Kootenai Health Ransomware Attack Affects 464,000 Individuals
Kootenai Health, a Coeur d’Alene, ID-based health system that serves patients in northern Idaho and the Inland Northwest, has announced that it has experienced a data security incident involving the personal and protected health information of patients, employees, and employees’ dependents. Kootenai Health said the incident has not had any impact on its operations, and care has continued to be provided to patients; however, the incident disrupted some of its IT systems. Unusual activity was detected within its computer systems on March 2, 2024. Third-party cybersecurity experts were engaged to investigate the incident, and evidence was found that an unauthorized individual gained access to its network on or around February 22, 2024. Kootenai Health conducted a review of all files on the systems that were accessed to determine if they contained any personal or protected health information, and that process was completed on August 1, 2024. The incident affects employees and patients of Kootenai Health, Kootenai Clinic, Kootenai Outpatient Surgery, and Kootenai Outpatient...
FBI-led Operation Shut Down Radar/Dispossessor Ransomware Group’s Servers
The Federal Bureau of Investigation (FBI) led an international operation against the Radar/Dispossessor ransomware group, resulting in the dismantling of 24 servers used by the group, including 3 in the US, along with 9 criminal domains, 8 of which were in the US. Radar/Dispossessor is a criminal ransomware-as-a-service (RaaS) group led by an individual with the moniker ‘Brain.’ The group uses affiliates to conduct attacks in exchange for a percentage of any ransoms that are paid and has been in operation since August 2023. Like many other criminal ransomware groups, Radar/Dispossessor engages in double extortion, where sensitive data is identified and exfiltrated from victims’ systems and held to ransom in addition to encrypting files. Payment is required to decrypt data and to prevent the stolen data from being released to the public. The group is known to exploit weak passwords and a lack of 2-factor authentication to gain access to victims’ networks, then administrator rights are obtained to access and exfiltrate files and deploy the ransomware payload. If victims do not make...
What is an FQHC in Healthcare?
An FQHC in healthcare is a Federally Qualified Health Center that provides low cost “safety net” medical services in an underserved area or to an underserved population. Qualifying FQHCs are funded by Federal grants and receive cost-based reimbursement for Medicare and Medicaid patients. They also qualify for malpractice coverage under the Federal Tort Claims Act (FTCA). FQHCs in healthcare are more commonly known as Community Health Centers as they were originally privately funded non-profit clinics serving the poorest urban areas. Federal support for Community Health Centers started in the 1960s; and, in 1990, the term Federally Qualified Health Center was added to the Social Security Code to distinguish Community Health Centers that provided services for patients under Medicare and Medicaid. In 1996, the Health Centers Consolidation Act expanded the definition of an FQHC in healthcare to include Migrant Health Centers, Health Care for the Homeless Programs, and Public Housing Primary Care Programs that received federal grants. The Act also added a new Section to the Public...
Indiana Attorney General Drops Privacy Lawsuit Against IU Health
Indiana Attorney General Todd Rokita has dropped a privacy lawsuit against IU Health and IU Health Associates that alleged violations of the Health Insurance Portability and Accountability Act (HIPAA) and the Indiana Deceptive Consumer Sales Act for failing to protect a child’s protected health information. The lawsuit stemmed from comments made to the media by IU Health obstetrician-gynecologist Dr. Caitlin Bernard about an abortion she provided to a 10-year-old patient. The girl was the victim of a rape and could not legally have an abortion in her home state. She traveled to Indiana where abortions could be legally provided. The state has since updated its law and has made abortion illegal, except in very limited circumstances. IU Health investigated Dr. Bernard over the disclosure and was satisfied that the HIPAA Rules had not been violated. Dr. Bernard provided comments to a reporter from the IndyStar but did not disclose the patient’s name, only her age, home state, and gender. The Indiana Medical Board determined that sufficient information had been disclosed to allow the...
Six Healthcare Providers Added to Ransomware Data Leak Sites
Recent reports by Rapid7 and Guidepoint Security indicate the number of active ransomware groups has increased in 2024, as has the number of attacks. The healthcare industry is a prime target for ransomware groups and there has been a recent flurry of listings on ransomware groups’ data leak sites. Surgery Center of Mid Florida The Surgery Center of Mid Florida has recently alerted patients about a network encryption event (ransomware). The attack was detected on or around February 21, 2024, when unusual network activity was observed. The investigation confirmed file encryption, with the initial hacking occurring at its IT vendor. The hackers then used the connection with the IT vendor to launch an attack on its network. While the investigation found no evidence that patient information was viewed or acquired by the hackers, the decision was made to notify all 48,684 patients about the attack as unauthorized data access/theft could not be ruled out. Following the attack, the Surgery Center of Mid Florida terminated its contract with the IT vendor and contracted with a new...



