White House Reviewing Proposed HIPAA Security Rule Update
In December 2023, the Department of Health and Human Services published its Healthcare Sector Cybersecurity Strategy, which outlined the steps that the HHS was planning to take to improve cybersecurity across the healthcare sector. The strategy included voluntary cybersecurity performance goals, which were published in January 2024, but voluntary goals alone were not believed to be sufficient to drive the cyber-related behavioral change that is needed across the healthcare sector. Consequently, HHS also planned an update to the Security Standards for the Protection of Electronic Protected Health Information (HIPAA Security Rule) to incorporate new cybersecurity requirements for HIPAA-regulated entities. The update was expected to be completed by Spring 2024; however, it was delayed. OCR Director Melanie Fontes Rainer confirmed earlier this year that work was underway on the update and that it should be released before the end of the year. The proposed update to the HIPAA Security Rule has now been completed and was passed to the Office of Information and Regulatory Affairs at the...
More Than 909,000 Individuals Affected by Cyberattack on New York IT Services Provider
ATSG Inc., an IT services company headquartered in New York, has recently reported a September 2024 data breach to the Department of Health and Human Services (HHS) Office for Civil Rights (OCR) that involved the protected health information of 909,469 individuals. The breach was reported as a hacking/IT incident involving unauthorized access to a network server. It is currently unclear how many ATSG clients were affected, but one was Boston Children’s Health Physicians. Boston Children’s Health Physicians recently confirmed that it had fallen victim to a cyberattack through its IT vendor and said sensitive data was stolen in the attack. Boston Children’s Health Physicians has only released limited information about the attack and data breach at this stage but has confirmed that it was one of several clients of the IT vendor to be affected. Boston Children’s Health Physicians chose to issue its own notifications to the affected patients, which were sent around a month after the attack occurred. The BianLian threat group claimed responsibility for the attack and added Boston...
FortiManager Zero-Day Has Been Exploited Since July 2024
A zero-day vulnerability in Fortinet’s FortiManager appliances is being mass exploited by at least one threat actor. The first known instance of exploitation was on June 27, 2024. The critical vulnerability is tracked as CVE-2024-47575 has been assigned a CVSS v3.1 severity score of 9.8. The vulnerability, dubbed FortiJump by security researcher Kevin Beaumont, is due to missing authentication for a critical function in the FortiManager fgfmd daemon and allows an unauthenticated attacker to use a FortiManager device to execute arbitrary code or commands against vulnerable FortiManager devices. In order to successfully exploit the vulnerability, an attacker requires a valid Fortinet device certificate. The certificate could be obtained from an existing Fortinet device and could be reused for multiple attacks. According to Fortinet, attacks exploiting the vulnerability have involved an automated script that exfiltrates files from FortiManager. Those files contain IP addresses, credentials, and device configurations. So far, Fortinet has not detected any modified databases or...
Two Men Indicted for Role in February 2024 Cyberattack on Cedars-Sinai
Two Sudanese nationals have been charged for their role in a series of cyberattacks on corporate networks, government agencies, and critical infrastructure entities in the United States, including a February 2024 attack on Cedars-Sinai Medical Center in Los Angeles that caused patients to be diverted to alternative facilities for 8 hours. The two men – Ahmed Salah Yousif Omer, 22, and Alaa Salah Yusuuf Omer, 27 – are alleged members of an online cybercriminal group called Anonymous Sudan, a group that has been active since mid-January 2023 and has conducted more than 35,000 distributed denial-of-service (DDoS) attacks worldwide. While many cybercriminal groups are primarily financially motivated, Anonymous Sudan claims to be a hacktivist group that conducts attacks against targets it considers to be anti-muslim, in part in support of Palestine, although the group has attempted to extort money from some victims. Due to the sophistication of the group’s attacks and the financial resources required, there have been suggestions that the group has significant backing, and...
Patient Data Compromised in Email Breaches in Indiana, New York & Wisconsin
Email accounts have been compromised in security incidents at Tower Clock Eye Center in Wisconsin, DMEScripts in Indiana, and General Physician, P.C. in New York. Tower Clock Eye Center Tower Clock Eye Center in Green Bay, Wisconsin, has identified unauthorized activity in its email system. A security breach was detected on July 9, 2024, and action was taken to prevent further unauthorized access. Third-party cybersecurity experts were engaged to investigate and determine the extent of the unauthorized activity. The investigation confirmed that a limited number of employee email accounts had been accessed by an unauthorized third party who may have viewed or obtained patient data. The breach was confined to email accounts, which were found to contain limited patient data. The types of data involved varied from individual to individual and may have included names in combination with one or more of the following: address, date of birth, financial account number, payment card number, medical record number, patient ID or account number, Medicare number, Medicaid number, health...



