Center for Vein Restoration Data Breach Affects Almost 450,000 Individuals
The Center for Vein Restoration, a Greenbelt, MD-based provider of treatments for varicose and spider veins, has experienced a major data breach affecting current and former patients and employees. Unusual system activity was detected on October 6, 2024, and action was taken to isolate the affected systems and law enforcement was notified. The investigation confirmed unauthorized access to its network and files containing patient and employee data may have been viewed or exfiltrated in the attack. The file review confirmed that the types of patient data involved varied from individual to individual and may have included names combined with one or more of the following: address, date of birth, Social Security number, driver’s license number, medical record number, diagnoses, lab results, medications, treatment information, health insurance information, provider names, dates of treatment, and/or financial information. Current and former employees had data exposed related to their employment. The Center for Vein Restoration has implemented additional safeguards and technical security...
Kaye-Smith Settles Class Action Data Breach Lawsuit for $2 Million
The marketing company and mailing vendor, Kaye-Smith Enterprises, has agreed to settle a class action lawsuit filed in response to a 2022 cyberattack and data breach. Hackers gained access to its systems, used ransomware to encrypt files, and potentially exfiltrated sensitive data. Several healthcare providers were affected by the incident, including MultiCare Health System, St. Luke’s Health System, UW Medicine, Delta Dental of Washington, Geisinger Health System and Seattle Children’s Hospital. Several class action lawsuits were filed in response to the breach, which were consolidated into a single action – Smith, et al. v. Kaye-Smith Enterprises Inc.- in the U.S. District Court of Oregon. The plaintiffs asserted a variety of claims related to the failure to protect sensitive data. Kaye-Smith maintains there was no wrongdoing; however, the decision was taken to settle the lawsuit to avoid further legal costs and the uncertainty of trial. The $2 million settlement includes benefits for consumers whose personal and protected health information was compromised in the attack...
Critical Cleo File-Transfer Flaw Under Active Exploitation; Cl0p Claims Responsibility
A critical flaw in Cleo file-transfer software is being actively exploited by threat actors. The vulnerability is believed to be a previously patched flaw, CVE-2024-50623, which allows unrestricted file uploads and downloads, including dangerous file types. Successful exploitation of the vulnerability can lead to remote code execution. The vulnerability affects the following Celo products: Cleo Harmony before 5.8.0.21 Cleo VLTrader before 5.8.0.21 Cleo LexiCom before 5.8.0.21 Cleo issued a patch to fix the vulnerability in October; however, the patch does not provide full protection against exploitation. Researchers at Huntress have observed mass exploitation and post-exploitation activity in patched and unpatched versions of the affected products since December 3, 2024. An analysis of the attacks allowed Huntress to develop a proof-of-concept exploit for the flaw, and while they believe threat actor activity uses the same method to exploit the flaw, they do not have full details of the vulnerability so they could not confirm whether that was the case. It is possible that threat...
OCR Settles Alleged HIPAA Violations with Puerto Rican Healthcare Clearinghouse
The U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) has agreed to settle alleged HIPAA Privacy and Security Rule violations with the Puerto Rican healthcare clearinghouse, Inmediata Health Group. The alleged HIPAA violations were discovered during an investigation of the exposure of individuals’ electronic protected health information (ePHI) via the Internet. OCR received a complaint on November 16, 2018, alleging patients’ ePHI held by Inmediata was accessible over the Internet. OCR’s investigation substantiated the allegations and determined that between May 16, 2016, and January 23, 2019, the ePHI of 1,565,338 individuals was publicly available on the Internet and had been indexed and cached by search engines. Inmediata analyzed the exposed data and determined that names, dates of birth, home addresses, Social Security numbers, claims information, diagnosis/conditions, and other treatment information had been exposed online. OCR determined that the exposure of ePHI violated the HIPAA Privacy Rule, and HIPAA Security Rule violations were...
HealthAlliance Pays $550,000 for Failing to Address a Known Cybersecurity Vulnerability
A New York healthcare provider that experienced a breach of the personal and protected health information of 242,641 New Yorkers has been ordered to pay a financial penalty of $550,000 and take steps to strengthen its data security practices. HealthAlliance serves patients in Ulster and Delaware counties in New York State and operates HealthAlliance Hospital in Kingston, Margaretville Hospital in Margaretville, and Mountainside Residential Care Center in Margaretville. In July 2023, HealthAlliance was notified by its vendor, Citrix, that three vulnerabilities had been identified in its NetScaler networking products, including the critical zero-day vulnerability CVE-2023-3519 that affected two of the NetScaler products deployed on the HealthAlliance network. The cybersecurity advisory explained that threat actors were actively exploiting the vulnerability to deploy a web shell, that gave them remote access to victims’ networks. HealthAlliance attempted to patch the vulnerabilities but was unable to install the patch for the CVE-2023-3519 due to technical issues. HealthAllinace...



