June 2024 Healthcare Data Breach Report
In June 2024, 47 data breaches of 500 or more healthcare records were reported to the HHS’ Office for Civil Rights (OCR), the fewest number of breaches since October 2023. Data breaches were down 9.6% from May 2024, and 30.9% down from June 2023, and were well below the 12-month average of 64 data breaches a month. For the second consecutive month, the number of breached records has fallen. Across the 47 breaches reported in June, the protected health information of 3,837,356 individuals was exposed, stolen, or impermissibly disclosed. June’s compromised record total is the second lowest monthly total in 2024, 54.7% lower than May 2024, and well below the 12-month average of 11,637,320 breached records a month. It is likely to be a very different story next month, as Change Healthcare will be mailing breach notification letters to the individuals affected by its February 2024 ransomware attack from July 20, 2024, which means OCR will soon be notified about the extent of the breach. The CEO of Change Healthcare’s parent company, UnitedHealth Group, told a senate hearing that the...
What is the Confidentiality Definition in Healthcare?
The confidentiality definition in healthcare is an ethical obligation to preserve authorized restrictions on access to – and disclosures of – sensitive personal information gathered in association with the care of a patient. In this respect, the ethical confidentiality definition in healthcare is broader than the legal confidentiality definition in HIPAA. The ethical confidentiality definition in healthcare is derived from the definition of confidentiality used in Title 44, Chapter 35 of the US Code relating to Information Security. The definition states “confidentiality […] means preserving authorized restrictions on access and disclosure, including means for protecting personal privacy and proprietary information.” The reason it is a derived definition rather than an actual definition is because few healthcare regulations define “confidentiality”. Even the “Confidentiality of SUD Patient Records” (42 Part 2) does not define confidentiality – despite giving HHS the authority to impose penalties on healthcare providers that fail to maintain the confidentiality of SUD patient...
CISA Issues Alert About Multiple Philips Vue PACS Vulnerabilities
More than a dozen vulnerabilities have been identified in the Philips Vue PACS image management and communication system, including critical vulnerabilities that can be remotely exploited in a low-complexity attack. Successful exploitation of the vulnerabilities could allow an unauthenticated individual to remotely execute code, install unauthorized software, eavesdrop, view, or modify data, or negatively impact the confidentiality, integrity, or availability of the system or data. The 13 vulnerabilities affect all versions prior to 12.2.8.410. Vue PACS Vulnerabilities CVE Type CVSS v3.1 CVSS v4 CVE-2017-17485 Deserialization of untrusted data 9.8 9.3 CVE-2020-11113 Deserialization of untrusted data 8.8 7.1 CVE-2020-10673 Deserialization of untrusted data 8.8 8.7 CVE-2023-40159 Exposure of sensitive information to an unauthorized actor 8.2 8.8 CVE-2020-35728 Deserialization of untrusted data 8.1 9.3 CVE-2021-20190 Deserialization of untrusted data 8.1 9.3 CVE-2020-14061 Deserialization of untrusted data 8.1 9.3 CVE-2021-28165 Uncontrolled resource consumption 7.5 8.8 CVE-2020-40704...
Memorial Sloan Kettering Cancer Center Employees Tricked by Phishing Email
Memorial Sloan Kettering Cancer Center (MSK) has announced that the protected health information of 12,274 individuals has been exposed in a phishing attack. On April 26, 2024, MSK identified suspicious activity in an employee email account. The account was used to send an email to many other MSK employees that contained a link to a spoofed web page that prompted users to log in to their MSK accounts and captured their credentials when they were entered. Several employees were tricked by the email because the message had been sent from a valid MSK account and appeared to be a valid internal request. An analysis of the compromised email accounts confirmed they contained some protected health information, including first and last names, medical record numbers, diagnoses, medication names, treatment types, and dates of treatment. A subset of the affected individuals also had their contact information (address, email, telephone number) and dates of birth exposed. MSK confirmed that the breach was limited to email accounts, medical records were not accessed, and Social Security numbers...
ITRC: More Than 1 Billion Individuals Affected by H1, 2024 Data Compromises
The first half of 2024 saw a significant increase in the number of victims of data breaches, according to a recently published H1 Data Breach Analysis by the Identity Theft Resource Center. In the first 6 months of the year, there were 1,571 publicly reported compromises, up 14% from H1, 2023, and more than 1 billion victims. The size of some of the data breaches was astonishing. The two biggest attacks in terms of the number of affected individuals occurred at Ticketmaster Entertainment and Advance Auto Parts, with the former involving the personal data of 560 million individuals and the latter affecting 380 million individuals. A data breach at Dell Technologies affected 49 million individuals, a breach at LoanDepot affected 16.9 million individuals, and a healthcare data breach at Kaiser Foundation Health Plan rounded out the top 5 and affected 13.4 million individuals. Two other healthcare data breaches made the top 10 – The attack on the debt collection firm, Financial Business and Consumer Solutions, Inc., which affected 3,435,640 individuals, and the attack on the...



