Class Action Lawsuit Filed Against Cencora/Lash Group Over Cyberattack
A lawsuit has been filed against Cencora Inc. and The Lash Group LLC over a recently disclosed data breach. The lawsuit, which is likely to be one of many, names Keith Wolford as the plaintiff, and alleges the defendants failed to implement reasonable and appropriate safeguards to ensure the confidentiality of personally identifiable and protected health information. As a result of those failures, patient data has been impermissibly disclosed to cybercriminals. Cencora, a wholesale drug company formerly known as AmerisourceBergen and the parent company of The Lash Group, announced in May 2024 that an unauthorized third party accessed its network and exfiltrated sensitive data. The forensic investigation confirmed that the stolen data included personal and health information such as first names, last names, dates of birth, diagnoses, and/or medications and prescriptions. Notifications were issued to the affected individuals in May 2024 and free credit monitoring and remediation services have been offered for 24 months. Cencora notified the Securities and Exchange Commission (SEC)...
Panorama Eyecare Notifies 377K Individuals a Year After Ransomware Attack
In July 2023, the LockBit ransomware group added Panorama Eyecare to its data leak site and claimed to have exfiltrated 798 GB of data from the Fort Collins, CO-based physician-led management services organization The ransomware group claimed to have obtained data from its clients, including Eye Center of Northern Colorado, Denver Eye Surgeons, Cheyenne Eye Clinic & Surgery Center, and 2020 Vision Center. Panorama Eyecare has now confirmed the attack, a year after the intrusion was first detected. According to the breach notification issued to the Maine Attorney General, the intrusion was detected on June 3, 2023. The letters state that the forensic investigation confirmed that an unauthorized actor had access to its network between May 22, 2023, and June 4, 2023, and that as a result of the cybersecurity incident the attacker “may have accessed and removed certain files from our network environment.” The reason for the delay in issuing HIPAA notification letters was due to the comprehensive review of the impacted files which took until May 9, 2024, to complete. That review...
FBI Urges LockBit Ransomware Victims to Contact IC3; 7,000 Decryption Keys Obtained
The Federal Bureau of Investigation (FBI) is urging victims of LockBit ransomware attacks to get in touch with the Internet Crime Complaint Center (IC3). The FBI has obtained more than 7,000 decryption keys that can be used by past victims to recover from their data breaches for free. At the 2024 Boston Conference on Cyber Security yesterday, FBI Cyber Assistant Director Bryan Vorndran confirmed that the FBI has obtained a significant number of decryption keys from its ongoing efforts to disrupt the LockBit ransomware operation. The FBI was involved in an international law enforcement operation – Operation Cronos – headed by the UK National Crime Agency that resulted in 34 servers being seized and more than 2,500 decryption keys being obtained. The FBI was able to create a free decryptor to allow victims to recover their files for free, with more obtained from its ongoing operation against the group. The FBI has also been able to confirm that LockBit ransomware-as-a-service (RaaS) operation was set up by a Russian coder named Dimitri Khoroshev, aka LockBitsupp, who has now been...
Is OneDrive HIPAA Compliant?
Microsoft OneDrive is HIPAA compliant provided covered entities subscribe to a plan that supports OneDrive HIPAA compliance, agree to the terms of Microsoft’s Business Associate (Data Protection) Addendum, and configure the file storage service to be used in compliance with HIPAA. Microsoft OneDrive is a convenient file storage service that facilitates document sharing and collaboration. Many healthcare organizations subscribe to a Microsoft or Office 365 business plan that includes OneDrive; and, when the file storage service is used for administrative and operational purposes that do not involve disclosures of Protected Health Information (PHI), HIPAA compliance is not an issue. However, when the service is used to store and share files that contain PHI, it is important OneDrive is HIPAA compliant. This means that the Microsoft or Office 365 business plan must include the capabilities to support HIPAA compliance, and that the capabilities are configured to ensure OneDrive is used in compliance with HIPAA. It is also important a Business Associate Agreement is in place....
HHS Must Take Immediate Action to Improve Cybersecurity at Large Healthcare Organizations
Senate Finance Committee chair, Senator Ron Wyden (D-OR) wrote to Department of Health and Human Services (HHS) Secretary Xavier Becerra this week calling for immediate action against large healthcare companies to ensure they improve their cybersecurity practices. “The current epidemic of successful cyberattacks against the health care sector is a direct result of HHS’s failure to appropriately regulate and oversee this industry,” said Sen. Wyden. This year has seen major cyberattacks on large healthcare organizations including Change Healthcare and Ascension that have caused massive disruption to healthcare services across the United States. The attacks have disrupted patient care and caused actual harm to patients, and a huge amount of highly sensitive patient data has been stolen and is now in the hands of cybercriminals putting them at risk of identity theft and fraud. Change Healthcare, part of UnitedHealth Group (UHG), is the largest healthcare company in the United States, yet a hacker gained access to its internal network due to lax cybersecurity practices. The hacker used...



