Tycon Medical Systems Reports Data Breach Affecting 112,847 Individuals
Data breaches have been confirmed by Tycon Medical Systems, North Los Angeles County Regional Center, Mohawk Valley Cardiology, and Summa Health. Tycon Medical Systems Tycon Medical Systems, a Norfolk, Virginia-based home medical equipment provider and distributor, has experienced a breach of the protected health information of 112,847 individuals. A breach notification was sent to the Massachusetts Attorney General about a cybersecurity incident involving personal information; however, the breach notification lacks any detail about the nature of the breach such as when it was discovered or the types of information involved. There is currently no substitute breach notice on the Tycon Medical Systems website. The HHS’ Office for Civil Rights website lists the data breach as a hacking/IT incident involving a network server. The affected individuals started to be notified on December 30, 2024, and have been offered complimentary credit monitoring and identity theft protection services for 24 months, which include a $1,000,000 identity theft insurance policy and credit restoration...
Solara Medical Supplies Pays $3M to Settle Alleged HIPAA Security and Breach Notification Rule Violations
The HHS’ Office for Civil Rights (OCR) has announced that a settlement has been reached with a direct-to-patient distributor of medical products to resolve multiple violations of the HIPAA Rules. Solara Medical Supplies, LLC, a subsidiary of AdaptHealth, claims it is the largest American supplier of continuous glucose monitors, insulin pumps, and other supplies to patients with diabetes, and is a Medicare provider that partners with more than 300 insurance providers. Solara Medical Supplies sent a breach notification to OCR in November 2019 about a phishing incident that led to the email accounts of eight employees being accessed by an unauthorized individual between April 2019 and June 2019. Solara’s investigation confirmed the accounts contained the electronic protected health information (ePHI) of 114,007 individuals. Then, in January 2020, OCR was notified that while sending breach notification letters about that incident, 1,531 letters were sent to incorrect mailing addresses, resulting in a further breach of the protected health information (PHI) – demographic...
Dignity Health Lassen Medical Clinic Cyberattack Affects 65,482 Patients
Cyberattacks have been reported by Dignity Health Lassen Medical Clinic in California, The Baker Center for Children and Families in Massachusetts, and Golden Age Home Health in Oklahoma. Sidney Health Center in Montana and The Center for Child Development in Delaware have identified HIPAA breaches by employees. Dignity Health Lassen Medical Clinic Dignity Health Lassen Medical Clinic has notified 65,482 patients of its clinics in Red Bluff and Cottonwood in California that some of their protected health information has been exposed or stolen in a September 2024 cyberattack. The attack was detected on September 20, 2024, when its IT network was disabled. Prompt action was taken to prevent further unauthorized access, and the network was restored the following day. An investigation by a third-party cybersecurity vendor determined that between September 17 and September 20, 2024, files were copied from the network that contained patient data. The electronic medical record system was not involved, but the stolen files included patient data such as names, addresses, dates of birth,...
2024 Was Another Bad Year for Healthcare Ransomware Attacks
A recently published analysis by Comparitech has revealed the extent to which ransomware groups have been breaching networks, encrypting files, and demanding ransom payments from victims. Comparitech’s researchers identified 5,461 successful ransomware attacks in 2024 based on claims by ransomware groups on their data leak sites, and 1,204 of those attacks were confirmed by the attacked organizations. Across the 1,204 confirmed attacks, 195.4 million records were compromised and held to ransom, with the majority of those attacks conducted in North America and Europe. In 2024, RansomHub was the most prolific ransomware group with 89 confirmed attacks, with LockBit close behind with 83 attacks followed by Medusa with 62 attacks and Play with 57 attacks. While the figures for 2024 are high, there was a reduction in attacks compared to 2023 when there were 1,474 confirmed attacks involving 261.5 compromised records. The average ransom demand in 2024 was more than $3.5 million, with $133.5 million in confirmed payments to ransomware groups. The average ransom payment was $9,532,263....
McPherson Hospital Agrees to $500,000 Settlement to Resolve Class Action Data Breach Lawsuit
McPherson Hospital, a 25-bed critical access hospital in Kansas, has agreed to a $500,000 settlement to resolve a class action lawsuit that alleged the hospital was negligent as it failed to implement reasonable and appropriate safeguards to protect patient data. According to the lawsuit, had those safeguards been implemented the data breach could have been prevented. McPherson Hospital mailed notification letters to 19,020 patients in May 2023 informing them that some of their protected health information was accessed and potentially stolen in a July 2022 ransomware attack. The ransomware group accessed its network after an employee responded to a phishing email and disclosed their credentials. The investigation and file review confirmed on March 15, 2023, that patient data had potentially been viewed or stollen in the attack, including names, dates of birth, Social Security numbers, medical treatment information, billing information, and health insurance information. The affected individuals were offered 12 months of complimentary single-bureau credit monitoring services....



