RRCA Accounts Management Falls Victim to Play Ransomware Attack
RRCA Accounts Management and Aspen Healthcare Services have confirmed they experienced ransomware attacks that involved unauthorized access to patient data. Pinnacle Claims Management has recently announced that it was affected by a MOVEit hack in May 2023. RRCA Accounts Management Last month, the Sterling IL-based collection agency, RRCA Accounts Management, announced that it had fallen victim to a ransomware attack by the Play ransomware group. The attack occurred on June 6, 2024, and was detected and blocked on June 7, 2024. The forensic investigation confirmed that the majority of files accessed by the Play ransomware group did not include any personal information; however, some personal information provided by its healthcare clients had been stolen. RRCA confirmed in its breach notice that there was a full release of the stolen data by the Play threat group on August 20, 2024. The personal information stolen in the attack varied from individual to individual and may have included full names, addresses, phone numbers, dates of birth, and email addresses with one or more of the...
HHS Information Security Program Rated Not Effective for FY24
A review of the U.S. Department of Health and Human Services (HHS) to assess compliance with the Federal Information Security Modernization Act of 2014 (FISMA) for Financial Year 2024 has revealed the HHS information security program is not effective, as was the case with last year’s HHS Office of Inspector General (HHS-OIG) review. The review assessed maturity levels across the five functions of the Cybersecurity Framework – Identify, Protect, Detect, Respond, and Recover, with the level of maturity given one of 5 scores: Level 1 (Ad hoc); Level 2 (Defined); level 3 (Consistently Implemented); level 4 (Managed and Measurable); and Level 5 (Optimized). To receive an effective rating, the HHS must achieve a level 4 rating of Managed and Measurable across all five of the functions of the Cybersecurity Framework. The HHS was assessed on core metrics and supplemental metrics across 10 IG FISMA Domains, but only achieved the Managed and Measurable level in two of those Domains – Risk Management and Information Security Continuous Monitoring, with an overall maturity rating for the...
October 2024 Healthcare Data Breach Report
In October, 57 healthcare data breaches of 500 or more records were reported to the U.S. Department of Health and Human Services (HHS) Office for Civil Rights, slightly fewer than the 2024 average of 62 data breaches per month. While data breaches were below average, there was a 62.9% month-over-month increase in reported data breaches, following a particularly low number in September (35 breaches) – the lowest total since May 2020. As of October 31, 2024, 594 large data breaches have been reported to OCR, almost 100 fewer than this time last year (593 data breaches). Unless there is a sharp uptick in data breaches in November and December, this year will be one of the exceptionally rare years where there is a year-over-year decline in healthcare data breaches. Across the 57 data breaches, the protected health information of 5,232,507 individuals was exposed, stolen, or impermissibly disclosed, with 35% of that total coming from a single data breach. The number of breached records increased by 2.98% from September, although the total is considerably lower than the median of...
HIPAA Compliant Hosting
HIPAA compliant hosting is a service most often provided by cloud service providers that enables covered entities and business associates to take advantage of a hosting environment that complies with the HIPAA Security Rule standards. Most often, a HIPAA compliant hosting service includes access controls, data encryption, operating system security, and segregated servers. The Health Insurance Portability and Accountability Act (HIPAA) was signed into law in 1996 at a time when the Internet was still in its infancy and when most healthcare organizations were recording patient information on paper. It could not have been predicted how technology would progress and how IT practices would change over the next two decades, so the legislation has been kept technology neutral. Web hosting and other cloud services are not mentioned in the HIPAA text, but it is covered by the HIPAA Privacy and Security Rules and there are restrictions placed on the use of cloud services in connection with protected health information (PHI ). HIPAA does not prohibit healthcare organizations from moving...
Ransomware Groups Increasingly Targeting Poorly Secured and Outdated VPNs for Initial Access
Ransomware attacks continue to be conducted at elevated levels, with the number of new victims added to data leak sites increasing slightly (0.72%) in Q3, 2024 from the previous quarter, according to the 2024 Q3 Cyber Threat Report from Corvus. In Q3, 2024 Corvus tracked 1,257 new additions to data leak sites, down 1.64% from Q3, 2023. There has been a marked change in the ransomware landscape, which is far more distributed than last year when a few highly prolific threat groups conducted the majority of attacks. Successful law enforcement operations against LockBit and ALPHV saw affiliates of both groups jump ship, and following the ransomware attack on Change Healthcare, the ALPHV operation was shut down pushing the remaining affiliates into joining other groups or starting up their own operations. In Q3, 2024, there were 59 active ransomware groups, many of which were small-scale ransomware groups, although some highly active ransomware groups remain. The most active group in the quarter was RansomHub, which increased its activity by 160% with at least 195 successful attacks....



