HPH Sector Warned About Email Bombing Attacks
Healthcare organizations have been warned about the threat of email bombing attacks, which are a type of denial-of-service (DoS) attack that targets email systems. As with other types of DoS attacks, the aim is to render systems unavailable. These attacks, also known as mail bomb or letter bomb attacks, usually involve a botnet – a network of malware-infected computers under the control of an attacker. Once a target is selected, an email server is flooded with hundreds or thousands of email messages that overload the email system. These attacks are an inconvenience for the victim; however, these attacks can hide other malicious activities. For example, security warnings may be hidden within all the emails making it easier for those warnings to be missed. Those warning emails may be about account sign-in attempts, updates to account information such as changes to contact information, information about financial transactions, or online order confirmations. These attacks can also be used as a smokescreen to draw the attention of security teams while other systems are attacked. When...
R1 RCM Data Breach Impacts 16,000 Patients
Data breaches have recently been reported by R1 RCM, St. Mary’s Healthcare System for Children, Philips Respironics, and California Correctional Health Care Services. R1 RCM R1 RCM Inc., a provider of revenue cycle management services to hospitals, has recently reported a breach of the protected health information of 16,121 individuals. According to a breach notice sent to the Massachusetts Attorney General, R1 learned on November 23, 2023, that protected health information associated with Dignity Health’s St. Rose Dominican Hospital de Lima was in the possession of an unauthorized third party. The hospital’s network was not compromised in the incident. A review was conducted to determine the data types that had been obtained, and on January 11, R1 determined that the information contained names, contact information, dates of birth, Social Security numbers, location of services, clinical and/ or diagnosis information, and patient account and/or medical record numbers. R1 has notified the affected individuals directly and has offered them 2 years of complimentary credit...
Sen. Cassidy Seeks Feedback on the Regulation of Clinical Tests
U.S. Senator Bill Cassidy, M.D. (R-LA), ranking member of the Senate Health, Education, Labor, and Pensions (HELP) Committee, is seeking feedback from stakeholders on ways to improve the regulation of clinical tests in the United States. Since the Medical Device Amendments (MDA) of 1976 established the Food and Drug Administration’s (FDA) framework for medical devices more than 50 years ago there have been major advancements in in vitro diagnostic technologies that have required improvements to the framework. Similarly, advances in clinical laboratory medicine in the 35 years since the Clinical Laboratory Improvement Amendments of 1988 (CLIA) were enacted demand standards that reflect advances in molecular and genetic testing, as well as appropriate oversight of tests. While Congress has considered proposals to reform these regulations, there have been no substantive updates to either of these frameworks. Sen. Cassidy is seeking feedback from stakeholders on potential updates to the FDA regulatory framework for diagnostics and the CLIA Regulatory Framework for LDTs, in particular,...
Healthcare Providers Sue UnitedHealth Group Over Change Healthcare Ransomware Attack
Lawsuits have started to be filed against UnitedHealth Group, Optum Inc., and Change Healthcare by healthcare providers that have been unable to access Change Healthcare’s services due to the shutdown of its computer networks after a Blackcat ransomware attack. Without access to those systems, healthcare providers have been unable to get paid for the medical services they have provided while Change Healthcare’s systems have been offline. Many of the affected healthcare providers have limited financial resources to cover payroll and operating expenses, which have been rapidly drained. The severe delays in processing claims and revenue cycle services have pushed many healthcare providers close to bankruptcy. Last week, a class action lawsuit was filed on behalf of a women’s healthcare practice in Albany, MS, and other healthcare providers that have suffered delays processing claims and revenue cycle services. Like many healthcare providers, Advanced Obstetrics & Gynecology PC has limited liquidity and relies on the prompt payment of claims to keep the business afloat. The lawsuit...
Concentra Health Services Sued Over PJ&A Data Breach
Concentra Health Services is facing a class action lawsuit over a data breach at one of its business associates that exposed the data of almost 4 million of its patients. Concentra used the transcription service provider PJ&A and during the normal course of business, PJ&A had access to patients protected health information (PHI). PJ&A detected suspicious activity within its network on May 2, 2023, and the forensic investigation confirmed that unauthorized individuals had access to its systems between March 27, 2023, and May 2, 2023, and acquired sensitive information. In January 2024, Concentra confirmed that the PHI of 3,998,162 patients was compromised in the attack. In total, the PJ&A data breach is known to have affected more than 14 million individuals. A lawsuit has recently been filed against Concentra Health Services Inc., its parent company Select Medical Holdings Inc., and Perry Johnson & Associates Inc., by plaintiff Stephen Tate, whose sensitive information was compromised in the attack. According to the lawsuit, the hackers behind the attack...



