Health-ISAC/AHA Issue Warning Following Ransomware Attacks on Mission-Critical Suppliers
Health-ISAC and the American Hospital Association (AHA) have issued a joint threat bulletin following three ransomware attacks by Russian ransomware groups on blood suppliers, which have caused shortages of blood and blood products that have massively disrupted patient care. The most recent attack occurred on July 30, 2024, on OneBlood, a Florida-based provider of blood to around 250 hospitals in Alabama, Florida, Georgia, and North and South Carolina. The attack prompted the Florida Hospital Association to recommend hospitals that receive blood from OneBlood activate their critical blood shortage protocols. The RansomHub threat group is thought to have been behind the attack. In early June, the Qilin ransomware group conducted an attack on Synovis, a provider of pathology services to the UK’s National Health Service, which caused massive disruption with more than 800 operations and 700 outpatient appointments canceled. The attack resulted in major blood shortages, with O-negative and O-positive blood donations destroyed as it was not possible to match them to electronic health...
Ransomware Group Targets IT Workers by Impersonating Legitimate Scanning Tool
The Hunters International threat group is targeting IT workers by impersonating a legitimate IP and port scanning tool to deliver malware to gain initial access to networks. Hunters International is a ransomware group that first emerged in October 2023. The group has been linked with the Hive ransomware group, which was the subject of a law enforcement operation and shut down in January 2023. While security researchers have suggested Hunters International was a rebrand of Hive due to a 60% code overlap with Hive, the group claims to have purchased the Hive code and that it is an independent group. Hunter’s International is not the most prolific ransomware group but has conducted more than 130 attacks so far this year. As the group’s name suggests, attacks are conducted worldwide, with the threat actor claiming victims in around 30 countries. The group primarily hunts for data, which is exfiltrated from victims’ networks. Threats are issued to publish the stolen data if a ransom is not paid, with the attacks often including file encryption. Hunters International poses a significant...
What is an NPI in Healthcare?
An NPI in healthcare is a ten-digit numeric National Provider Identifier issued by the Centers for Medicare and Medicaid Services (CMS) that must be used by HIPAA covered healthcare providers in all Part 162 transactions. In certain circumstances, an NPI in healthcare can also be issued to healthcare providers who are not covered by HIPAA. Prior to the passage of HIPAA, healthcare providers used a variety of codes to identify themselves in healthcare transactions (eligibility checks, authorization requests, claims and billing, etc.). The codes could be in different formats and of differing lengths depending on the type(s) of healthcare services being provided, industry standards, and/or the requirements of the paying entity. In 1993, the Health Care Financing Administration (now the CMS) undertook the task of replacing the COBRA-mandated Unique Physician Identification Number (UPIN) with a new identification system for all healthcare providers participating in the Medicare and Medicaid programs. The outcome was an eight-digit alphanumeric identifier that distinguished between...
Franklin County, Kansas Falls Victim to Ransomware Attack
Franklin County, Kansas recently fell victim to a ransomware attack that involved the theft of protected health information stored on its network. The attack was detected on May 20, 2024, and a nationally recognized digital forensics firm was engaged to assist with securing its network and investigating the incident. The investigation confirmed that on May 19, 2024, data had been exfiltrated, including the protected health information of individuals who had previously received services from the County Health Department and the County Adult Detention Center. The investigation and document review are ongoing, so it is currently unclear how many individuals have been affected. The breach has been reported to the HHS’ Office for Civil Rights as affecting at least 501 individuals. The total will be updated when the investigation and document review have been finished. Franklin County officials have confirmed that the compromised data includes names, addresses, Social Security numbers, dates of birth, diagnosis information, treatment information, medical record numbers, vaccination...
Rhysida Threat Group Auctions Data Stolen in City of Columbus Ransomware Attack
The City of Columbus in Franklin County, Ohio, recently fell victim to a ransomware attack that involved the theft of information stored on its network. The attack was detected on July 18, 2024, and the foreign threat actor attempted to deploy ransomware to encrypt files and solicit a ransom payment. The fast action of the Department of Technology limited exposure, which included severing the internet connection to prevent further unauthorized access, and the actions of the Department of Technology were successful in disrupting the threat actor’s activity. The threat actor was identified and information about the attack was shared with the Federal Bureau of Investigation (FBI) and the Department of Homeland Security. The city is working with those agencies and cybersecurity experts and is implementing additional safeguards to harden security to prevent similar attacks in the future. The investigation into the incident is ongoing, the city is in the process of issuing notifications to the affected individuals. Initially, it was thought that access was gained after an employee...



