Is Postmark HIPAA Compliant?
Postmark is not HIPAA compliant and cannot be used by HIPAA covered organizations to send emails containing Protected Health Information (PHI) unless the subject of the PHI has provided an authorization allowing the disclosure of their PHI. While this scenario is unlikely for bulk mail, there are occasions when a non-compliant service can be used for “consented” transactional emails. Postmark (also known as Postmark App) is an email service provider that provides SMTP services to improve the delivery speed and delivery rates of bulk email (i.e., marketing emails, newsletters, etc.), and the accountability of transactional emails (i.e., welcome emails, password reset emails, etc.). Email service providers such as Postmark can be valuable to organizations that want to run large email promotions, but who need to keep their own mail servers free for operational purposes. With regards to the question is Postmark HIPAA compliant, the email service only needs to be HIPAA compliant if outbound emails contain PHI. When marketing emails, newsletters, and other general healthcare bulletins...
1.3 Million-Record Database of Netherlands COVID-19 Testing Lab Exposed Online
A medical laboratory in the Netherlands that served as a COVID-19 testing facility has left a database exposed on the Internet that contained the sensitive data of almost 1.3 million individuals including names, dates of birth, appointment details, email addresses, COVID-19 testing information, and passport numbers. The exposed database was found by Jeremiah Fowler, co-founder of Security Discovery and security researcher at vpnMentor. The database did not require any authentication to access and the entire database could be accessed by anyone who knew the path name. The database included an estimated 1,285,277 records, including 118,441 certificates, 506,663 appointments, 660,173 testing samples, and a small number of internal application files. The database also contained thousands of QR codes that linked to web pages that included appointment details and email addresses. The documents had the name and logo of a now inaccessible website, Coronalab.eu, which belongs to Coronalab. Coronalab is owned by the Amsterdam-based ISO-certified laboratory, Microbe & Lab, one of the top...
HHS Unveils Voluntary HPH Cybersecurity Performance Goals
The Department of Health and Human Services (HHS) has unveiled the Cybersecurity Performance Goals (CPGs) that were outlined in its December 2023 Healthcare Sector Cybersecurity Strategy. These voluntary goals will help healthcare organizations take the necessary steps to improve cybersecurity and guide them through implementing high-impact measures to quickly improve resilience to cyber threats and recover quickly should their defenses be breached. Cyberattacks on healthcare organizations have increased significantly in recent years with 2023 breaking records for the number of notified HIPAA data breaches (725) and the number of breached records (133M). The HHS Cybersecurity Strategy aims to help the healthcare and public health (HPH) sector prepare for and respond to cyber threats, adapt to a rapidly changing threat landscape, and improve cyber resilience across the sector, with the establishment of voluntary cybersecurity goals the first step in that process. The voluntary CPGs will help HPH sector organizations prioritize the implementation of high-impact cybersecurity...
Transformative Healthcare Sued Over Fallon Ambulances Service Data Breach
Transformative Healthcare is facing legal action over a recently disclosed data breach that affected 911,757 patients of the Fallon Ambulance Service. The lawsuit also names Coastal Medical Transportation Systems, LLC, as a defendant. Coastal Medical Transportation Systems acquired Fallon Ambulance Services in September 2022, although the data breached was an archive copy of data from before the acquisition. The lawsuit – Daniel Durgin v. Transformative Healthcare, LLC, and Coastal Medical Transportation Systems, LLC – was filed in the U.S. District Court for the District of Massachusetts on January 18, 2023, on behalf of Daniel Durgin, who received emergency medical transportation from the Fallon Ambulance Service before it ceased operations in December 2022. The lawsuit alleges the defendants should have known how to keep sensitive data protected, yet failed to implement reasonable and appropriate cybersecurity measures and comply with industry security standards, which allowed hackers to gain access to the plaintiff’s and class members’ sensitive data. The lawsuit claims...
Russian National Sanctioned for Medibank Ransomware Attack
A Russian national who was involved in a ransomware attack on the Australian health insurance provider Medibank in 2022 has been sanctioned by the governments on Australia, the United States, and the United Kingdom. Alexander Ermakov (aka blade_runner, GistaveDore, GustaveDore, or JimJones), 33, is believed to have been a member of the now-disbanded ransomware group REvil. REvil was one of the most notorious cybercriminal groups until July 2021 when the group ceased operations and disappeared. Prior to that, the group was a ransomware-as-a-service group that encrypted appropriately 175,000 computers and was paid an estimated $200 million in ransom payments from its attacks. In October 2022, REvil gained access to the Medibank network and stole the data of approximately 9.7 million of its customers and then used ransomware to encrypt files. The stolen data included names, dates of birth, Medicare numbers, and highly sensitive medical information including mental health, sexual health and drug use data. As a Russian national, Ermakov is unlikely to face justice for the Revil attacks...



