What is an NPI in Healthcare?
An NPI in healthcare is a ten-digit numeric National Provider Identifier issued by the Centers for Medicare and Medicaid Services (CMS) that must be used by HIPAA covered healthcare providers in all Part 162 transactions. In certain circumstances, an NPI in healthcare can also be issued to healthcare providers who are not covered by HIPAA. Prior to the passage of HIPAA, healthcare providers used a variety of codes to identify themselves in healthcare transactions (eligibility checks, authorization requests, claims and billing, etc.). The codes could be in different formats and of differing lengths depending on the type(s) of healthcare services being provided, industry standards, and/or the requirements of the paying entity. In 1993, the Health Care Financing Administration (now the CMS) undertook the task of replacing the COBRA-mandated Unique Physician Identification Number (UPIN) with a new identification system for all healthcare providers participating in the Medicare and Medicaid programs. The outcome was an eight-digit alphanumeric identifier that distinguished between...
Franklin County, Kansas Falls Victim to Ransomware Attack
Franklin County, Kansas recently fell victim to a ransomware attack that involved the theft of protected health information stored on its network. The attack was detected on May 20, 2024, and a nationally recognized digital forensics firm was engaged to assist with securing its network and investigating the incident. The investigation confirmed that on May 19, 2024, data had been exfiltrated, including the protected health information of individuals who had previously received services from the County Health Department and the County Adult Detention Center. The investigation and document review are ongoing, so it is currently unclear how many individuals have been affected. The breach has been reported to the HHS’ Office for Civil Rights as affecting at least 501 individuals. The total will be updated when the investigation and document review have been finished. Franklin County officials have confirmed that the compromised data includes names, addresses, Social Security numbers, dates of birth, diagnosis information, treatment information, medical record numbers, vaccination...
Rhysida Threat Group Auctions Data Stolen in City of Columbus Ransomware Attack
The City of Columbus in Franklin County, Ohio, recently fell victim to a ransomware attack that involved the theft of information stored on its network. The attack was detected on July 18, 2024, and the foreign threat actor attempted to deploy ransomware to encrypt files and solicit a ransom payment. The fast action of the Department of Technology limited exposure, which included severing the internet connection to prevent further unauthorized access, and the actions of the Department of Technology were successful in disrupting the threat actor’s activity. The threat actor was identified and information about the attack was shared with the Federal Bureau of Investigation (FBI) and the Department of Homeland Security. The city is working with those agencies and cybersecurity experts and is implementing additional safeguards to harden security to prevent similar attacks in the future. The investigation into the incident is ongoing, the city is in the process of issuing notifications to the affected individuals. Initially, it was thought that access was gained after an employee...
Arisa Health Confirms Data Breach Affected More Than 375,000 Patients
Arisa Health Incorporated in Arkansas has experienced a breach of the protected health information of 375,436 individuals. Cyberattacks and data breaches have also been reported by Sun City Pediatrics in Texas and Calibrated Healthcare in California. Arisa Health Incorporated Arisa Health Incorporated, an Arkansas-based integrated behavioral health system, has started notifying hundreds of thousands of patients about a recent cyberattack. The attack was detected on or around March 18, 2024, when connectivity to its network was disrupted. The forensic investigation confirmed that unauthorized individuals had access to its network between March 1, 2024, and March 18, 2024, and there may have been unauthorized access to files containing sensitive patient data. Those files may also have been exfiltrated from the network in the attack. The review of those files confirmed that the following data had been exposed: full names, addresses, email addresses, dates of birth, Social Security numbers, medical record numbers, health insurance numbers/Member IDs, certification of substance abuse...
Almost Three-quarters of Ransomware Victims Hit Multiple Times
A recent study conducted by the cybersecurity firm Semperis has revealed that companies are often targeted by ransomware groups multiple times, with almost three-quarters (74%) of companies that experienced a ransomware attack saying they had been attacked multiple times. These attacks caused disruption at 87% of attacked companies, 37% reported suffering data loss and 33% of companies said they had to take all of their systems offline. In healthcare, 40% suffered data loss and 29% had to take all of their systems offline. Companies in the United States and the United Kingdom were most likely to have experienced a ransomware attack, with 85% of surveyed companies in those countries suffering at least one ransomware attack in the past 12 months. The industries with the highest number of attacks were finance and healthcare, with 88% and 85% of respondents in those sectors saying they had experienced a ransomware attack in the past 12 months. Initial attacks were most successful in education and healthcare, with healthcare organizations the most likely to suffer multiple simultaneous...



