Patient Data Stolen from Livanova in October 2023 Ransomware Attack
The medical device manufacturer Livanova, the Massachusetts community behavioral health center Aspire Health Alliance, and Santa Rosa Behavioral Healthcare Hospital in California have experienced ransomware attacks that exposed patient data. Livanova, London, UK Livanova, a UK-headquartered medical device manufacturer specializing in cardiac surgery and neuromodulation devices, has suffered a ransomware attack that disrupted portions of its IT systems. The ransomware attack was discovered on November 19, 2023, and the forensic investigation confirmed that hackers gained access to its network on October 26, 2023. The LockBit ransomware group claimed responsibility for the attack. Livanova announced in a SEC filing in November that it was dealing with a cyberattack; however, it was initially unclear to what extent patient data was involved. On April 10, 2024, Livanova confirmed that the personal and protected health information of U.S. patients had been exfiltrated from its systems in the attack. In an April 25, 2024, announcement, Livanova said the investigation is ongoing however...
Email Breach at Wisconsin Dental Surgery Center Affects 13,000 Patients
Bay Oral Surgery & Implant Center (Bay Oral), a network of oral & maxillofacial dental surgery centers serving the Green Bay, Marinette, and Niagara communities in Wisconsin, has recently reported a data breach to the HHS’ Office for Civil Rights (OCR) that involved the protected health information of 13,055 patients. On February 27, 2024, Bay Oral identified suspicious activity in an employee’s email account. The password for the account was immediately changed to prevent further unauthorized access and a third-party cybersecurity firm was engaged to investigate the incident. The forensic investigation confirmed that an unauthorized individual had installed software and gained access to an employee’s email account on January 18, 2024. The review of the emails and attachments confirmed that patients’ protected health information had been exposed. The types of information involved included names, addresses, email addresses, dates of birth, Social Security numbers, insurance card numbers, credit card numbers, banking account information, x-rays, patient health history forms,...
Which Section of the OSH Act Prevents Employers Discriminating Against Employees?
Section 11(c) of the OSH Act prevents employers discriminating against employees when they exercise their rights to engage in a protected activity as defined by the Occupational Safety and Health Act. However, before filing an 11(c) complaint with OSHA, it is important to understand what activities are protected and what OSHA defines as discrimination. One of the goals of the Occupational Safety and Health Act (OSH Act) is to involve workers in workplace safety and health (§1977.1(c)). To achieve this goal, the OSH Act encourages employers to create workplace environments in which employees feel comfortable asking questions, voicing concerns, or reporting injuries and illnesses without fear of discrimination. If employers fail to create a suitable environment, and are not responsive to employees’ concerns, the OSH Act gives employees the right to escalate their concerns to the Occupational Safety and Health Administration (OSHA). Section 11(c) of the OSH Act prevents employers discriminating against employees when they exercise this right – and several others. What Employee...
FTC Issues Final Rule Updating Health Breach Notification Rule
The Federal Trade Commission (FTC) issued a final rule on April 26, 2024, that updates the FTC Health Breach Notification Rule. The update includes revised definitions that encompass health apps and other technologies not covered by the Health Insurance Portability and Accountability Act (HIPAA), clarification of what the FTC considers a breach of security, new requirements for the content of breach notifications, changes to the timeframe for issuing notifications, and an expansion of the permitted methods for notifying consumers. “Protecting consumers’ sensitive health data is a high priority for the FTC,” said Samuel Levine, Director of the FTC’s Bureau of Consumer Protection. “With the increasing use of health apps and connected devices, the updated HBNR will ensure it keeps pace with changes in the health marketplace.” The Health Breach Notification Rule applies to vendors of personal health records (PHRs) and related entities that are not covered by HIPAA and requires them to notify individuals in the event of a breach of unsecured personally identifiable health data, and in...
Health Data Analytics Firm Reports 1.1-Million Record Data Breach
A Portland, ME-based accounting and consulting firm has recently reported a data breach to the Maine Attorney General that involved the personal information of 1,107,354 individuals. Berry, Dunn, McNeil & Parker, LLC (BerryDunn) provides health data analytics services to healthcare providers, health insurers, and government regulatory and healthcare policy agencies and its clients provide BerryDunn with personal and health data to allow the firm to perform its contracted services. BerryDunn’s Health Analytics Practice Group (HAPG) contracted with a managed service provider (MSP) called Reliable Networks of Maine, LLC, which manages systems on behalf of HAPG. According to BerryDunn’s breach notice, Reliable Networks notified HAPG on September 14, 2023, that it had identified suspicious activity on its network, including in the systems it manages for HAPG. BerryDunn immediately initiated its incident response protocols and brought in third-party cybersecurity experts to investigate to determine the extent to which client data was involved. BerryDunn immediately initiated...



