Lurie Children’s Hospital Restores EHR System a Month After Ransomware Attack
It has been just over a month since Ann & Robert H. Lurie Children’s Hospital in Chicago experienced a ransomware attack that forced it to take down its phone, email, and medical record systems. Lurie Children’s Hospital, which treats more than 220,000 patients a year, detected a breach of its systems on January 31, 2024, and has confirmed that “a known threat actor” gained access to its systems but did not state whether ransomware was used and has yet to confirm the extent of the data breach. The known threat actor is the Rhysida ransomware group, which is a relatively new ransomware-as-a-service operation that has been active since May 2023. The group mostly targets organizations in education, government, and manufacturing; however, several attacks have been conducted on healthcare organizations including Singing River Health System and Prospect Medical Holdings. The group is not a major player in the ransomware market but is a well-established group that conducted at least 74 attacks in 2023 – around 2% of all ransomware attacks globally, and last year was behind 4% of...
Sen. Cassidy Proposes Legislative Updates to Improve Health Data Privacy
Senator Bill Cassidy (R-LA), Ranking Member of the U.S. Senate Health, Education, Labor, and Pensions (HELP) Committee, has published a white paper that proposes updates to the Health Insurance Portability and Accountability Act (HIPAA) to improve privacy protections for health information and urges Congress to take action to expand privacy protections for all health data. The white paper – Strengthening Health Data Privacy for Americans: Addressing the Challenges of the Modern Era – follows Sen. Cassidy’s September 2023 request for information from healthcare industry stakeholders on the current state of HIPAA, how best to enhance health data privacy, and ensure that health data collected by entities that are not bound by HIPAA is also protected. New technologies are being introduced in healthcare and interoperability of health data is increasing, which is helping to improve care and patients’ access to their health information; however, new technology has increased the attack surface and improved access can easily lead to increased vulnerability for inappropriate data...
Multiple Class Action Lawsuits Filed in Response to Change Healthcare Ransomware Attack
Change Healthcare experienced a Blackcat ransomware attack on February 21, 2024, and is still recovering from the incident, with many systems still offline more than 2 weeks after the attack. The Blackcat ransomware group claimed to have stolen 6TB of data before encrypting files and the affiliate behind the attack alleged a $22 million ransom was paid by Optum to have the stolen data and obtain the decryption keys. The affiliate claims the Blackcat group stole the funds and didn’t pay, Blackcat claimed law enforcement shut down its operation, and the affiliate still has 6TB of the stolen data. Nether Change Healthcare, Optum, of their parent company, UnitedHealth Group, have confirmed the extent of any data breach and whether a ransom was paid, only issuing a statement saying they are currently focused on the investigation and bringing their systems back online. Given the history of the Blackcat group, it is likely that the stolen data includes a significant amount of patient data, and with Change Healthcare processing around 15 billion healthcare transactions each year –...
HHS Responds to Change Healthcare Cyberattack with New Flexibilities for Affected Providers
The Department of Health and Human Services (HHS) has issued a statement about the February 2024 Blackcat ransomware attack on UnitedHealth Group-owned Change Healthcare. The attack took more than 100 of Change Healthcare’s systems out of action, which has had far-reaching consequences for the providers that rely on those systems for checking insurance coverage, submitting claims, and getting paid. Several industry groups wrote to the HHS requesting assistance for their members, who are experiencing severe cash flow problems as they have been unable to receive payments without Change Healthcare’s systems. UnitedHealth Group has set up a temporary financial assistance program to help providers who have been unable to receive payments, but the move has been criticized by industry groups due to the limited eligibility and onerous terms. The HHS said it recognized the impact the cyberattack has had on healthcare operations nationwide and that its first priority is to help coordinate efforts to avoid disruptions to care. The HHS is in regular contact with UnitedHealth Group leadership...
Personal Touch Holding Corp. Settles Class Action Data Breach Lawsuit
Personal Touch Holding Corp. has received preliminary approval for a settlement to resolve a class action lawsuit that was filed following a January 2021 ransomware attack and data breach that affected 753,107 patients. The Lake Success, NY-based provider of home health services operates around 30 Personal Touch Home Care subsidiaries in more than half a dozen U.S. states. In January 2021, a ransomware group gained access to cloud-stored business records and the data of 29 of its subsidiaries. Initial access was gained when an employee responded to a phishing email and downloaded malware. Individuals who had previously received services from Personal Touch or its subsidiaries had their names, addresses, telephone numbers, dates of birth, Social Security numbers, financial information, including check copies, credit card numbers, bank account information, medical treatment information, health insurance card, health plan benefit numbers, and medical record numbers compromised in the attack. A class action lawsuit – Everetts v. Personal Touch Holding Corp. – was filed in...



