HPH Sector Warned About Grant Donation Email Scam
The Health Sector Cybersecurity Coordination Center (HC3) has issued a sector alert about a grant donation email scam that impersonates Mackenzie Scott, the former wife of Amazon Founder Jeff Bezos. HC3 said it is aware of several healthcare and public health (HPH) sector entities that have received the emails. The emails, a copy of one which was obtained by PCRisk, offer the recipient a share of $4 billion that is being donated to charities, churches, individuals, colleges, and businesses that are suffering financially due to the economic impact of COVID-19 and the war in Ukraine. The emails inform the recipient that they have been randomly selected through an electronic ballot process and are offered a multi-million-dollar grant. While the aims of the scammer are unclear, these types of scam emails typically require the disclosure of sensitive information such as bank account/credit card numbers or require administration fees or other costs associated with the transfer of funds to be paid in advance with the promised funds never sent. A response to the email could result in a...
Lehigh Valley Health Network Data Breach Lawsuit Settled for $65 Million
A $65 million settlement has been agreed to resolve a class action data breach lawsuit against Lehigh Valley Health Network (LVHN) that will see plaintiffs compensated for having nude photographs and other sensitive data stolen and published on the dark web. In February 2023, LVHN in Pennsylvania confirmed it had fallen victim to a Blackcat ransomware attack. The attack was detected on February 6, 2023, and affected a network that supported a Lackawanna County physician practice, which included a system used to store clinically appropriate patient images for radiation oncology treatment. The Blackcat ransomware group demanded a ransom payment to prevent the publication of the stolen data on its data leak site, then started to release images of breast cancer patients, naked from the waist up, to increase the pressure on LVHN to pay the ransom. LVHN refused to pay the ransom and Blackcat leaked the stolen data. A lawsuit was filed by Simon B. Paris and Patrick Howard of the law firm Saltz, Mongeluzzi, & Bendesky, P.C. in March 2023 on behalf of plaintiff Jane Doe and other...
Microsoft & Ivanti Patch Multiple Critical and Actively Exploited Flaws
Microsoft issued patches to fix 79 vulnerabilities on September 2024 Patch Tuesday, including 3 actively exploited vulnerabilities and one that Microsoft considers to be exploited. This month’s updates include fixes for 7 critical flaws, 71 important flaws, and 1 moderate-severity flaw. The actively exploited vulnerabilities affect Windows and Microsoft Publisher CVE-2024-38014 – Windows Installer, Elevation of Privilege – CVSS 7.8 An actively exploited flaw that allows a threat actor to gain SYSTEM privileges on Windows systems. CVE-2024-38226 – Microsoft Publisher, Security Feature Bypass – CVSS 7.3 A flaw allowing an attacker to bypass a security feature that protects against macros embedded in downloaded documents. CVE-2024-38217 – Windows Mark of the Web, Security Feature Bypass – CVSS 5.4 The vulnerability allows an attacker to open specially crafted malicious LNK files and bypass Smart App Control and Mark of the Web security warnings and is thought to have been exploited since 2018. CVE-2024-43491 – Windows Update, Remote Code Execution – CVSS 9.8 Microsoft has not detected...
Email Accounts Compromised at Welcome Health & United Way of Connecticut
Welcome Health and United Way of Connecticut have reported breaches of employee email accounts and potential unauthorized access to patient data. Welcome Health On July 8, 2024, Welcome Health identified suspicious activity in a user’s email account and immediately terminated access to its systems. The forensic investigation confirmed that the user’s credentials had been compromised and were used by an unauthorized individual to access Welcome Health’s systems between June 11, 2024, and July 8, 2024. The file review was completed on August 12, 2024, and confirmed that patient and contractor information had potentially been viewed or acquired. For patients, the compromised information included first and last name, date of birth, patient number, health plan member number, claim number, date(s) of service, and diagnosis and treatment information. Contractors affected by the incident had their first and last names, Social Security numbers, and tax identification numbers compromised. The affected individuals have now been notified and offered complimentary credit monitoring and...
HHS-OIG Audit Finds Deficiencies in New Mexico’s Medicaid Personal Care Services Program
The Department of Health and Human Services Office of Inspector General (HHS-OIG) conducted an audit of New Mexico’s state Medicaid agency’s personal care services (PCS) program and found that it did not always ensure that PCS were provided by appropriately qualified personnel, which put Medicaid enrollees at risk. The audit of the New Mexico Human Services Department, New Mexico’s state Medicaid agency, covered 2.7 million paid Medicaid PCS encounter claims in calendar year 2019, from which a stratified random sample of 300 claims was selected for the audit. HHS-OIG assessed the qualifications of the attendants who provided services for those claims. HHS-OIG identified 294 unique attendants associated with the 300 sampled claims. The attendants for just over one-third (106) of the sampled claims met federal and state qualification requirements; however, the attendants for almost two-thirds (194) of the claims did not meet one or more of the requirements in areas such as criminal background checks, abuse registry checks, TB testing, written competency tests, annual training, and...



