NIST Releases Finalized Post-Quantum Encryption Standards
The National Institute of Standards and Technology has released three new encryption standards that have been developed to resist decryption via quantum computing. Current public-key encryption systems render data unintelligible and are widely used to secure communications and transactions to prevent unauthorized access to data. These encryption methods rely on math problems that even today’s most powerful supercomputers cannot defeat. That could all change, however, with quantum computers. Data encrypted today using the most powerful encryption algorithms could be stolen and decrypted at a later date when quantum computers become readily available. Quantum computers are still in the early stages of development; however, researchers have created a processor comprised of fast, high-fidelity quantum logic gates, which in benchmark testing, performed a computation in 200 seconds that it would currently take the world’s fastest supercomputer 10,000 years to product a similar output. Quantum computers pose a significant threat to encryption systems, hence the need for new...
Acadian Ambulance Facing Multiple Class Action Lawsuits Over Data Breach
Several class action lawsuits have been filed against Acadian Ambulance over a recent ransomware attack and data breach that may have affected up to 10 million individuals. At the time of publication, the breach has yet to be reported to the HHS’ Office for Civil Rights, so it is unclear exactly how many individuals have been affected. The threat group behind the attack, Daixin Team, claimed to have stolen 11 million lines of data, including 10 million unique records. The group said the stolen data includes names, dates of birth, phone numbers, medical histories, case histories, employment information, symptoms, suspected drug use, as well as employee information. Acadian Ambulance has confirmed the attack, and while the total number of affected individuals has yet to be determined, Acadian Ambulance says it is much lower than the attackers allege. Acadian Ambulance is a Lafayette, LA-based private ambulance service that operates in Louisiana, Texas, Tennessee, and Mississippi. At least six lawsuits have now been filed in the U.S. District Court for the Western District of...
Alabama Cardiovascular Group Cyberattack Affects 280,500 Individuals
Alabama Cardiovascular Group, Gastrointestinal Medicine Associates & United Urology Group have recently reported data breaches involving the protected health information of at least 323,573 individuals. RansomHub claims to have stolen data from the Neurological Spine Institute of Savannah in Georgia. Alabama Cardiovascular Group Alabama Cardiovascular Group (ACG) has discovered unauthorized individuals accessed its computer network over the space of a month between June 6, 2024, and July 2, 2024, and during that time, exfiltrated files containing sensitive data. The intrusion was detected on July 2, 2024, and immediate steps were taken to prevent further unauthorized access to the network. The cyberattack has been reported to law enforcement and the HHS’ Office for Civil Rights (OCR). The OCR breach portal indicates up to 280,534 individuals have been affected, including current and former patients, guarantors, employees, and physicians. Those individuals have been notified by mail and offered 24 months of complimentary access to Experian’s IdentityWorks identity theft...
Healthcare Data Breaches Affect Patients in AL, IN, MN, NC, NY, OR, and NY
Breaches of protected health information have recently been confirmed by Fraser Child and Family Center (MN), UAB School of Nursing (AL), Meridian Internal Medicine (NC), Advantage Orthopedic & Sports Medicine (OR), and South Western Communications (IN), and Aire Dental Arts (NY). Fraser Child and Family Center, Minnesota Fraser Child and Family Center, a Minnesota-based provider of autism, mental/behavioral health, and disability services, detected suspicious activity within its computer network on June 2, 2024. Steps were taken to secure its IT systems and prevent further unauthorized access and a third-party forensic investigation was initiated to determine the nature and scope of the incident. The investigation confirmed that an unauthorized third party had access to its network From May 30, 2024, to June 2, 2024, and during that time, accessed or copied files without authorization. The file review determined that up to 67,000 patients may have been affected and potentially had their names, addresses, dates of birth, Social Security numbers, and medical information exposed;...
Illinois, Florida, and Puerto Rico Healthcare Providers Confirm Data Breaches
Investigations of cyberattacks at healthcare providers in Illinois, Florida, and Puerto Rico are continuing, with announcements made that data breaches have occurred, although at this stage it is unclear how many individuals have been affected. Roseland Community Hospital, Illinois The Roseland Community Hospital Association in Illinois has confirmed that it has fallen victim to a cyberattack that exposed the protected health information of patients of Roseland Community Hospital in Chicago. The cyberattack was detected on June 2, 2024, and steps were immediately taken to secure its systems to block further unauthorized access. Third-party cybersecurity experts were engaged to assist with the investigation and confirmed that there had been unauthorized access to its IT network on June 2 and files were accessed or obtained by the threat actor. The file review confirmed that the data elements compromised in the incident include names, in combination with one or more of the following: date of birth, address, medical record number, patient account number, health insurance information,...



