Warning Issued to HPH Sector About Qilin Ransomware Group
A warning has been issued to the healthcare and public health (HPH) sector about the Qilin ransomware group, which is known to attack healthcare organizations due to their reliance on uptime and the sensitivity of the data they hold. Around 7% of the ransomware attacks conducted by the group have been on healthcare organizations. One of the most recent attacks has caused massive disruption to healthcare services in London. The group attacked a National Health Service (NHS) pathology vendor (Synnovis), which manages blood tests for NHS trusts and GP offices in south-east London. The attack did not directly affect any NHS hospitals as it was confined to Synnovis systems, but it has caused massive disruption with thousands of NHS surgeries and appointments canceled, and blood testing services have been reduced to around 10% of normal levels. The attack has caused major problems with blood matching, leading to a shortage of O-positive and O-negative blood. Synnovis expects the recovery to take weeks and anticipates a full recovery will take several months. Qilin is a...
May 2024 Healthcare Data Breach Report
There has been a fall in the number of reported healthcare data breaches for the second consecutive month to the lowest monthly total since October 2023. In May, 51 data breaches of 500 or more healthcare records were reported to the Department of Health and Human Services Office for Civil Rights (OCR), well below the 12-month average of 65 large data breaches a month. Such a low total has not been seen in May since 2020, with reported breaches down 7.3% from the previous month and 33.8% from May 2023. While there has been a reduction in reported data breaches, they are still up by 22% for the year. 333 data breaches of 500 or more records were reported to OCR between January 1, 2024, and May 31, 2024. , compared to 273 for the corresponding period last year. The average breach size in 2024 is 123,785 records and the median data breach size is 3,716 records. Across those 333 data breaches, the records of 41,220,380 individuals have been exposed or stolen. Even with two massive data breaches of 2.8 million and 2.5 million records in May, there was a fall in the number of breached...
Texas Judge Vacates OCR’s Website Tracking Technology Guidance
On Thursday, a federal judge in Texas ruled that the guidance issued by the HHS’ Office for Civil Rights on website tracking technologies was unlawful, ruling that OCR overstepped its authority when it issued the guidance. The judge ruled that metadata collected from an unauthenticated web page does not qualify as individually identifiable health information when combined with an IP address. In 2022, the extent to which hospitals and health systems used tracking technologies became clear and OCR responded by issuing guidance on HIPAA and website tracking technologies in December 2022. These technologies, which include Meta Pixel code, are added to websites and provide beneficial functions; however, they also collect data on website users and transfer that information to third parties. The information collected may reveal diagnoses, reasons for appointments, health concerns, and other potentially sensitive information that can be tied to individuals by identifiers such as IP addresses. In the case of Meta pixel code, collected data is sent to Meta (Facebook) and may be made...
Sav-Rx Sued Over 2.8 Million-record Data Breach
A class action lawsuit has been filed against A&A Services, a medication benefits management service provider that operates as Sav-Rx, over a data breach in October 2023 that affected 2.8 million individuals. On or around October 3, 2023, hackers accessed the Sav-Rx network and exfiltrated files containing the protected health information of employees and clients’ health plan members. The breach was detected on October 8, 2023, and the file review confirmed names, contact information, dates of birth, and Social Security numbers had been stolen. Sav-Rx said it was provided with the final results of its file review on April 30, 2024, and the affected individuals were notified about the breach on May 10, 2024, and were offered complimentary credit monitoring and identity theft protection services. On June 5, 2024, a class action lawsuit was filed in the U.S. District Court for the District of Nebraska by Rodney Hill, whose protected health information was compromised in the cyberattack. The lawsuit alleges the defendant failed to implement reasonable and appropriate cybersecurity...
PHI Compromised in Cyberattacks on South Texas Oncology and Hematology & Highland Health Systems
Patients and employees have been notified about cyberattacks and data breaches at South Texas Oncology and Hematology in Texas and Highland Health Systems in Alabama. South Texas Oncology and Hematology Cyberattack Affects 175,195 Patients South Texas Oncology and Hematology (STOH), a cancer treatment center in San Antonio, TX, has notified 176,303 individuals about a cybersecurity incident detected on February 15, 2024. Upon discovery of the security breach, the network was disconnected, and a third-party cybersecurity firm was engaged to assist with securing its systems and conducted a forensic analysis to determine the nature and scope of the incident. On February 19, 2024, STOH confirmed that an unauthorized individual had access to parts of its network containing the personal information of employees and the protected health information of current and former patients, and those files may have been acquired in the attack. The files are currently being reviewed and are likely to include names and medical information, although other types of information may also have been...



