Ransomware Attack on Texas Ophthalmology Practice Exposes Data of 80,000 Patients
A Texas ophthalmology practice has experienced a ransomware attack that resulted in the encryption of files on its computer systems. The attack affected Victoria Surgery Center, Victoria Eye Center, and Victoria Vision Center and involved the personal and protected health information of 80,122 individuals. The attack was detected on March 21, 2024, when the file encryption made certain computer systems inaccessible. Third-party forensics specialists were engaged to assist with the investigation and help secure systems, restore access to patient information, and determine the extent to which patient information was involved. The investigation confirmed that there had been unauthorized access to systems and that certain files containing patient data were accessed in the attack. The file review has recently been completed and confirmed that names, addresses, and medical identification were compromised. The affected individuals have now been notified and offered 12 months of credit monitoring and identity theft protection services. Steps have been taken to prevent similar incidents in...
15 State Attorneys General Ask Congress to Respect State Privacy Laws
The American Privacy Rights Act (APRA), the successor of the American Data Privacy and Protection Act (ADPPA), has been criticized by 15 State Attorneys General who are urging Congress not to proceed with the proposed federal data privacy law in its current form. A draft of the APRA was released in April 2024 that addressed some of the problems with the ADPPA that prevented the bill from progressing. While the APRA could win over some of the critics of the ADPPA, one of the main sticking points was the preemption of state laws and that issue has not been properly addressed in the APRA. If the APRA is passed, residents of states with weak privacy protections would benefit and get new rights and protections for their personal data, but states with strong data privacy laws would see their protections watered down. One of the states with the strongest privacy protections is California. California was the first state to enact a comprehensive privacy law in 2018, and since then, 17 other states have followed suit and introduced laws that give consumers better rights over their personal...
Patient Data Exposed in Laptop Theft Incidents
Incidents involving the theft of portable electronic devices containing protected health information are now relatively rare, but two incidents were reported this month. Former Multnomah County Health Department Employee Failed to Return Laptop Containing Patient Information Multnomah County Health Department in Portland, OR, has notified 1,092 Multnomah County Health Center patients that some of their protected health information has been exposed. On March 4, 2024, the Health Department dismissed an employee who failed to return their Health Department laptop. When employees are dismissed, their network account, email, and access to clinical systems and electronic medical records are terminated, as was the case with this dismissal; however, some patient data was stored on the laptop. While employed, the former employee was authorized to view the information, but that authorization ended when the employee was terminated. On April 24, 2024, the Health Department’s anti-malware system generated an alert about suspicious activity on the unreturned laptop indicating the laptop was...
Superior Air-Ground Ambulance Service Data Breach Affects 858K Individuals
Superior Air-Ground Ambulance Service, a leading ambulance and EMS provider serving Illinois, Indiana, Michigan, Ohio, and Wisconsin, has confirmed that the protected health information of 858,238 patients was exposed or stolen in a cyberattack in May 2023. Suspicious activity was identified in its IT systems in May 2023 and action was immediately taken to isolate those systems and an investigation was launched to identify the source of the activity. On June 23, 2023, it was confirmed that there had been unauthorized access to its network between May 15 and May 23, 2023, and during that time, an unauthorized actor copied files from its network. Superior Air-Ground Ambulance Service then conducted a comprehensive and time-intensive review of the affected files to determine the individuals affected and the types of data that had been exposed or stolen. After that process was completed, Superior Air-Ground Ambulance Service worked on obtaining up-to-date contact information to allow notification letters to be sent. Due to the number of individuals involved, that process has taken a...
CentroMed Falls Victim to Another Cyberattack: 400,000 Affected
The San Antonio, TX, healthcare provider El Centro Del Barrio, which does business as CentroMed, has confirmed that it has fallen victim to a cyberattack. This is the second cyberattack and data breach to be disclosed by CentroMed in the past year. The previous data breach was announced by CentroMed in August 2023, following unauthorized access to its systems on June 9, 2024. The Karakurt threat group claimed responsibility for the attack and claimed to have stolen 42 GB of data, although the group does not appear to have leaked the data. CentroMed reported the breach to the HHS’ Office for Civil Rights as involving the protected health information (PHI) of 350,000 patients. The latest incident was recently announced on CentroMed’s website, and notification letters started to be mailed to the 400,000 affected individuals on May 17, 2024. CentroMed explained that unusual activity was identified within its IT network on May 1, 2024. Steps were immediately taken to secure its networks and data and an investigation was launched to identify the cause of the abnormal activity. The...



