226,000 Individuals Affected by Regional Care, Inc. Cyberattack
Regional Care, Inc., a Scottsbluff, NE-based health insurance agency, has notified 225,728 individuals about a cybersecurity incident that involved some of their personal and protected health information. Suspicious activity was identified within its network on September 18, 2024. The investigation confirmed on or around November 8, 2024, that there had been unauthorized access to its network, and the threat actor viewed or acquired information such as names, birth dates, Social Security numbers, medical information, and health insurance information. Notification letters were mailed to the affected individuals on December 16, 2024, and individuals whose Social Security numbers were involved were offered complimentary credit monitoring services. Regional Care said it had taken many precautions to safeguard personal information and continually evaluates and modifies its practices and internal controls to enhance data security. Email Breach at Amergis Healthcare Staffing Affects 11,000 Individuals Columbia, MD-based Amergis Healthcare Staffing, Inc., formerly Maxim Healthcare...
Brockton Neighborhood Health Center Suffers Interlock Ransomware Attack
Brockton Neighborhood Health Center in Massachusetts has suffered an Interlock ransomware attack and data breaches have been announced by Kitsap Mental Health Services in Washington state and Continental Cafe Holdings in Michigan. Brockton Neighborhood Health Center Suffers Interlock Ransomware Attack Brockton Neighborhood Health Center in Massachusetts is alerting patients about a cyberattack detected on November 3, 2024. Suspicious activity was identified within its computer network, and an investigation was launched to determine the nature and scope of the incident. On November 18, 2024, Brockton Neighborhood Health Center learned that a threat actor had access to its network from November 1 through November 3, 2024, and viewed or copied certain files from its systems. The file review confirmed on November 29, 2024, that the data related to patients who received treatment between 2017 and 2022, and included names, addresses, dates of birth, diagnoses/conditions, lab test results, medications, other treatment information, medical record numbers, and health insurance information....
Texas Tech University Health Sciences Center Ransomware Attack Affects 1.46 Million Patients
Texas Tech University Health Sciences Center, an academic health institution and medical school of Texas Tech University, has confirmed that a large volume of patient data was exfiltrated in a September ransomware attack involving systems shared by Texas Tech University Health Sciences Center in El Paso, Texas Tech Physicians, and UMC Health System. Two breach reports have been submitted to the HHS’ Office for Civil Rights confirming the electronic protected health information (ePHI) of 1,465,000 patients was compromised in the attack, 650,000 of whom were patients of Texas Tech University Health Sciences Center and 815,000 were patients of its El Paso center. UMC Health previously reported the breach as affecting at least 501 individuals. The Health Sciences Centers (HSCs) explained that the ransomware attack was detected in September 2024 when some of their computer systems and applications were disrupted. Immediate action was taken to secure its systems, and an investigation was launched to identify the cause of the disruption. The HSCs confirmed that the disruption was caused...
UT Southwestern Medical Center Data Breach Affects 43,000 Patients
UT Southwestern Medical Center (UTSW) in Texas has recently reported an email-related unauthorized access/disclosure incident to the HHS’ Office for Civil Rights (OCR) involving the protected health information of up to 43,048 patients. The substitute breach notice on its website explains that UTSW was made aware of the privacy incident on October 10, 2024. Members of the workforce were using a third-party calendar management tool which inadvertently allowed the vendor to access certain calendars and, in some cases, the calendars included patients’ protected health information. The investigation revealed employees had added patient data to the third-party tool which included names, dates of birth, medical record numbers, phone numbers, date(s) of planned services, medical diagnoses, lab test results, medication information, insurance benefits information, and, for certain patients, partial social security numbers. The breach notice does not state for how long the calendar tool was used by employees, whether UT Southwestern Medical Center had expressly permitted employees to use the...
Survey Reveals 65% of Employees Take Security Shortcuts
Organizations invest in cybersecurity solutions and develop policies and procedures to ensure compliance and minimize risk, only for employees to circumvent those policies and security measures. The scale of the problem was highlighted by a recent survey conducted by Censuswide on behalf of the security and access management vendor, CyberArk. The survey explored employee behaviors and was conducted in October 2024 on more than 14,000 employees in a wide range of job roles and various verticals in the US, UK, France, Germany, Australia, and Singapore. Almost all surveyed employees had some form of privileged access or access to sensitive data, and all employees accessed business-critical applications using corporate devices. 80% of employees also admitted to accessing work applications using their personal devices. While employers may have Bring Your Own Device (BYOD) policies allowing personal devices to be used for work purposes, personal devices typically lack security controls and pose a security risk. For instance, 36% of employees who said they use a personal device for work...



