Continuum Health Alliance Data Breach Affects 377,000 Consensus Medical Group Patients
Marlton, NJ-based Continuum Health Alliance has recently confirmed that it has experienced a security incident that exposed the data of 377,119 patients of its client, Consensus Medical Group, a physician-owned medical group in Evesham, NJ. Continuum identified unauthorized activity within its network on October 19, 2023, and after taking steps to secure its systems, third-party cybersecurity specialists were engaged to identify the suspicious activity. The forensic investigation confirmed that an unauthorized third party had gained access to some of its systems between October 18 and October 19, and acquired certain files. On February 16, 2024, Continuum announced on its website that it was investigating the incident. The file review was completed on March 8, 2024, when it was confirmed that the exposed data included patients’ names and Social Security numbers. Continuum then worked to verify the information and obtain up-to-date address information, and HIPAA notification letters were mailed on April 29, 2024. Continuum has implemented additional safeguards to prevent further...
Types of Telehealth
Telehealth, also known as telemedicine, refers to the provision of medical care and healthcare services from a distance. Telehealth has been offered to patients for decades, but thanks to advances in technology, healthcare providers have been able to expand the range of telehealth services they provide. With many patients having access to a smartphone or tablet and Wi-Fi, healthcare providers have been able to significantly improve the reach of telehealth. The telehealth software solutions now available have also made providing telehealth services far easier, and healthcare providers and patients alike have greatly benefitted. Telehealth services have been shown to cost-effectively enhance the quality of care that can be provided to patients. Studies have shown that the many different types of telehealth greatly benefit patients, and can reduce the number of patients requiring hospitalization and reduce readmissions into hospital after discharge. COVID-19 Greatly Expanded the Types of Telehealth Services Offered The COVID-19 pandemic greatly expanded telehealth services, not just...
BioPlus Specialty Pharmacy Services Proposes Settlement to Resolve Data Breach Lawsuit
BioPlus Specialty Pharmacy Services has proposed a settlement to resolve a class action lawsuit that was filed in response to a 2021 data breach that exposed the data of up to 350,000 patients. Hackers gained access to the BioPlus network for more than 2 weeks between October and November 2021, and potentially stole names, dates of birth, contact information, health insurance information, prescription information, and Social Security numbers. The Florida specialty pharmacy chain notified the affected individuals within a month and offered them complimentary credit monitoring services. A lawsuit was filed over the data breach alleging BioPlus should have prevented the breach and could have if reasonable cybersecurity measures had been implemented and industry-standard security best practices had been followed. BioPlus disagreed with the allegations; however, a settlement has been proposed to bring the legal action to an end. BioPlus has not admitted liability or any wrongdoing related to the cyberattack and data breach. Under the terms of the proposed settlement, class members may...
BakerHostetler Report Identifies Healthcare Data Breach and Litigation Trends
BakerHostetler has released the 10th edition of its Data Security Incident Response Report, which shares data from the incidents the law firm has helped to manage. The report provides insights into the current cyber threat landscape and litigation trends. Data Breach Insights Healthcare accounted for 28% of data breach incidents, followed by finance and insurance (17%), business and professional services (15%), and education (13%). The biggest known root cause of all incidents was the exploitation of unpatched vulnerabilities (23% of incidents) followed by phishing (20%). By far the most common cause of security incidents in 2023 was network intrusions, which accounted for 51% of security incidents the law firm helped to manage, followed by business email compromise incidents (26%), and inadvertent disclosures (26%). Cybercriminals are getting better at covering their tracks, as the root cause of 36% of network intrusions could not be determined. The main known cause of these incidents was vulnerability exploitation (25% of attacks). Phishing was involved in 9% of network...
Healthcare Ransomware Attacks Involve 20% of Stored Sensitive Data
Ransomware groups target the healthcare sector because a successful attack gives them access to large amounts of sensitive data that can be easily monetized and used as leverage to get a ransom paid. Healthcare organizations are also heavily reliant on access to data to operate, therefore there is a higher probability that a ransom will be paid to regain access to encrypted data. Attacks on the sector are also increasing. According to Recorded Future, there were 358 ransomware attacks on healthcare organizations in 2023, a year-on-year increase of 46%. A recent study by the cybersecurity firm Rubrik assessed the impact of ransomware attacks and found that attacks on healthcare providers impact more data than other industry sectors. Researchers at Rubrik Zero Labs determined that 20% of a healthcare organization’s sensitive data holdings are affected by a ransomware encryption event, compared to 6% in other industry sectors. That means 20% of healthcare data is encrypted, deleted, or stolen in an attack. Healthcare organizations generally hold more sensitive data than other industry...



