Harvard Pilgrim Health Care Ransomware Attack Affected at Least 2,967,000 Individuals
Harvard Pilgrim Health Care has issued an updated notification to the Maine Attorney General about its April 2023 ransomware attack, increasing the total number of affected individuals by 106,601 to 2,967,396 individuals. In the notification, Harvard Pilgrim Health Care said the investigation into the data breach is still ongoing, so that may not be the final total. Harvard Pilgrim Health Care said the investigation uncovered evidence that a significant amount of data was copied from its systems between March 28, 2023, and April 17, 2023, which included personal and protected health information. The data stolen in the attack is known to have included names, physical addresses, phone numbers, dates of birth, health insurance account information, Social Security numbers, and clinical information such as medical histories, diagnoses, treatment information, dates of service, and provider names. A limited number of the affected individuals also had their financial account information stolen. Harvard Pilgrim Health Care has been issuing notifications on a rolling basis to individuals...
OCR Imposes $240,000 HIPAA Fine on Californian Healthcare Provider
The Department of Health and Human Services (HHS) Office for Civil Rights (OCR) has imposed a $240,000 civil monetary penalty on Providence Medical Institute to resolve potential violations of two provisions of the HIPAA Security Rule. This is the fifth investigation of a ransomware attack to result in a penalty for noncompliance with the HIPAA Rules. Providence Medical Institute (PMI) is a Californian healthcare provider that acquired a full-scope orthopedic medical service provider – Center for Orthopaedic Specialists (COS) – in July 2016. PMI planned to fully integrate COS as a PMI unit within 2 years, although the integration was delayed until May 2019. On February 18, 2018, a ransomware group encrypted files on COS systems. The threat actor gained a foothold in the network after an employee responded to a phishing email and disclosed their credentials. Within a few days of the encryption event, systems were restored from backup tapes; however, on February 25, 2018, COS systems were encrypted a second time. Within a few days, files were restored from backup tapes for a second...
What is a HIPAA Course?
A HIPAA course is a training course that is either provided by an employer to members of the workforce, or that is taken independently by an individual in order to obtain a qualification that demonstrates an understanding of HIPAA. The first type of HIPAA course is most often a regulatory requirement. The second type of HIPAA course is optional, but is recommended for students, jobseekers, and employees in the healthcare industry. The HIPAA training requirements in §164.530(b) of the HIPAA Privacy Rule require covered entities to provide training on HIPAA policies and procedures to all new members of the workforce when they join the covered entity’s workforce. A HIPAA training course must also be provided for all members of the workforce when their functions are affected by a material change to policies and procedures. Business associates must also comply with these requirements “where provided”. In addition, covered entities and business associates are required by §164.308(a) of the Security Rule to provide security and awareness training to all members of the workforce...
Four Individuals Connected to LockBit Ransomware Attacks Arrested; Evil Corp Members Sanctioned
An international law enforcement operation has resulted in the arrests of four individuals suspected of involvement in LockBit ransomware attacks and the takedown of nine servers linked to LockBit ransomware operations. Operation Cronos The latest actions are part of phase three of Operation Cronos, an international law enforcement operation led by the UK’s National Crime Agency (NCA) that successfully took down the online infrastructure of the LockBit ransomware operation in February this year. The February operation caused significant disruption to the group’s operations, and while the group claimed to have restored its infrastructure within a week, it was clear that Operation Chronos caused significant disruption that lasted longer than the group was willing to acknowledge. The NCA obtained around 7,000 decryption keys, which allowed victims to recover their data. The operation uncovered the leader of the group, Russian national Dmitry Khoroshev aka LockBitSupp, who has since been sanctioned by the Foreign, Commonwealth & Development Office (FCDO), US Department of the...
Email Account Breaches Reported by Four HIPAA Covered Entities
Four HIPAA-covered entities have recently reported breaches of their email environments: Southern Bone & Joint Specialists in Mississippi, Connally Memorial Medical Center in Texas, Rim Country Health and Rehabilitation in Arizona, and Michigan Masonic Home. Southern Bone & Joint Specialists Southern Bone & Joint Specialists in southern Mississippi have reported a breach of their email environment. Unauthorized activity was identified in certain employee email accounts on May 7, 2024, and after the accounts were secured, a specialized cybersecurity firm was engaged to investigate the breach. The investigation confirmed there had been unauthorized access to the accounts and that certain files and data stored in the email environment had been accessed. The file review was completed on August 6, 2024, and confirmed that the protected health information of 7,162 patients had been exposed. The types of information involved varied from individual to individual and may have included names, addresses, phone numbers, dates of birth, diagnosis codes, insurance policy numbers, and...



