Email Data Breaches Announced by 4 U.S. Healthcare Orgs
Unauthorized individuals have gained access to employee email accounts at four healthcare organizations over the summer, resulting in HIPAA email compliance breaches: HealthFund Solutions in Florida, Option Care Health in Illinois, and Liberty Endo and Numotion in New York. HealthFund Solutions HealthFund Solutions, LLC, a Florida-based health insurance solutions company, has discovered unauthorized access to an employee’s email account. The email account breach was detected on August 14, 2024, and after securing the account, a third-party digital forensics firm was engaged to investigate the incident. The investigation confirmed that unauthorized access was limited to a single email account, and on September 16, 2024, it was determined that the email account contained the protected health information of 5,198 individuals. Information compromised in the incident included names, addresses, dates of birth, Social Security numbers, medical information, and health insurance information. Notification letters were mailed to the affected individuals on November 15, 2024. While there has...
Feds Update BianLian Cybersecurity Alert as Threat Actor Adopts New Tactics
The Federal Bureau of Investigation (FBI), Cybersecurity and Infrastructure Security Agency (CISA), and the Australian Cyber Security Centre (ACSC) have updated their cybersecurity advisory about the BianLian threat group following the adoption of new tactics in recent attacks. BianLian is believed to operate from inside Russia and has many Russia-based affiliates. Since June 2022, the threat group has attacked many critical infrastructure entities in the United States and Australia, including healthcare organizations such as Boston Children’s Health Physicians, Amherstburg Family Health, River Region Cardiology Associates, Healthcare Management Systems, and Augusta-Aiken Orthopedic Specialists. The group has also targeted the property development and professional services sector. Bianlian is a ransomware developer, deployer, and data extortion group, and its early attacks involved breaching networks, stealing data, and encrypting files. In January 2023, the BianLian group started transitioning to data extortion-only attacks, exfiltrating data and issuing ransom demands, but...
Does HIPAA Apply to Veterinarians?
HIPAA does not apply to veterinarians because veterinarians do not conduct electronic healthcare transactions for which the Department of Health and Human Services has adopted standards and therefore do not qualify as HIPAA covered entities. However, regulations similar to HIPAA apply to veterinarians in several states or in certain circumstances. In the context of the question does HIPAA apply to veterinarians, the “Applicability” section of the HIPAA General Provisions provides the answer. The Applicability section (§160.102) states HIPAA applies to health plans, health care clearinghouses, and healthcare providers who transmit health information in electronic form in connection with a covered transaction (collectively “covered entities”). HIPAA also applies “where provided” to business associates of covered entities. Even though it could be argued that veterinarians qualify as healthcare providers (for animals), they do not fulfill the remaining criteria to qualify as HIPAA covered entities. This is because they do not electronically transmit health information relating to a...
OSHA Confirms Signature Health Has Improved Employee Safety Following April Stabbing Incident
In April 2024, a patient of a Signature Health mental health treatment facility in Maple Heights, Ohio attacked a nurse practitioner, repeatedly stabbing the employee with a knife that the patient had brought into the facility. The Maple Heights facility only had a single security guard, who, assisted by other members of the facility staff, was able to disarm the patient and stop the attack. As required by law, the workplace injury was reported to the Department of Labor’s Occupational Safety and Health Administration (OSHA) and an investigation was launched, which resulted in Signature Health being issued with a citation for a serious violation under the general duty clause of the OSH Act for failing to protect employees from workplace violence. Signature Health entered into a settlement agreement and agreed to pay a penalty of $16,131 and take steps to improve its workplace violence prevention program. In the 6 months following the attack, Signature Health has implemented several measures at the Maple Health facility to improve employee safety. Those measures include the...
RRCA Accounts Management Falls Victim to Play Ransomware Attack
RRCA Accounts Management and Aspen Healthcare Services have confirmed they experienced ransomware attacks that involved unauthorized access to patient data. Pinnacle Claims Management has recently announced that it was affected by a MOVEit hack in May 2023. RRCA Accounts Management Last month, the Sterling IL-based collection agency, RRCA Accounts Management, announced that it had fallen victim to a ransomware attack by the Play ransomware group. The attack occurred on June 6, 2024, and was detected and blocked on June 7, 2024. The forensic investigation confirmed that the majority of files accessed by the Play ransomware group did not include any personal information; however, some personal information provided by its healthcare clients had been stolen. RRCA confirmed in its breach notice that there was a full release of the stolen data by the Play threat group on August 20, 2024. The personal information stolen in the attack varied from individual to individual and may have included full names, addresses, phone numbers, dates of birth, and email addresses with one or more of the...



