Keenan & Associates Data Breach Affects More Than 1.5 Million Individuals
The Torrance, CA-based insurance broker Keenan & Associates has recently reported a cybersecurity incident to the Maine Attorney General that has affected 1,509,616 individuals. Keenan & Associates is part of AssuredPartners NL, one of the largest brokerage firms in the United States. The company has clients across a variety of industries, including healthcare and the public sector, and is the third-party administrator of Prime Healthcare’s employee benefit health plan. Prime Healthcare was one of the affected clients. The cybersecurity incident was detected on Sunday, August 27, 2023, when some of its network servers were disrupted. Action was immediately taken to contain the attack and isolate the affected network servers and third-party cybersecurity experts were engaged to investigate to determine the nature and scope of the unauthorized activity. The forensic investigation confirmed that there had been unauthorized access to its internal systems at various points between August 21, 2023, and August 27, 2023, and during that time, certain files were exfiltrated from its...
314,000 Patients Affected by Cyberattack on CompleteCare Health Network
CompleteCare Health Network, a health system serving patients in southern New Jersey, has recently confirmed that the protected health information of 313,973 patients has potentially been compromised in an October 2023 ransomware attack. An unauthorized third party gained access to certain CompleteCare Health Network computer systems and attempted to use ransomware to encrypt files. CompleteCare Health Network said this was a sophisticated ransomware attack that was detected and stopped on or around October 12, 2023. Third-party cybersecurity experts were engaged to investigate the attack and determine the nature of any unauthorized activity, and whether any patient data was involved. The substitute breach notice on the CompleteCare Health Network states, “Please know that we have taken steps to ensure your data will not be further published or distributed,” which appears to confirm that there was data exfiltration, the threat group behind the attack threatened to publish the data, and payment was made to prevent that outcome. CompleteCare Health Network conducted a review of all...
Plaza Radiology Data Breach Affects Up to 569,000 Patients
Plaza Radiology, which does business as Chattanooga Imaging across several locations in Tennessee and North Georgia, has suffered a cyberattack and data breach that has affected up to 569,000 patients. Plaza Radiology identified the cyberattack on October 21, 2023, but did not disclose any details about the nature of the attack, other than stating that the initial results of the forensic investigation confirmed there had been unauthorized access to a small number of files on its network that contained patient information. The analysis of the results from the forensic investigation is ongoing and, at this stage, there have been no reports of any actual or attempted misuse of patient data. Plaza Radiology reported the data breach to the HHS’ Office for Civil Rights on December 20, 2023, and said it will be mailing individual notification letters to the affected patients when the specific individuals affected have been identified and the types of data involved have been determined. Legal counsel for Plaza Radiology confirmed that several steps have been taken in response to the...
Florida Bill Seeks Safe Harbor for Organizations with Robust Cybersecurity Programs
Healthcare organizations and businesses in Florida could soon be given protection against data breach lawsuits if they implement and maintain cybersecurity measures that meet government and industry standards. The Florida Cybersecurity Incident Liability Act (H.B 473) has been introduced in the Florida legislature and aims to introduce a “safe harbor” that limits liability for all businesses that implement reasonable and appropriate cybersecurity measures that meet industry standards and cybersecurity frameworks. Businesses can make significant investments in cybersecurity to protect their networks and sensitive data from unauthorized access, but the sophisticated nature of cyber threats means that cyberattacks may still succeed. It is now common for multiple lawsuits to be filed over data breaches that allege a failure to implement appropriate cybersecurity measures, irrespective of the cybersecurity measures that have been implemented. The Florida Cybersecurity Incident Liability Act is intended to provide businesses with a legal defense against tort claims in data breach...
Is Salesforce HIPAA Compliant?
Salesforce can be used in a HIPAA compliant manner provided uses and disclosures of PHI are limited to services covered by Salesforce’s Business Associate Agreement and that the restrictions to each covered service are complied with. It is also important to be aware that Salesforce’s Business Associate Agreement does not apply to third party integrations with access to PHI. Salesforce is a well-known Customer Relationship Management (CRM) service that facilitates communications between businesses and customers. Through the “marketing cloud”, Salesforce offers products for customer service, data analytics, and marketing, and developers can also build apps on the Salesforce platform. By default, there are a number of features in Salesforce that support its use in a HIPAA-compliant manner. Salesforce has a minimum standard security protocol with a 128- bit encryption key and requires an HTTPS connection – both of which are steps towards protecting data in accordance with the HIPAA Security Rule. However, there are some compliance issues with certain products and services. For...



