LockBit Leader Named and Sanctioned
The UK’s National Crime Agency (NCA) has named the leader of the infamous LockBit ransomware group as Russian national Dmitry Yuryevich Khoroshev, also known as LockBitSup. Lockbit is a ransomware-as-a-service group that has been in operation for four years. During that time, the group became the most prolific ransomware operation and targeted thousands of companies worldwide. According to the U.S. Department of Justice, LockBit has claimed more than 2,000 victims worldwide, has obtained more than $500 million in ransom payments, and has caused billions of dollars in losses. In February 2024, an international law enforcement operation – Operation Cronos – headed by the NCA successfully infiltrated the group’s systems, took control of its infrastructure, and locked the group out of its systems. The NCA took control of the group’s administrative systems, which the group’s affiliates used to conduct ransomware attacks, and the group’s public-facing data leak site where victims are named and stolen data are published. According to the NCA, information was gathered on LockBit’s 194...
OrthoConnecticut Data Breach Affects 118,000 Patients
OrthoConnecticut has confirmed that the protected health information of more than 118,000 patients has been exposed in a cyberattack. Data breaches have also been reported by Green Diamond Resource Company and Empath Health. OrthoConnecticut OrthoConnecticut, a Danbury, CT-based multi-specialty orthopedic practice with 9 locations in Connecticut, recently identified unauthorized access to its network. The forensic investigation confirmed that an unauthorized third party had access to its network between November 24, 2023, and November 28, 2023, and during that time, may have removed files from the network that contained patients’ protected health information. OrthoConnecticut conducted a comprehensive review of all files on the network to determine which patients were affected, and it was confirmed on March 27, 2024, that the protected health information of 118,141 patients had been exposed. The types of information involved varied from patient to patient and may have included full names in combination with one or more of the following: Social Security number, date of birth, and...
Email Breaches Reported by MedStar Health, Bluebonnet Trails Community Services, Bluegrass Care Navigators
MedStar Health is notifying more than 118,000 patients about an email security incident that exposed their protected health information. Email accounts have also been compromised at Bluebonnet Trails Community Services and Bluegrass Care Navigators. MedStar Health MedStar Health, a non-profit healthcare provider that operates 10 hospitals in the Baltimore-Washington area, said hackers gained access to its network and may have obtained the protected health information of 183,000 patients, including names, addresses, dates of birth, dates of service, provider names, and health insurance information. MedStar Health did not say when the unauthorized access was first detected but confirmed that the email accounts of three employees were accessed by unauthorized individuals intermittently between January 2023 and October 2023. MedStar Health said it has no reason to believe that patient data was accessed or acquired, but it was not possible to rule out data theft with a high degree of certainty. As required by HIPAA, MedStar Health had implemented technical, physical, and administrative...
Presbyterian Healthcare Services Agrees to Settle Email Breach Lawsuit
Presbyterian Healthcare Services has proposed a settlement to resolve a class action lawsuit that was filed by patients whose protected health information was compromised in a 2019 phishing attack. In June 2019, the New Mexico-based healthcare system discovered hackers had gained access to the email accounts of some of its employees when they responded to phishing emails. The email accounts contained the names, dates of birth, Social Security numbers, clinical information, and health plan information of 183,370 patients and health plan members. A class action lawsuit was filed in response to the data breach that alleged Presbyterian Healthcare Services had failed to implement reasonable cybersecurity measures, did not follow industry-standard cybersecurity practices, and could have prevented the breach if those measures had been implemented. Presbyterian Healthcare Services did not agree with the allegations but has chosen to settle the lawsuit with no admission of wrongdoing or liability. Under the terms of the settlement, individuals who were notified about the breach by...
OSHA Proposes $163K Fine for Home Health Agency After Murder of Home Health Worker
The Occupational Safety and Health Administration (OSHA) has proposed a $163, 627 fine for a home healthcare provider that the agency alleged failed to protect workers from serious hazards of workplace violence. OSHA cited Jordan Health Care Inc. and New England Home Care Inc., which do business as Elara Caring – one of the largest home healthcare providers in the United States with more than 200 branches in 17 states. OSHA initiated an investigation following the attempted sexual assault and murder of visiting nurse, Joyce Grayson, in October 2023. Grayson visited a halfway house in Willimantic, Connecticut on October 28, 2023, to provide medications to a client. The police were called after Grayson failed to attend subsequent appointments, and her body was found in the basement of the residence. The client she was visiting, Michael Reese, 39, had previously been convicted of rape and had served 14 years in prison after sexually assaulting and stabbing a woman in 2006. He has since been charged with murder, felony murder, and attempted first-degree sexual assault. OSHA...



