OSHA Makes it Easier to Search and Use Severe Workplace Injury Report Data
The Department of Labor’s Occupational Safety and Health Administration has released a new online dashboard that makes it easier to search OSHA’s severe injury report database and identify workplace injury trends in states covered by federal OSHA. Since January 1, 2015, OSHA regulations have required employers to report all severe injuries in the workplace to OSHA within 24 hours. Severe injuries are defined as amputations, loss of an eye, or in-patient hospitalization. The reports are compiled into a database which can be accessed through the OSHA website. The new dashboard allows users to search the severe injury database. The search tool includes the option of searching using criteria such as year, industry, state, establishment name, Occupational Injury and Illness Classification System code, event type, nature of the incident, and even the affected body part. The search data are represented in graphical form and can be downloaded through the tool. OSHA has also released a video presentation that explains how to use the dashboard. The tool shows the most common cause of severe...
Almost 2.9 Million Individuals Affected by Acadian Ambulance Cyberattack
Acadian Ambulance Service has started notifying the individuals affected by its recent cyberattack and data breach. Daixin Team claimed responsibility for the attack and suggested 10 million unique records were stolen from the Louisiana-based private ambulance service. While the breach involved a significant number of records, it was not as severe as Daixin Team claimed. On August 20, 2024, Acadian Ambulance reported the breach to the HHS’ Office for Civil Rights as involving the protected health information of 2,896,985 individuals. Acadian Ambulance confirmed in its breach notification letters that suspicious activity was identified within its computer systems on June 21, 2024. Action was taken to isolate its systems to prevent further unauthorized access, and third-party computer specialists were engaged to investigate the security breach. They determined that a threat actor had access to its network between June 19, 2024, and June 21, 2024. During that time, files were exfiltrated from its systems. It has taken more than two months to investigate the incident, review...
Texas Sues HHS to Overturn HIPAA Privacy and Reproductive Healthcare Privacy Final Rules
Texas Attorney General Ken Paxton (R) has filed a lawsuit against the Department of Health and Human Services (HHS), HHS Secretary Xavier Becerra, and Office for Civil Rights (OCR) Director Melanie Fontes Rainer alleging the HIPAA Privacy Rule, which has been in effect for more than two decades, and the 2024 HHS final rule on reproductive healthcare privacy are unlawful and should be vacated. The HHS issued the 2024 final rule – HIPAA Privacy Rule to Support Reproductive Health Care Privacy – on April 22, 2024, to strengthen the privacy protections of the Health Insurance Portability and Accountability Act for lawfully provided reproductive healthcare in response to the overturning of Roe v. Wade. In 1971, a pregnant woman (Roe) brought a class action lawsuit – Roe v. Wade – challenging the constitutionality of a Texas statute that prohibited procuring or attempting an abortion, except when such a procedure was necessary to save the mother’s life. In 1973, the Supreme Court held that the U.S. Constitution protected the right to an abortion prior to the viability...
Data Breaches Reported by VeriSource Services & CBIZ Benefits & Insurance Services
The protected health information (PHI) of more than 112,000 individuals was compromised at VeriSource Services, a website vulnerability was exploited at CBIZ Benefits & Insurance Services affecting 9,100 individuals, and Okanogan Behavioral HealthCare has experienced a breach of the PHI of almost 1,100 individuals. VeriSource Services Confirms Breach of PHI of 112,726 Individuals VeriSource Services, a Houston, TX-based provider of employee benefit administrative and enrollment solutions to employer groups, has confirmed that personal and protected health information (PHI) was stolen in a February cyberattack. On August 20, 2024, VeriSource Services issued notifications to 112,726 individuals about the cyberattack, which was identified on February 28, 2024, when unusual activity was identified within its computer network. Immediate action was taken to secure its systems and prevent further unauthorized access, and third-party cybersecurity experts were engaged to conduct a forensic investigation. The investigation confirmed that there had been unauthorized access to its...
Active Ransomware Groups Increase by 57% as Ransomware Landscape Fragments
There has been a significant increase in the number of ransomware groups conducting attacks, according to Searchlight Cyber. In H1, 2023, Searchlight Cyber identified 46 active ransomware groups from posts to dark web data leak sites, with the number of active groups increasing by 57% in H1, 2024 to 72 active groups. In the first half of 2024, 2,879 organizations have been added to ransomware groups’ data leak sites, which is a 50% increase from H1, 2023, although a 16% decrease from H2, 2023. It is important to note that there was an increase in attacks in the second half of 2023 when the number of victims added to ransomware groups’ data leak sites was at the highest level since ransomware groups started adopting data theft and leak tactics in addition to file encryption. There has been some fluctuation in the most prolific ransomware groups in the first half of the year. LockBit has retained its position as the most active ransomware group, despite efforts by law enforcement to disrupt its operation. At least 434 victims were added to the LockBit data leak site in H1, 2024,...



