October 2024 Healthcare Data Breach Report
In October, 57 healthcare data breaches of 500 or more records were reported to the U.S. Department of Health and Human Services (HHS) Office for Civil Rights, slightly fewer than the 2024 average of 62 data breaches per month. While data breaches were below average, there was a 62.9% month-over-month increase in reported data breaches, following a particularly low number in September (35 breaches) – the lowest total since May 2020. As of October 31, 2024, 594 large data breaches have been reported to OCR, almost 100 fewer than this time last year (593 data breaches). Unless there is a sharp uptick in data breaches in November and December, this year will be one of the exceptionally rare years where there is a year-over-year decline in healthcare data breaches. Across the 57 data breaches, the protected health information of 5,232,507 individuals was exposed, stolen, or impermissibly disclosed, with 35% of that total coming from a single data breach. The number of breached records increased by 2.98% from September, although the total is considerably lower than the median of...
HIPAA Compliant Hosting
HIPAA compliant hosting is a service most often provided by cloud service providers that enables covered entities and business associates to take advantage of a hosting environment that complies with the HIPAA Security Rule standards. Most often, a HIPAA compliant hosting service includes access controls, data encryption, operating system security, and segregated servers. The Health Insurance Portability and Accountability Act (HIPAA) was signed into law in 1996 at a time when the Internet was still in its infancy and when most healthcare organizations were recording patient information on paper. It could not have been predicted how technology would progress and how IT practices would change over the next two decades, so the legislation has been kept technology neutral. Web hosting and other cloud services are not mentioned in the HIPAA text, but it is covered by the HIPAA Privacy and Security Rules and there are restrictions placed on the use of cloud services in connection with protected health information (PHI ). HIPAA does not prohibit healthcare organizations from moving...
Ransomware Groups Increasingly Targeting Poorly Secured and Outdated VPNs for Initial Access
Ransomware attacks continue to be conducted at elevated levels, with the number of new victims added to data leak sites increasing slightly (0.72%) in Q3, 2024 from the previous quarter, according to the 2024 Q3 Cyber Threat Report from Corvus. In Q3, 2024 Corvus tracked 1,257 new additions to data leak sites, down 1.64% from Q3, 2023. There has been a marked change in the ransomware landscape, which is far more distributed than last year when a few highly prolific threat groups conducted the majority of attacks. Successful law enforcement operations against LockBit and ALPHV saw affiliates of both groups jump ship, and following the ransomware attack on Change Healthcare, the ALPHV operation was shut down pushing the remaining affiliates into joining other groups or starting up their own operations. In Q3, 2024, there were 59 active ransomware groups, many of which were small-scale ransomware groups, although some highly active ransomware groups remain. The most active group in the quarter was RansomHub, which increased its activity by 160% with at least 195 successful attacks....
Data Breaches Reported by Hopscotch; Athenahealth; Central Resources
Hopscotch Health Management has learned that a bad actor accessed the physical records of almost 5,000 patients. Data breaches have also been reported by the EHR vendor athenahealth and the debt collection company Central Resources. Hopscotch Health Management Hopscotch Health Management in Illinois has recently reported a data breach to the HHS’ Office for Civil Rights that involved the protected health information of 4,945 patients. Unauthorized access to physical records was detected by Hopscotch on August 27, 2024. The records contained information about patients of Cannon Family Health, which now operates as Hopscotch Primary Care, and specifically patients who received healthcare services at its primary care facility at 6 Brooklet Street in Asheville, NC. A bad actor with no affiliation with Hopscotch accessed the physical records. Law enforcement provided access to some of the impacted records on September 19, 2024, and Hopscotch confirmed they included billing statements that included name, the amount paid and identified the individual as a patient of Cannon Family Health,...
Phishing Campaign Abuses DocuSign API to Send Fake Invoices
The healthcare and public health sector (HPH) has been warned about an ongoing widespread phishing campaign that abuses DocuSign e-signature software to impersonate well-known brands. The aim of the campaign is to trick individuals into enabling authorization of payments for fake invoices from their billing department The campaign was identified in early December by researchers at Wallarm. The threat actor does not appear to be targeting any specific sector; however, the Health Sector Cybersecurity Coordination Center (HC3) has issued a sector alert as the threat activity has the potential to affect the HPH sector and the sector has been targeted in the past in similar fake invoice phishing campaigns. According to the researchers, the threat actor uses the DocuSign Envelopes API to create and mass-distribute fake invoices that appear to have been sent by companies such as Norton and PayPal. The invoices are realistic and include accurate pricing information for the products. For instance, one invoice was generated for the all-in-one security suite, Norton LifeLock 360. The invoice...



