or not. It is important that all security incidents are tracked and reviewed to identify potential weaknesses in security defenses. Misunderstandings can sometimes exist with regards to the distinction between the definition of a HIPAA security incident and the definition of a HIPAA breach. Although the two events are quite often linked, not all security incidents result in breaches, and not all breaches are attributable to security incidents. One of the reasons misunderstandings can exist about the two terms is that their definitions appear in separate subparts of the HIPAA Administrative Simplification Regulations. For example, the HIPAA security incident definition appears in §164.304 of the HIPAA Security Rule: “Security incident means the attempted (emphasis added) or successful unauthorized access, use, disclosure, modification, or destruction of information or interference with...
Vulnerabilities Identified in Orthanc Server and MicroDicom DICOM Viewer
Two vulnerabilities have been identified in DICOM medical imaging products – A critical vulnerability in the standalone DICOM server, Orthanc Server, and a medium-severity vulnerability in MicroDicom DICOM Viewer. Critical Orthanc Server Vulnerability A security researcher has identified a critical vulnerability in Orthanc Server that could be exploited by a threat actor to gain unauthorized access to the server. After successfully exploiting the flaw, an attacker could view or modify sensitive data on the server or cause a denial-of-service condition. The vulnerability, tracked as CVE-2025-0896, has a CVSS v3.1 base score of 9.8 (CVSS v4 9.2) and can be exploited remotely in a low-complexity attack. The vulnerability affects all Orthanc Server versions prior to version 1.5.8 and is due to basic authentication not being enabled by default when remote access is enabled. The vulnerability was reported to Orthanc by researcher Amitay Dan and has been addressed in the latest version of the free-to-use open-source software. If an update is not immediately possible, users should enable...



