MCG Health Settles Class Action Data Breach Lawsuit for $8.8 Million
The Seattle, WA-based software company, MCG Health, has proposed a $8.8 million settlement to resolve a consolidated class action lawsuit stemming from a February 2020 data breach that involved the protected health information of 793,283 individuals. It took MCG Health two years to discover that a threat actor had obtained data from its network, with that determination made on March 25, 2022. Patients of at least 10 of its clients had information compromised in the incident including names, Social Security numbers, medical codes, postal addresses, telephone numbers, email addresses, and dates of birth. Several class action lawsuits were filed in response to the breach that made similar claims and alleged negligence, invasion of privacy, bailment, breach of implied contract, breach of confidence, and a violation of the Washington Consumer Protection Act. The lawsuits were consolidated into a single action in the U.S. District Court for the Western District of Washington – In re: MCG Health Data Security Issue Litigation. MCG Health has not admitted any wrongdoing and chose to...
What is FISMA Compliance?
FISMA compliance is compliance with applicable standards and guidelines developed by the National Institute of Standards and Technology (NIST) following the passage of the Federal Information Security Management Act of 2002 (FISMA). FISMA compliance is mandatory for federal agencies, state and local government agencies in receipt of federal funding, and service providers working with federal, state, and local government agencies, When FISMA was passed in 2002, it required all federal agencies to develop, document, and implement an agency-wide program to provide information security for the information and systems that support the operations and assets of the agency. The requirements also applied to information and systems provided or managed by third party service providers, and was later extended to include state and local government agencies in receipt of federal funding. To support covered entities in meeting the FISMA compliance requirements, FISMA authorized NIST to develop standards and guidelines to protect federal information and information systems. NIST subsequently...
Cyberattack on The Medibase Group Affects 35,000 Patients
Cyberattacks have recently been announced by the Medibase Group, Therapeutic Health Services, and the law firm Smith, Gambrell & Russell. The Medibase Group The Medibase Group, Inc., a Woodstock, GA-based provider of software solutions, technical assistance, and business office solutions to healthcare delivery organizations, has experienced a cyberattack that exposed the protected healthcare information of 35,106 patients of its healthcare provider clients. The cyberattack occurred on or around January 26, 2024, and involved unauthorized access to one of Medibase’s systems. Prompt action was taken to contain the attack, and a leading security and forensics company was engaged to assist with the investigation. The investigation confirmed that the attack was limited to the Medibase system, and no client systems were compromised. The review of the affected files revealed they contained full names, Social Security numbers, dates of birth, admission/discharge dates, outstanding balance amounts, and health insurance information. While data theft is possible, Medibase believes the...
Two LockBit Ransomware Affiliates Plead Guity and Face Up to 70 Years in Prison
The Department of Justice has announced that two foreign nationals have pleaded guilty to charges related to their participation in the LockBit ransomware operation and for using ransomware to attack businesses in the United States and worldwide. The LockBit ransomware-as-a-service (RaaS) operation emerged in 2020 and rapidly became the most prolific ransomware group worldwide. LockBit ransomware has been used to attack more than 2,500 victims, including 1,800 in the United States, and has generated more than $500 million in ransom payments. In February 2024, an international law enforcement operation (Operation Chronos) seized the infrastructure of the group, including data leak sites, servers, around 14,000 accounts involved with data exfiltration, and around 200 cryptocurrency accounts that were used by the group and its affiliates. The group survived the disruption but has since operated at a reduced capacity. Ruslan Magomedovich Astamirov, 21, a Russian national of the Chechen Republic in Russia, and Mikhail Vasiliev, 34, a dual Canadian and Russian national of Bradford,...
Faulty CrowdStrike Software Update Causing Major Disruption at U.S. Healthcare Organizations
After the massive disruption and financial difficulties caused by the Change Healthcare ransomware attack, the last thing healthcare providers need right now is further disruption; however, many hospitals have been forced to cancel appointments and delay services due to a faulty software update that has disabled their Windows devices. While the update has affected Windows devices, the issue was a faulty software update from the Cybersecurity company CrowdStrike that affects users of its Falcon threat detection platform. It was supposed to be just another routine software update; however, the bug crashed Windows devices and triggered the dreaded blue screen of death, preventing Windows devices from rebooting and rendering them inoperable. Mac and Linux systems were not affected by the update. “I want to sincerely apologize directly to all of you,” said CrowdStrike CEO, George Kurtz. “All of CrowdStrike understands the gravity and impact of the situation.” Kurtz stressed that there was no unauthorized access to systems, the problem has been identified, and the...



