Researcher Identifies Exposed Database Containing Mental Health and Substance Abuse Treatment Information
A cybersecurity researcher has found an exposed healthcare database containing mental health and substance abuse treatment records that could be accessed via the Internet without a password. Researcher Jeremiah Fowler traced the database to Confidant Health, an Austin, TX-based company that has an AI-powered platform that connects individuals with therapists, psychiatrists, and providers of addiction treatment services. The company serves individuals in the states of Connecticut, Florida, New Hampshire, Texas, and Virginia. Fowler identified around 126,000 files and 1.7 million logging records, which included sensitive personally identifiable information of patients, therapists, and healthcare professionals. The exposed information included names, addresses, driver’s license information, state IDs, Medicaid cards, prescription medications, medical record requests, drug test results, and other health information. Audio recordings of sessions and text transcripts had also been exposed. Fowler notified Confidant Health about the exposed data, was told that the incident would be...
HHS-OIG Audit South Carolina Identifies Failure to Invoice $14.2 Million for Drug Rebates
The HHS Office of Inspector General (HHS-OIG) audited the South Carolina Department of Health and Human Services, South Carolina’s Medicaid agency, to assess compliance with the Medicaid requirements for invoicing manufacturers for rebates for physician-administered drugs dispensed to MCO enrollees. For a covered outpatient drug to be eligible for federal reimbursement under the Medicaid program’s drug rebate requirements, manufacturers must pay rebates to the states for the drugs. HHS-OIG has conducted previous audits that indicate states do not always invoice and collect rebates for MCO’s enrollees. This was the latest in a series of audits to assess compliance with the Medicaid drug rebate program, which took effect in 1991. HHS-OIG reviewed physician-administered drug claims paid by the MCOs between January 1, 2016, and December 31, 2019, which totaled $168,590,761. After removing claims for drugs that were not eligible for rebates or where invoices for rebates were sent, HHS-OIG identified physician-administered drug claims totaling $45,244,489 and then worked with the state...
Feds Issue Warning About Russian Hacking Group Targeting Critical Infrastructure
The Federal Bureau of Investigation (FBI), Cybersecurity and Infrastructure Security Agency (CISA), National Security Agency (NSA), and their partners have issued a joint cybersecurity advisory about Russian military hackers who have been targeting critical infrastructure entities in the United States and other NATO countries. The authorizing agencies believe the hackers are affiliated with the Russian General Staff Main Intelligence Directorate (GRU) 161st Specialist Training Center (Unit 29155) but are distinct from other more established GRU hacking groups. The hacking group is tracked by several cybersecurity companies under the names Cadet Blizzard, Ember Bear, Frozenvista, UNC2589, and UAC-0056. The hackers conduct computer network operations against targets around the world for espionage, sabotage, and to cause reputational harm and have been active since at least 2020. Since January 2022, the hackers have been targeting organizations in Ukraine and deploying the destructive multi-stage wiper malware WhisperGate. In addition, offensive cyber campaigns have been conducted...
OSHA Makes it Easier to Search and Use Severe Workplace Injury Report Data
The Department of Labor’s Occupational Safety and Health Administration has released a new online dashboard that makes it easier to search OSHA’s severe injury report database and identify workplace injury trends in states covered by federal OSHA. Since January 1, 2015, OSHA regulations have required employers to report all severe injuries in the workplace to OSHA within 24 hours. Severe injuries are defined as amputations, loss of an eye, or in-patient hospitalization. The reports are compiled into a database which can be accessed through the OSHA website. The new dashboard allows users to search the severe injury database. The search tool includes the option of searching using criteria such as year, industry, state, establishment name, Occupational Injury and Illness Classification System code, event type, nature of the incident, and even the affected body part. The search data are represented in graphical form and can be downloaded through the tool. OSHA has also released a video presentation that explains how to use the dashboard. The tool shows the most common cause of severe...
Almost 2.9 Million Individuals Affected by Acadian Ambulance Cyberattack
Acadian Ambulance Service has started notifying the individuals affected by its recent cyberattack and data breach. Daixin Team claimed responsibility for the attack and suggested 10 million unique records were stolen from the Louisiana-based private ambulance service. While the breach involved a significant number of records, it was not as severe as Daixin Team claimed. On August 20, 2024, Acadian Ambulance reported the breach to the HHS’ Office for Civil Rights as involving the protected health information of 2,896,985 individuals. Acadian Ambulance confirmed in its breach notification letters that suspicious activity was identified within its computer systems on June 21, 2024. Action was taken to isolate its systems to prevent further unauthorized access, and third-party computer specialists were engaged to investigate the security breach. They determined that a threat actor had access to its network between June 19, 2024, and June 21, 2024. During that time, files were exfiltrated from its systems. It has taken more than two months to investigate the incident, review...



