Cyberattack on Help at Home Affects 26,700 Current & Former Patients
Data breaches have been reported by Help at Home, Kinsler Family Dentistry, ParkTree Community Health Center, and Providence Pediatrics Manito. Help at Home HAH Group Holding Company, a home healthcare provider that does business as Help at Home, has discovered the protected health information of 26,744 individuals has been exposed at one of its vendors. The vendor notified Help at Home about the intrusion on March 21, 2021; however, at the time, it was unclear to what extent personal information was involved. The unnamed former vendor conducted a review of the affected data and confirmed on June 19, 2024, that the information exposed and potentially stolen in the incident included names, dates of birth, Social Security numbers, financial account numbers, usernames and passwords, and/or certain medical, health insurance, and/or treatment information. HAH Group Holding Company mailed individual notifications on August 16, 2024, and has offered complimentary credit monitoring services. Kinsler Family Dentistry Kinsler Family Dentistry, the Frankfort, IN, dental practice of Julie D....
Karakurt Ransomware Group Member Charged in Ohio
An alleged member of the Karakurt threat group has been charged in U.S. District Court in Cincinnati with conspiracy to commit money laundering, wire fraud, and Hobbs Act extortion. Karakurt is a Russian cybercrime group thought to be a splinter group of the now-defunct Conti ransomware group. Karakurt specializes in data extortion rather than ransomware attacks, and gains access to corporate networks, steals sensitive data, and threatens to sell the stolen data if the ransom is not paid. The group maintains an auction site and if a sale cannot be arranged, the stolen data is added to the group’s data leak site where it can be downloaded for free. The group’s ransom demands have ranged from $25,000 to $13,000,000, with victims typically given a week from notification to pay the ransom. Karakurt has conducted attacks on a wide range of industry sectors, including several U.S. healthcare organizations. The group has claimed responsibility for attacks on CentroMed, Methodist McKinney Hospital, McAlester Regional Health Center, The Chattanooga Heart Institute, and most recently, Ann...
Healthcare Sector Warned About Everest Ransomware Group
The Health Sector Cybersecurity Coordination Center has issued a threat profile of the Everest Ransomware group, which was behind the recent ransomware attack on Gramercy Surgery Center in New York. The group has also claimed responsibility for attacks on Horizon View Medical Center in Las Vegas, 2K Dental in Ohio, Prime Imaging in Tennessee, and Stages Pediatric Care in Florida, and has increasingly been targeting the healthcare and public health (HPH) sector since 2021. The group has added more than 120 victims to its data leak site, around 34% of which are located in the United States, and around 27% of U.S. victims are in the healthcare industry. Between April 2021 and July 2024, the group conducted at least 20 attacks on healthcare organizations, disproportionately targeting medical imaging providers. The Everest ransomware group was first identified in December 2020 and rapidly became well-known within the cybercrime community after conducting attacks on high-profile targets including the Brazilian government and NASA. The group uses double extortion tactics, where ransomware...
Breaches of Patient Confidentiality
Breaches of patient confidentiality – defined as disclosures of private information without the patient’s consent – occur more often than most people are aware of due to blind spots in reporting requirements and “information breaches of patients” – which are permitted by the HIPAA Privacy Rule and required by law in some states. Although HHS’ Office for Civil Rights publishes an annual report which includes the total number of breach notifications it receives each year, it is impossible to accurately calculate how many breaches of patient confidentiality occur each year because of reporting failures, notifications that should be retracted, and reports made “in an abundance of caution”. In addition, there are inconsistent interpretations of the HIPAA breach notification requirements, and occasions when information breaches of patients are permitted by HIPAA. It is also the case that some healthcare providers do not qualify as HIPAA covered entities, and breaches of patient confidentiality in their organizations are subject to state notification laws. Reported Breaches of...
Welltok Data Breach Victim Count Rises to 14.76 Million
More than 14.7 million individuals are now known to have been affected by the 2023 MOVEit Transfer data breach at the Denver-based patient engagement company Welltok, which makes it the second-largest healthcare data breach to be reported to the HHS’ Office for Civil Rights (OCR) by a HIPAA-regulated entity to date. While recompiling our healthcare data breach statistics this month, we found that the number of individuals affected by healthcare data breaches in 2023 had increased considerably. Currently, the OCR breach portal lists 744 healthcare data breaches in 2023 and 160,009,510 affected individuals. The massive increase was due to an updated figure for the Welltok data breach, which was previously listed as affecting 8,493,379 individuals. The Welltok data breach is now listed as affecting 14,762,475 individuals, with the update occurring at some point after April 2024. The substitute breach notice indicates at least 165 of its healthcare clients were affected. Welltok was the victim of a global cyberattack by the Clop group, which exploited a zero-day vulnerability in...



