ConsensioHealth Ransomware Attack Affects 61,000 Patients
The Wisconsin-based medical billing service, ConsensioHealth, has recently notified 60,871 individuals about a July 2023 ransomware attack. The attack was discovered on July 3, 2023, when staff were prevented from accessing files on the network. Steps were immediately taken to prevent further unauthorized access and third-party cybersecurity experts were engaged to assist with the investigation and to help determine whether patient data was accessed or copied from its systems. The investigation confirmed that data had been stolen, and on November 7, 2023, it was confirmed that some of those files contained the data of patients of the following covered entities: Emergency Medicine Specialists, S.C. Ascension Wisconsin Wisconsin Urgent Care Kenosha Urgicare Fox Valley Emergency Medicine Dr. Linda Jingle Woundcare Innovations of Golf Land The impacted data varied from individual to individual and may have included the following data types: Name, address, date of birth, driver’s license or other state identification number, Social Security number, account access credentials, health...
What is Healthcare Compliance Policy Management?
Healthcare compliance policy management is an important part of healthcare administration because it helps healthcare organizations and their workforces comply with applicable regulations, standards, and best practices that govern the healthcare industry. However, the effective management of healthcare compliance policies is not without its challenges. Healthcare compliance consists of complying with mandatory standards of federal laws such as HIPAA, OSHA, and the conditions for participation in Medicare and Medicaid, state privacy regulations (i.e., the Texas Medical Records Privacy Act), and voluntary standards such as the Joint Commission Accreditation Standards and the HITRUST Common Security Framework. To support compliance activities, healthcare organizations develop compliance policies that cover elements of their activities such as patient care, data security, workplace safety, and workforce conduct. Systems are put in place to monitor workforce compliance with the policies, and sanctions are applied to workforce members who violate the compliance policies. The Importance...
FTC Prohibits Data Broker from Selling Sensitive Location Data
The Federal Trade Commission (FTC) has announced its first settlement with a data broker over the sale of the precise geolocation data of consumers. Under the terms of the settlement, X-Mode Social is prohibited from selling or sharing sensitive location data with third parties unless it obtains consent from consumers or de-identifies the data. Virginia-based X-Mode Social, now Outlogic LLC, works with app developers and provides a software development kit (SDK) that can be integrated into smartphone apps that allows data to be collected via the apps, including precise geolocation data. Precise geolocation data can identify where an individual lives and works, the residences of friends and family members, and other locations they visit. Some of those locations may be highly sensitive, such as places of worship, domestic violence centers, addiction treatment centers, places offering services to the LGBTQIA+ community, and reproductive health facilities. If precise geolocation data is collected that confirms consumers’ visits to sensitive locations such as reproductive health clinics...
Multiple Threat Groups Exploiting Ivanti VPN/NAS Zero-Days
Urgent action is required to fix two zero day flaws in Ivanti Connect Secure VPN and Policy Secure NAS appliances. The vulnerabilities were discovered by researchers at Volexity and were disclosed by Avanti last week. While they have been exploited in the wild since December 2023 by an Advanced Persistent Threat group, the attacks have been highly targeted and at the time of the disclosure, fewer than 20 customers had been attacked but the situation has now changed. On January 11, 2023, multiple threat actors started mass exploiting the flaws in indiscriminate attacks on businesses of all sizes across multiple sectors. Ivanti will be releasing patches to fix the flaws starting in the week of January 22, 2024, and final patches will be released in the week of February 19, 2024; however, there is a workaround that can prevent exploitation of the flaws until the patches are released Any HIPAA-regulated entity that uses one of the vulnerable products should ensure that the workaround is implemented immediately given the extent to which the flaws are being exploited. The vulnerabilities...
Novant Health Settles $6.6 Million Pixel Privacy Breach Lawsuit
Novant Health has agreed to settle a class action lawsuit that stemmed from its use of tracking pixels on its MyChart patient portal. The pixel code on the patient portal collected the personally identifiable information of users with the goals of “improving access to care through virtual visits and to provide increased accessibility to counter the limitations of in-person care,” however the information collected was also transferred to third-party technology companies that were not authorized to receive the data. The North Carolina Health System was the first healthcare provider to report a pixel-related HIPAA violation to the HHS Office for Civil Rights (OCR). In the summer of 2022, Novant Health said the protected health information of up to 1,362,296 individuals had been disclosed to third parties such as Meta (Facebook) between May 1, 2020, to Aug. 12, 2022. The HIPAA breach was reported several months before OCR issued guidance on HIPAA and tracking pixels confirming that pixel-related disclosures of protected health information to third parties violated the HIPAA...



