Numotion Ransomware Attack Affects More Than 602,000 Individuals
United Seating and Mobility, L.L.C., a provider of wheelchair and mobility equipment that does business as Numotion, discovered on March 2, 2024, that an unauthorized third party had access to its computer systems and used ransomware to encrypt files. Immediate action was taken to secure its systems and prevent further unauthorized access and a third-party cybersecurity company was engaged to conduct a forensic investigation to determine the scope of the unauthorized activity. Forensic investigations often take several weeks before it is confirmed that hackers accessed or acquired files containing sensitive data; however, two days after the attack on March 4, 2024, Numotion verified that the unauthorized third party had access to its systems from February 29, 2024, to March 2, 2024, and may have acquired sensitive data such as names, dates of birth, equipment order details, supporting medical documentation, and medical insurance information. A subset of the affected individuals also had their Social Security numbers and/or driver’s license numbers exposed. The breach notice...
Texas Children’s Hospital Whistleblower Doctor Indicted on Four Counts of Criminal HIPAA Violations
A doctor who provided documents to a reporter confirming Texas Children’s Hospital was providing gender-affirming care to minors after making public statements that the care would cease has been indicted by the Department of Justice on four counts of criminally violating the Health Insurance Portability and Accountability Act (HIPAA). Texas Children’s Hospital in Houston, the largest children’s hospital in the United States, announced in March 2022 that hormone-related prescription therapies for gender-affirming care would no longer be provided to minors due to potential legal and criminal liability, following Texas Governor Greg Abbott’s threat of legal action against the hospital. In May 2023, The City Journal published an article alleging the hospital was still providing that care and had not followed through on its public claim that the procedures would no longer be provided. Reporter Christopher F. Rulo had been provided with documents from a whistleblower that confirmed medical interventions continued to be provided to transgender children, including implanted puberty...
Cyberattacks Reported by Medjet; Angels Neurological Centers; Native American Health Center
Cyberattacks and data breaches have been reported by Medjet/MedjetAssist in Alabama, Native American Health Center in California, and Angels Neurological Centers in Massachusetts. Medjet/MedjetAssist Medjet and MedjetAssist (Medjet), a Birmingham, AL-based air medical transport and travel security membership program, has announced that a threat actor installed malware on its network that rendered certain systems unavailable. The attack was detected on October 17, 2023, and the forensic investigation confirmed on December 5, 2023, that the threat actor may have acquired files from the network during the period of access. A review was conducted to determine which files may have been copied from its systems, and that process was completed on or around May 10, 2024. The exposed information included names, addresses, and Social Security numbers. Medjet said it is unaware of any actual or attempted misuse of client information at the time of issuing notifications. Notification letters started to be sent on January 5, 2024; however, as the investigation progressed it became clear that...
HHS-OIG Report to Congress Highlights Achievements in Tackling Fraud, Waste, and Abuse
The Department of Health and Human Services Office of Inspector General (HHS-OIG) has published its semi-annual report to Congress detailing HHS-OIG’s accomplishments in tackling fraud, waste, and abuse and promoting the economy, efficiency, and effectiveness of HHS programs. Over the 6 months between October 1, 2023, and March 31, 2024, HHS-OIG’s enforcement efforts resulted in 712 civil and criminal actions, $2,76 billion in expected recoveries and receivables, and 1,795 bad actors were added to the HHS-OIG exclusion list, removing them from federally funded programs. The latter includes the owner of a medical supply company who was excluded from federal programs for at least 23 years after being convicted of conspiracy to commit health care fraud in a medically unnecessary durable medical equipment scheme. Two of the most egregious cases investigated by HHS-OIG defrauded Medicare out of more than $203 million. A Florida nurse practitioner fraudulently billed Medicare for genetic testing and medical equipment that the Medicare beneficiaries did not need in a $192 million...
Designed Receivable Solutions Sued Over 500M-Record Data Breach
Designed Receivable Solutions, a Cypress, CA-based revenue cycle management company, is facing a class action lawsuit over a data breach that affected almost half a million individuals. The intrusion was detected on January 22, 2024, and it was confirmed on March 8, 2024, that sensitive data had been exfiltrated in the attack, including the data provided by at least 17 of its clients. According to the notifications sent to the HHS’ Office for Civil Rights, the protected health information of 498,686 individuals was exposed or stolen in the attack, including names, addresses, dates of birth, health insurance information, dates of service, and Social Security numbers. The lawsuit alleges that the data breach was preventable and would have been prevented if Designed Receivable Solutions had implemented reasonable and appropriate cybersecurity measures. As a result of that failure, the personal and protected health information of more than 498,000 individuals is now in the hands of malicious actors who conducted the attack for financial gain, and those individuals now face an...



