Cyberattack on Minnesota Radiology Practice Affects 584,000 Patients
The Edina, Minnesota-based radiology services company, Consulting Radiologists, has started sending individual notifications to the 583,824 patients affected by a February 2024 cyberattack. Consulting Radiologists provides teleradiology-based interpretation services to more than 100 healthcare facilities in Minnesota. On February 12, 2024, suspicious activity was identified within its computer network and action was immediately taken to secure its systems and prevent any further unauthorized access. A third-party cybersecurity company was engaged to investigate the incident and confirmed that there had been an intrusion and an unauthorized third party accessed a server that contained patient data. Consulting Radiologists said it conducted a time-consuming and detailed reconstruction of the server to determine which patients had been affected and the types of data involved. The review confirmed on April 17, 2024, that patient data had been exposed and potentially acquired, including names, addresses, dates of birth, medical information, and health insurance information. The types...
Adventist Health Settles Alleged HIPAA Violations with California Attorney General
California Attorney General Rob Bonta has announced a settlement with Adventist Health Hanford to resolve alleged violations of the Health Insurance Portability and Accountability Act (HIPAA), California’s Confidentiality of Medical Information Act (CMIA), unfair competition law, and the California Constitution. Adventist Health was investigated over disclosures of the protected health information (PHI) of two female patients to law enforcement after they suffered stillbirths at the hospital. Staff at the hospital disclosed patient information – including PHI – to law enforcement without a warrant and both women were later charged with murder. Both women spent time in jail before their convictions were overturned. The first alleged unlawful disclosure occurred in December 2017. Adora Perez sought medical assistance at Adventist Health and suffered a stillbirth. Staff at the hospital unlawfully shared medical information with law enforcement related to her labor, the state of the fetus, and alleged drug use by the patient, with the latter attributed to causing the...
Almost 20,000 Aptihealth Patients Affected by Business Associate Data Breach
Data breaches have been announced by the behavioral health engagement company Aptihealth and the civil engineering and architecture firm Wilson & Company. Aptihealth The Saratoga Springs, NY-based behavioral health engagement company, Aptihealth, has confirmed that the HIPAA protected health information of almost 20,000 patients has been exposed or stolen. The breach occurred at Sisense, a business associate of Aptihealth that provides data analytics services. In order to provide those services, Sisense is given access to Aptihealth data, which includes patients’ protected health information. On April 17, 2024, Sisense notified Aptihealth and other clients that an unauthorized individual had gained access to a restricted access server between March 13, 2024, and April 10, 2024. The server contained names, addresses, dates of birth, dates of service, doctors’ names, medical treatment and diagnosis information, health insurance company names, and health insurance identification numbers. The incident affected 19,805 Aptihealth patients. Aptihealth said Sisense has confirmed...
Superior Air-Ground Ambulance Service Facing Class Action Lawsuit Over 858K-Record Data Breach
Superior Air-Ground Ambulance Service is facing a class action lawsuit over a data breach that affected more than 858,000 individuals. Superior Air-Ground Ambulance Service is the largest independent and locally owned emergency medical services provider in the greater Chicagoland area and operates in 5 states in the Midwest. Unauthorized access to its network was detected in May 2024, and the forensic investigation confirmed that an unauthorized third party had access to its network for a week and copied files that contained patients’ protected health information. The information stolen in the attack included names, addresses, dates of birth, Social Security numbers, driver’s license/state identification numbers, financial account and payment card information, patient record information, medical diagnosis/condition information, treatment information, and health insurance information. 858,238 patients were affected and had their data stolen in the attack. On June 6, 2024, a lawsuit was filed in the U.S. District Court for the Northern District of Illinois by Kirston Spann II whose...
Multifactor Authentication Could Have Prevented 9.7 Million-Record Medibank Data Breach
In 2022, a hacker breached the network of the Australian health insurance provider Medibank, obtained the personal and medical information of 9.7 million individuals, and released the stolen data on the dark web. It has now been confirmed that, like the ransomware attack on Change Healthcare, the attack could have been prevented if multifactor authentication had been implemented. Medibank had previously stated that the breach was due to an error by a contractor and a misconfigured firewall; however, the Australian Information Commissioner (AIC) disclosed details of the security failures that led to the breach in a recent Australian Federal Court filing. According to the filing, the cyberattack started with the theft of the credentials of an IT service desk contractor, who had saved Medibank usernames and passwords for multiple accounts in his internet browser profile on his work computer, which he used to provide IT services to Medibank. The contractor subsequently used his personal computer to sign into his internet browser profile on his personal computer, and the credentials...



