Russian National Sanctioned for Medibank Ransomware Attack
A Russian national who was involved in a ransomware attack on the Australian health insurance provider Medibank in 2022 has been sanctioned by the governments on Australia, the United States, and the United Kingdom. Alexander Ermakov (aka blade_runner, GistaveDore, GustaveDore, or JimJones), 33, is believed to have been a member of the now-disbanded ransomware group REvil. REvil was one of the most notorious cybercriminal groups until July 2021 when the group ceased operations and disappeared. Prior to that, the group was a ransomware-as-a-service group that encrypted appropriately 175,000 computers and was paid an estimated $200 million in ransom payments from its attacks. In October 2022, REvil gained access to the Medibank network and stole the data of approximately 9.7 million of its customers and then used ransomware to encrypt files. The stolen data included names, dates of birth, Medicare numbers, and highly sensitive medical information including mental health, sexual health and drug use data. As a Russian national, Ermakov is unlikely to face justice for the Revil attacks...
Lincare Holdings Proposes $7.25 Million Settlement to Resolve Data Breach Lawsuit
A $7.25 million settlement has been proposed to resolve a class action lawsuit – In re: Lincare Holdings Inc. Data Breach Litigation – filed against Lincare Holdings over a September 2021 data breach that affected 2,918,444 individuals. Lincare Holdings is a provider of in-home respiratory care and equipment. In September 2021, unauthorized activity was detected within its network and the forensic investigation confirmed an unauthorized third party had gained access to files containing patient data. The exposed HIPAA protected health information included names, addresses, Lincare account numbers, dates of birth, treatment information, provider names, dates of service, diagnosis and procedure information, account or record numbers, health insurance information, and prescription information, and for a small number of affected individuals, Social Security numbers. Legal action was taken by the affected individuals who alleged that Lincare Holdings was negligent for failing to implement reasonable and appropriate cybersecurity measures, and had those measures been...
Patch Fortra GoAnywhere Now: Exploit Code Released for Critical Flaw
Fortra has disclosed and patched a critical vulnerability in its GoAnywhere Managed File Transfer (MFT) solution. The vulnerability – CVE-2024-0204 – is an authentication bypass bug due to a path traversal weakness. If exploited, an unauthenticated user can create a new admin user via the administration portal and remotely take control of the customer’s environment and gain access to their network. The vulnerability has a CVSS severity score of 9.8 out of 10. Fortra explained in its security advisory that the vulnerability affects all versions of GoANywhere MFT prior to 7.4.1. All users of the file transfer solution should ensure they update to version 7.4.1 as soon as possible. If it is not possible to immediately upgrade, Fortra has suggested temporary workarounds. For non-container deployments, users should delete the InitialAccountSetup.xhtml file in the install directory and restart the services. For container deployments, the InitialAccountSetup.xhtml file should be deleted and replaced with an empty file, followed by a restart. Managed file transfer solutions are...
Is Intercom HIPAA Compliant?
Intercom is HIPAA compliant and can be used to collect, store, and process electronic Protected Health Information (ePHI) provided organizations subscribe to an “Expert” business plan and agree to the terms of Intercom’s Business Associate Agreement. Thereafter, it is important the software is configured to support HIPAA compliance and that users are trained to operate Intercom in compliance with HIPAA. Intercom is a customer service and engagement solution that enables organizations to provide top-quality support for customers via multiple communication channels. Depending on which business plan an organization subscribes to, the platform can provide proactive support with in-context messaging, an AI-powered workspace, and automated workflows. At the highest “Expert” level, Intercom includes advanced collaboration, security, and reporting tools for large support teams. For organizations in the healthcare sector, customer service and engagement solutions such as Intercom can significantly reduce the volume of resources required to run an efficient support center while providing...
What is a Healthcare Compliance Plan?
A healthcare compliance plan is a document that outlines the compliance obligations of a healthcare organization, lists what measures already exist to fulfil the compliance obligations, identifies gaps in compliance, and determines what measures are required to fill the gaps. A healthcare compliance plan is a valuable tool for organizations subject to multiple federal, state, local, and industry regulations because it can deduplicate compliance requirements and enhance compliance efficiency. Most healthcare organizations are subject to multiple federal, state, local, and industry regulations. In addition, most comply with voluntary standards to achieve or maintain accreditation. If an organization attempted to comply with each regulation and standard individually, it would likely never likely achieve a state of compliance due to number of duplicated regulations, provisions that preempt provisions of other regulations, multiple training requirements, and the speed at which regulations and standards change. A healthcare compliance plan can simplify compliance planning by combining...



