Patient Data Exposed in Phishing Attack on UC San Diego Health
Data breaches have recently been reported by UC San Diego Health, Littleton Regional Healthcare, UT Southwestern Medical Center, and the Texas Health and Human Services Commission UC San Diego Health Discloses January Phishing Attack UC San Diego Health has recently notified the California Attorney General about a phishing attack that was discovered on January 9, 2024, which exposed the sensitive data of patients. Two Hillcrest Medical Center employees responded to the phishing emails and disclosed their credentials, which allowed their email accounts to be accessed by unauthorized individuals. UC San Diego Health said the email accounts were accessed for brief periods between January 9, 2024, and January 22, 2024. A review of the exposed emails and attachments was completed on February 26, 2024, and confirmed that they contained patients’ protected health information such as names, Social Security numbers, and one or more of the following: mailing address; email address; date of birth; medical record number; health insurance information; treatment cost information; and/or...
63% of Known Exploited Vulnerabilities Can be Found in Hospital Networks
A typical U.S. hospital has between 10 and 15 medical devices per bed, which means a 1,000-bed hospital could have around 15,000 medical devices. Those devices include imaging devices, clinical IoT devices, and surgery devices, and they significantly increase the attack surface. A vulnerability in any of those devices could be exploited by a threat actor to gain access to the internal network and sensitive data, especially vulnerabilities in internet-facing devices. Research conducted by the cyber-physical systems (CPS) protection company Claroty – published in Claroty’s State of CPS Security Report: Healthcare 2023 Report – has revealed hospitals are not keeping their medical devices up to date. The researchers found that 63% of the vulnerabilities in the Cybersecurity and Infrastructure Security Agency’s (CISA) Known Exploited Vulnerabilities (KEV) Catalog can be found on healthcare networks, 23% of medical devices have at least one known exploited vulnerability, and 14% of medical devices are running an unsupported or end-of-life operating system. The study found 22% of...
FBI Data Shows Ransomware Attack Surge as Cybercrime Losses Reach $12.5 Billion
In 2023, the Federal Bureau of Investigation’s Internet Crime Complaint Center (IC3) received record numbers of complaints about cybercrime with losses increasing by 22% to a record-breaking $12.5 billion, according to the 2023 FBI Internet Crime Report. ICR registered 880,418 complaints in 2023, up 10% from 2022, with phishing/spoofing the most commonly reported cybercrime with 298,878 complaints, followed by personal data breaches (55,851 complaints) and non-payment/non-delivery (50,523 complaints). The costliest type of cybercrime was investment fraud, with losses increasing from $3.31 billion in 2022 to $4.57 billion in 2023 – a 38% increase. The second biggest cause of losses to cybercrime was business email compromise (BEC) with $2.9 billion in reported losses across 21,489 complaints, followed by tech support scams with 37,560 complaints and $1.3 billion in reported losses. IC3 received 2,825 complaints related to ransomware, including 1,193 ransomware complaints from critical infrastructure entities, up 18% from 2022. Healthcare was the worst affected sector with 249...
Cyberattacks on Eastern Radiologists and UNITE HERE Affect 1,680,000 Individuals
Major data breaches have been reported by Eastern Radiologists, Inc. in North Carolina and the New York-based labor union, UNITE HERE. The protected health information of almost 1,680,000 individuals has been compromised in these two incidents. Eastern Radiologists, Inc. Data Breach Affects Almost 887,000 Individuals Greenville, NC-based Eastern Radiologists, Inc. has recently notified 886,746 individuals that some of their HIPAA protected health information was exposed and potentially obtained by unauthorized individuals in a cyberattack that was detected on November 24, 2023. A third-party cybersecurity firm was engaged to investigate the cause of suspicious network activity and confirmed that there was unauthorized access to its network between November 20, 2023, and November 24, 2023. During that time, documents on the system were accessed and copied, some of which contained patient information. The investigation was completed on January 26, 2024, and confirmed that the exposed information included patients’ names plus one or more of the following: contact information, Social...
Sources for HHS OIG Fraud, Waste, and Abuse Guidelines
The HHS OIG fraud, waste, and abuse guidelines are intended to support healthcare organizations in their efforts to self-monitor compliance with all applicable laws and program requirements. The guidelines can be found in many different sources, including guidance documents, advisory opinions, online training programs, and the HHS OIG YouTube channel. The healthcare industry is one of the most highly regulated industries in the U.S. Federal rules and regulations exist that govern patient safety (i.e., PSQIA), data security (i.e., HIPAA), and the physical environment (i.e., OSHA). In addition, each state has its own requirements for licensing healthcare organizations and healthcare practitioners. Failure to comply with these rules, regulations, and requirements can result in fines, facility closures, and/or loss of license. However, the most substantial penalties for non-compliance are often reserved for offenses against the federal government – particularly offenses that relate to fraud, waste, and abuse against a healthcare program operated by the Department of Health and Human...



