Is Freshworks Helpdesk HIPAA Compliant?
Freshworks Helpdesk is HIPAA compliant and can be used to create, receive, store, or transmit Protected Health Information, but only if an organization subscribes to an Enterprise plan and complies with Freshworks’ mandatory configuration specifications. It will also be necessary to implement a “secure operating environment” if utilizing the Freshchat capability. Freshworks Helpdesk (aka Freshdesk) is an advanced customer service solution that accelerates the resolution of customer issues via automated keyword routing and ticket prioritization. The platform also supports collaboration between team members and external agents, and provides AI-powered sentiment and resolution analyses to monitor – and improve – team performance. When the Freshworks Helpdesk is used by a HIPAA covered entity or business associate to create, receive, store, or transmit Protected Health Information (PHI), it is important the platform has the capabilities to support HIPAA compliance, that the capabilities are configured to safeguard the privacy and security of PHI, and that customer service team members...
92% Of U.S. Healthcare Organizations Experienced a Cyberattack in the Past Year
Virtually all healthcare organizations have experienced at least one cyberattack in the past 12 months, according to a recent survey by the Ponemon Institute on behalf of Proofpoint. The survey was conducted on 648 IT/IT Security professionals at U.S. healthcare organizations and 92% said they had experienced at least one cyberattack in the past year, up from 88% of respondents in 2023. This year, out of the healthcare organizations that experienced a cyberattack, the average number of attacks was 40, although many, but not all, were halted before they escalated. 69% of respondents said at least one cyberattack disrupted patient care, 56% of respondents said they experienced poor patient outcomes due to delays in procedures and tests, 53% experienced an increase in medical procedure complications, and 28% said the patient mortality rate increased. Cyberattacks are proving incredibly costly for healthcare organizations. Respondents were asked about the single most expensive attack they experienced. Including all direct cash outlays, direct labor expenses, indirect labor costs,...
Muskogee City County Enhanced 911 Trust Authority & PRC-Saltillo Announce Data Breaches
Muskogee City County Enhanced 911 Trust Authority (MCC911) in Oklahoma has suffered a major data breach involving the protected health information of up to 180,000 individuals. The attack was detected on July 25, 2024, when unusual was detected within its network indicative of a ransomware attack. MCC911 took immediate action to contain the attack and prevent further unauthorized access to its systems and cybersecurity professionals were engaged to investigate the incident, determine how network access was gained, and confirm the scope of the incident. The investigation confirmed that a ransomware group had access to certain parts of its network between April 4, 2024, and July 31, 2024, during which time patient data may have been exfiltrated from its network. A file review was conducted that confirmed names, addresses, dates of birth, Social Security numbers, diagnoses/conditions, medication/treatment information, medical procedures, hospital provider names, and health insurance information had been exposed. The types of data involved varied from individual to individual and the...
Supreme Court Declines to Hear Biden Administration’s Challenge in Texas Emergency Abortion Dispute
The Supreme Court has declined to hear the Biden Administration’s appeal that sought to overturn the decision of a lower court regarding emergency abortion care in Texas. The lower court ruled that the federal Emergency Medical Treatment and Labor Act (EMTALA) does not trump the abortion ban in Texas, and that decision still stands. Since the Supreme Court overturned Roe v. Wade, many states, including Texas, have introduced bans on abortions. Texas has some of the strictest laws in the country, prohibiting almost all abortions in the state. While Texas does have exceptions, such as allowing abortions to be legally provided to save the life of a mother or to prevent substantial impairment of major bodily function, the wording of the exceptions is such that life-threatening or harmful pregnancies are not necessarily excepted. Doctors in the state have said that abortions can only be provided when the life of a mother is clearly at risk, not when there is a risk of the mother losing her reproductive ability. Should an abortion be provided in the state when the mother is at risk of...
HHS Issues Warning About Trinity Ransomware Following Healthcare Attacks
The Health Sector Cybersecurity Coordination Center (HC3) has shared information on the Trinity Ransomware group, a relatively new threat actor that emerged in May 2024 that has conducted at least two attacks on healthcare providers, one in the United States and one in the United Kingdom. The UK victim is a cosmetic dentistry practice in Jersey, and the U.S. victim is a provider of gastroenterology services. Trinity claims to have stolen 330 GB of data in the attack on Rocky Mountain Gastroenterology. Since the group has conducted at least two attacks on healthcare companies out of ten known attacks, the group is considered to pose a significant threat to the U.S. healthcare sector. Like many other ransomware actors, Trinity ransomware engages in double extortion, stealing data before encrypting files. Victims are told to pay the ransom to obtain the decryption keys and prevent the publication of the stolen data on its dark web data leak site. Victims are given 24 hours to make contact, or they will be added to the group’s data leak site. If the ransom is not paid within the...



