Otolaryngology Associates Data Breach Affects Almost 317,000 Patients
A cyber threat actor has tried to extort money from the Indiana ENT specialists, Otolaryngology Associates, after gaining access to its network and exfiltrating patient and employee data. Otolaryngology Associates said its security system generated alerts about a potential intrusion on February 17, 2024, a few hours after the threat actor gained access to the network. Immediate action was taken to secure the network and block the attack, and at no point was access to the network prevented. Three days later on February 20, and again on February 21, a threat actor made contact and claimed to have stolen data in the attack and threatened to publish the stolen data if the ransom was not paid. Third-party forensic experts were engaged to investigate the breach and they determined that the threat actor had not manually accessed files on the network but had run programs that exfiltrated data from internal systems. The forensic investigation was able to narrow down the data that may have been exfiltrated, but it was not possible to determine exactly what types of data had been taken. The...
Email Accounts Compromised at Aveanna Healthcare and UNC Hospitals & School of Medicine
Email accounts have been compromised at the Georgia home health provider Aveanna Healthcare and UNC Hospitals and School of Medicine in North Carolina. Patient data has been exposed and potentially stolen in the attacks. Aveanna Healthcare Aveanna Healthcare, an Atlanta, GA, provider of home health and hospice care, has announced a security breach of its email environment and the exposure of the data of 65,482 patients. Anomalous activity was identified in an employee email account on September 22, 2023. The account was immediately secured, and an investigation was launched to determine the nature of the activity, and whether patient data had been exposed or stolen. The investigation confirmed that an unauthorized third party had gained access to its email environment and potentially obtained files that contained patient information. Third-party specialists were engaged to review the affected files to determine the individuals affected and the types of data that may have been compromised. That process was completed on March 12, 2024, and notification letters started to be mailed to...
Malicious Actor Steals Patient Data from Multiple Ernest Health Hospitals
Ernest Health, the operator of rehabilitation and long-term acute care hospitals in Arizona, California, Colorado, Idaho, Indiana, Montana, New Mexico, Ohio, South Carolina, Texas, Utah, Wisconsin, and Wyoming, has started notifying patients about a recent data security incident involving their personal and protected health information. Ernest Health identified unauthorized activity in its computer systems on February 1, 2024, and the forensic investigation confirmed there had been unauthorized access to systems containing patient data between January 16, 2024, and February 4, 2024, and files were acquired in the attack that included patient information. For the majority of the affected individuals, the compromised data was limited to names, addresses, dates of birth, medical record numbers, health insurance plan member IDs, claims data, diagnosis, and prescription information. Some patients also had their Social Security and/or driver’s license numbers compromised. The security incident affected patients at multiple hospitals in the network, including: Affected Ernest Health...
Weak Cloud Security Controls at the Administration for Children and Families Have Put Sensitive Data at Risk
The Department of Health and Human Services (HHS) Administration for Children and Families (ACF) has put the sensitive data of families and children at risk by failing to address security gaps in its cloud environment, according to a recent audit by the HHS Office of Inspector General (HHS-OIG). HHS-OIG is conducting a series of audits of HHS divisions to determine if they have implemented effective cybersecurity controls for their cloud environments and are compliant with federal security requirements and guidelines. For the audit, HHS-OIG reviewed ACF’s cloud inventory, policies and procedures, and the configuration settings of ACF vulnerability scanners. Penetration tests were also conducted internally and externally on selected cloud information systems and web applications, and phishing tests were conducted on ACF personnel. While ACF had implemented security controls to protect its cloud information systems and data, HHS-OIG identified gaps in its security controls and vulnerabilities that could be exploited by malicious actors to gain access to systems and the sensitive data...
City of Hope Cyberattack Affects 827,000 Individuals
City of Hope, a non-profit clinical research and cancer treatment center in Duarte, California, has confirmed that the personal and protected health information of 827,149 individuals was compromised in a 2023 cyberattack. Suspicious activity was detected within some of its systems on October 13, 2023, and after securing the systems and implementing mitigation measures, a forensic investigation was launched to determine the nature and scope of the incident. A third-party cybersecurity firm assisted with the investigation and confirmed there had been unauthorized access to some of its systems between September 19, 2023, and October 12, 2023. During that time, copies of certain files were exfiltrated from its systems. The delay in issuing notifications was due to the time required to conduct a detailed review of all files on the compromised systems to determine the extent of the data breach. The investigation is ongoing, but City of Hope has confirmed that the files contained personal and protected health information. The types of data involved varied from individual to individual...



