Ransomware Attack Severity Increased 68% in H1, 2024
The use of ransomware in cyberattacks decreased slightly in the first half of the year; however, the severity of ransomware attacks increased according to the 2024 Cyber Claims Report: Mid-Year Update from cyber insurance and security service provider Coalition. For the report, Coalition examined claims against cyber insurance policies between January 1, 2024, and June 30, 2024. Claims by businesses with less than $25 million in revenue fell by 4% to an average of $73,000 per incident but claim amounts increased for all other businesses. Claims by businesses with revenues between $25 million and $100 million increased by 23%, with average losses of $129,000 per incident and there was a 140% increase in losses at businesses with $100 million or more in revenue, with average losses rising to a record high of $307,000 per incident. While there was an overall increase of 14% in claims severity in H1, 2024, largely driven by the increase in ransomware attack severity, Coalition saw the lowest frequency of claims since H2, 2022. There was a slight reduction in ransomware-related claims...
LinkedIn, Meta, and Healthcare Companies Sued for Using Tracking Tools
Lawsuits have recently been filed against the professional networking platform LinkedIn, Meta (Facebook), and three healthcare companies over the use of website tracking tools on websites that collect sensitive health information and use that information for marketing and advertising purposes. Social media companies provide website tracking tools that collect visitor data from web pages for advertising and marketing purposes. LinkedIn’s tool, LinkedIn Insight Tag, is a code snippet (pixel) that can be added to a website to help the website owner optimize their marketing campaigns, retarget website visitors with advertisements as they browse the Internet, and collect information about their audiences. Similar tracking code is provided by Meta – the Meta Pixel code snippet. Both social media companies have been named as co-defendants in the lawsuits along with the healthcare companies that use the code. When these code snippets are added to a healthcare web page, there is a risk that they will collect sensitive PHI. The lawsuits allege that the healthcare companies, LinkedIn,...
Presbyterian Healthcare Services & ORM Fertility Patients Affected by Data Breaches
Oregon Reproductive Medicine, doing business as ORM Fertility, has announced a security breach that impacted certain computer systems and caused network disruption. The security breach was detected on or around August 27, 2024, and the forensic investigation confirmed unauthorized access to its network between August 26, 2024, and August 27, 2024. ORM Fertility said there was no unauthorized access to its electronic medical records (EMR), email, or customer relationship management system (CRM), and financial and insurance information was not exposed. The review of the affected files is ongoing; however, it appears that only limited patient data was exposed, such as names and lab data. The exact data types will be confirmed when the file review is concluded. The security incident prompted ORM Fertility to implement additional security measures and security will continue to be monitored and enhanced to prevent similar incidents from occurring in the future. In its October 25, 2024 website notification, ORM Fertility said it is unaware of any misuse of the affected data, but as a...
Why is HIPAA Important to Patients?
HIPAA is important for patients because it provides a federal floor of privacy and security standards for their health data, requires covered entities to notify them if their data is accessed or disclosed impermissibly, and enables them to take more control over how their data is used. However, some patients misunderstand which organizations are required to comply with the Health Insurance Portability and Accountability Act (HIPAA). The Health Insurance Portability and Accountability Act The Health Insurance Portability and Accountability Act of 1996 – or HIPAA – is a federal law that applies to healthcare providers, health plans, and healthcare clearinghouses that conduct certain healthcare transactions electronically (i.e., eligibility checks, treatment authorizations, payment claims, etc.). HIPAA also applies to vendors – business associates – that perform functions on behalf of HIPAA-covered entities that requires them to have access to protected health information (PHI) or be provided with copies of PHI. (See What is Protected Health Information). Originally, HIPAA was...
HIPAA Guidelines for Nursing Students
The HIPAA guidelines for nursing students are that nursing students should understand what HIPAA is and what it protects to ensure HIPAA compliance training provided by an employer is better understood and better absorbed. Because student training can take many years to complete, it is also advisable for nursing students to undertake periodic refresher training. The nursing profession is not easy; and, when nursing students start on their career path, there is a lot to take in. In addition to learning the skills of their profession and completing years of coursework, nursing students are frequently asked to assist with the provision of healthcare. Although they are most usually supervised when working with patients, the risk exists that – without an understanding of HIPAA – violations of HIPAA could occur due to a lack of knowledge. For example, if a nursing student shares the events of the day with friends via social media, it is important the student has been trained on what constitutes PHI, when it can be disclosed, and the penalties for disclosing PHI without consent. If the...



