11 Vulnerabilities Identified in GE HealthCare Ultrasound Products
Almost a dozen vulnerabilities have been identified in GE HealthCare Vivid Ultrasound machines that could be exploited by threat actors to access and alter patient data, and potentially install ransomware locally to render the devices unavailable. The vulnerabilities were identified by researchers at the Operational Technology (OT) vendor Nozomi Networks during a review of the GE HealthCare Vivid Ultrasound family and the companion software that is used to review the generated medical data. The main focus of the review was the Vivid T9 ultrasound system, its pre-installed Common Service Desktop web application, and the EchoPAC software. The researchers identified 11 vulnerabilities that affect several systems and software products. The vulnerabilities were reported to GE HealthCare which issued a statement saying that existing controls mitigate the risks of exploitation of the flaws to an acceptable level, provided standard cybersecurity practices are followed, such as restricting physical access to the devices. Patches have been made available to fix the vulnerabilities which can...
How Long Is HIPAA Training Good For?
HIPAA training is usually good for one year. The industry best practice is to provide annual HIPAA training unless something changes in the organization. HIPAA training is good for as long as a HIPAA risk assessment does not identify a need for further training, for as long as there is not a material change to internal HIPAA policies and procedures, until HIPAA training is required as a sanction for a HIPAA violation, or until HHS’ Office for Civil Rights mandates HIPAA training as part of a corrective action plan. The HIPAA Privacy Rule Training Requirements Under the HIPAA Privacy Rule, training is mandated for all workforce members of covered entities and business associates who handle or have access to PHI, ensuring they understand how to maintain the confidentiality and security of this sensitive information. This includes education on the proper use and disclosure of PHI, the rights of individuals under HIPAA, and the entity’s privacy policies and procedures. The HIPAA Journal is the market leader in HIPAA training and has a reputation for providing the best HIPAA...
OCR HIPAA Audit Program to Commence in 2024
The Health Information Technology for Economic and Clinical Health Act (HITECH) Act of 2009 requires the HHS’ Office for Civil Rights to conduct periodic audits of HIPAA-regulated entities to assess compliance with the HIPAA Rules. OCR Director Melanie Fontes Rainer has confirmed that audits will be taking place this year and will focus on HIPAA Security Rule compliance. The HIPAA audit program was slow to commence, with the first round of audits conducted in 2012. There was then a long break before the second round of audits, which were conducted between 2016 and 2017, the findings of which were published by OCR in 2020. While OCR has been considering a permanent HIPAA audit program, multiple OCR directors have struggled to implement such a program due to a lack of resources. OCR’s budget has remained flat for years even though OCR’s workload has been increasing. OCR investigates all breaches of 500 or more records, which were reported at a rate of around 200 a year in 2010 and 2011. In 2014 more than 300 breaches were reported, and breaches more than doubled between 2017 and 2023...
Microsoft Patches Zero-Day Vulnerability Exploited to Deliver QakBot and Other Malware
Microsoft has released a patch to fix a zero-day Windows vulnerability – CVE-2024-30051 – exploited in attacks delivering QakBot malware. Healthcare organizations should prioritize this patch as QakBot has been used in many attacks on the healthcare sector. QakBot, aka QBot, was first identified in 2008 and was initially a banking trojan that was used to steal banking information and credentials. The malware has evolved over the years into a malware delivery service, with the operators acting as an initial access broker, selling access to infected companies to other threat actors, including ransomware groups. A law enforcement operation last summer successfully dismantled the QakBot botnet and took down its infrastructure; however, it was rebuilt and remains in operation. Several threat groups are known to work with the QakBot operators, including the Black Basta ransomware group. A joint cybersecurity alert was recently issued by CISA and partners warning critical infrastructure entities about Black Basta ransomware attacks. Black Basta has been linked with the recent...
Hypertension-Nephrology Associates Warn Patients of Data Theft Incident
Hypertension-Nephrology Associates in Michigan has recently announced that it was the target of a cyberattack in January 2024. An unknown threat actor dropped a ransom note on its computer system demanding payment to prevent the publication of patient data that was stolen in the attack. The healthcare industry continues to be targeted by ransomware gangs that steal data and encrypt files, demanding payment for the keys to decrypt files and to prevent the release of stolen data; however, many threat actors skip file encryption and conduct extortion-only attacks, as was the case in the attack on Hypertension-Nephrology Associates. After discovering the ransom note, an investigation was launched to verify the threat actor’s claims. Third-party cybersecurity experts were engaged to assist with the investigation and confirmed that the threat actor had access to its systems between January 20, 2024, and February 6, 2024. During that time, files containing patients’ protected health information were exfiltrated from its systems. A comprehensive review was conducted of the...



