Aveanna Healthcare Announces Breach of 11 Employee Email Accounts
The Georgia-based healthcare provider, Aveanna Healthcare, has recently announced that the email accounts of 11 employees have been accessed by an unauthorized third party, who gained access to the protected health information of 10,482 patients. This is the second email breach to be reported by Aveanna Healthcare in recent months. On March 15, 2024, Aveanna Healthcare reported an email breach to the HHS’ Office for Civil Rights that involved the protected health information of 65,482 patients. That incident involved unauthorized access to an employee email account on or around September 22, 2023. The latest breach was detected around a month after OCR was notified about the previous email breach. According to Aveanna Healthcare’s substitute breach notice, unusual activity was detected in the email accounts on April 17, 2024. Immediate action was taken to prevent further unauthorized access to the accounts and an investigation was launched to determine the nature and scope of the breach. On June 12, 2024, it was confirmed that protected health information was present in the...
HealthEquity Confirms Breach Involved PII of 4.3 Million Individuals
In early July, the HIPAA Journal reported on a data breach at the Draper, UT-based financial technology and business services company, HealthEquity. HealthEquity had disclosed in an 8-K filing with the Securities and Exchange Commission (SEC) that it had identified suspicious activity in the device of a business partner. The initial findings of the investigation indicated unauthorized access to the device and member information. HealthEquity has recently notified the Maine Attorney General about the incident and has confirmed that the personal identifying information (PII) of 4,300,000 individuals was exposed and potentially stolen, including the personal information of 13,480 Maine residents. HealthEquity, the parent company of WageWorks Inc. and Further Operations LLC, provides health savings account (HSA) services and other consumer-directed benefits solutions, including health reimbursement arrangements (HRAs). The company manages millions of HSAs, HRAs, and other benefit accounts. In the notification, HealthEquity explains that it was notified about a systems anomaly on March...
Debt Collection Agency Confirms 4.25 Million Individuals Affected by February 2024 Cyberattack
The debt collection agency Financial Business and Consumer Solutions (FBCS) has recently notified the Maine Attorney General that a previously reported breach that was initially reported as affecting 1,955,385 individuals is more than twice as bad. In the fifth report filed with the Maine Attorney General, FBCS has confirmed that 4,050,711 individuals are known to have been affected, including 7, 786 Maine residents. The total continues to increase, as the latest update in late July indicates 4,253,394 individuals have been affected, including 7,841 Maine residents. The data breach occurred on February 14, 2024, and was discovered a couple of weeks later on February 26, 2024. The forensic investigation by third-party cybersecurity specialists confirmed that the breach was confined to FBCS systems, the hackers had access to those systems for almost 2 weeks, and during that time they may have viewed or acquired files containing sensitive information. FBCS first notified the Maine Attorney General about the breach on April 26, 2024; however, the investigation had not concluded. As the...
What is EDI in Healthcare?
EDI in healthcare stands for Electronic Data Interchange – a system for securely transmitting information between healthcare providers, health care clearinghouses, and payers about a patient’s condition, treatment for the condition, and payment for the treatment. Since 2000, the standards used in EDI healthcare transactions have been governed by Part 162 of the HIPAA Administrative Simplification Regulations. To help explain what EDI in healthcare is, it can be useful to start with the scenario of a patient attending a checkup appointment with a doctor. The doctor examines the patient and identifies a problem that requires treatment. Before providing the treatment, the doctor sends an eligibility enquiry to the patient’s insurance company (or Medicare, etc.), and the insurance company replies to inform the doctor whether the patient is eligible for the treatment. In this case, the patient is eligible for the treatment without any further authorizations required. The doctor provides the treatment and submits a claim for payment supported by details of the patient/doctor encounter....
North Korean Hacker Indicted for Ransomware Attacks on U.S. Hospitals and Healthcare Orgs
A North Korean government hacker has been indicted for his involvement in Maui ransomware attacks on U.S. hospitals and healthcare organizations. The U.S. State Department is offering a reward of up to $10 million for information that leads to his capture. Rim Jong Hyok is a member of the Andariel (APT45), a North Korean hacking group that has been in operation since at least 2009. The hacking group conducts activities as part of North Korea’s cyber defensive operations, primarily targeting military and government personnel. The group’s primary aims are espionage and data theft, especially the theft of sensitive defense and technology data. The hacking group also conducts financially motivated ransomware attacks to obtain funds to support its cyber campaigns, including ransomware attacks on U.S. hospitals and healthcare providers. Hyok was indicted by a grand jury in the U.S. District Court, District of Kansas on Wednesday and has been charged with one count of conspiracy to knowingly cause the transmission of a program, information, code, and command to intentionally cause damage...



