CarePointe ENT Settles HIPAA Lawsuit with Indiana Attorney General
In late September 2023, Indiana Attorney General Todd Rokita filed a lawsuit against CarePointe ENT over a ransomware attack and data breach that affected 48,742 individuals. A settlement has been reached that will see CarePointe pay $125,000 to resolve alleged violations of the Health Insurance Portability and Accountability (HIPAA) Act and state data privacy and security laws. CarePointe ENT operates three ear, nose, throat, sinus, and hearing centers in Merrillville, Munster & Hobart in Northwest Indiana. On June 25, 2021, CarePointe ENT experienced a ransomware attack which resulted in files being encrypted and data being exfiltrated. The stolen data included names, addresses, dates of birth, Social Security numbers, medical insurance information, and health information. Affected individuals were notified about the data breach in August 2021. AG Rokita launched an investigation into the attack to determine if CarePointe ENT had complied with its obligations under HIPAA and state laws. Despite claiming that it was committed to safeguarding patient information, CarePointe ENT...
Is Google Sheets HIPAA Compliant?
Google Sheets is HIPAA compliant and can be used to create, manage, and share spreadsheets containing Protected Health Information (PHI) provided organizations subscribe to a Google Workspace plan that supports HIPAA compliance and Google Drive is configured to control access to files saved as Google Sheets. In addition, system administrators are required to review and accept Google’s Business Associate Addendum to the Workspace Service Agreement. Under HIPAA Rules, healthcare organizations are required to implement safeguards to ensure the confidentiality, integrity, and availability of PHI. While it is straightforward to implement controls internally to keep data secure, oftentimes third parties are contracted to provide services that require access to PHI. They too must abide by HIPAA Rules covering privacy, security, and breach notifications. A third-party that requires access to PHI – or copies of health data – to perform services on behalf of a covered entity is considered a business associate. A covered entity and business associate must enter into a contract – a...
Is doxy.me HIPAA Compliant?
On paper, doxy.me is HIPAA compliant and – subject to an organization subscribing to a business plan that supports HIPAA compliance – can be used to create, receive, store, and share Protected Health Information. However, concerns exist about the vendor’s understanding of HIPAA compliance and that the platform is unreliable for delivering quality patient care. Doxy.me is telemedicine platform that enables healthcare professionals to communicate remotely with patients via video, audio, and secure text messaging. The platform has been designed for ease-of-use, and – when subscribed to the premium service – healthcare professionals can take advantage of text and email notifications, secure payments, screen sharing, and group calling. In the context of is doxy.me HIPAA compliant, the perception a user might get from reviewing the HIPAA compliant video conferencing page on the doxy.me website is that it is. The page provides an explanation of the HIPAA requirements (albeit incorrect) and a list of capabilities that appears to fulfil these requirements. Doxy.me will also...
Urgent Action Required to Address Critical ownCloud Vulnerabilities
Three critical vulnerabilities in the ownCloud platform have been identified, one of which is being actively exploited. Urgent action is required to address the vulnerabilities to protect sensitive networks and sensitive data. The ownCloud platform is used extensively in healthcare for storing, synchronizing, and sharing files and collaborating and consolidating work processes. As such, the platform is a prime target for malicious actors as it allows them to access highly sensitive data. The Clop hacking groups demonstrated how serious vulnerabilities in file sharing platforms can be, having mass exploited vulnerabilities in Fortra’s GoAnywhere MFT and Progress Software’s MOVEit Transfer solution earlier this year. Security advisories were issued by ownCloud on November 21, 2023, about three vulnerabilities, the most serious of which has a maximum CVSS v3.1 severity score of 10. The remaining two vulnerabilities have been assigned CVSS scores of 9.8 and 9. Evidence of active exploitation of the flaws was identified by the cybersecurity firm Greynoise from November 25, 2023, with...
CitrixBleed Vulnerability Requires Urgent Action as Ransomware Groups Scale Up Attacks
Concern is growing as ransomware groups ramp up exploitation of a critical vulnerability in NetScaler ADS (formerly Citrix ADC) and NetScaler Gateway (Citrix Gateway) devices, dubbed CitrixBleed. Citrix issued a security advisory about the vulnerability on October 10, 2023, and issued a patch to correct the flaw, which can be exploited to bypass password protection and multifactor authentication. The buffer overflow vulnerability is tracked as CVE-2023-4966 and has a CVSS severity score of 9.4 out of 10. The vulnerability appears to have been exploited in the wild since August 2023. The vulnerability is easy to exploit and allows threat actors to take over legitimate user sessions. Once initial access has been gained, threat actors can elevate privileges, harvest credentials, move laterally, and access sensitive data and resources. The vulnerability affects the following NetScaler ADC and Gateway versions: NetScaler ADC and NetScaler Gateway 14.1-8.50 and later releases NetScaler ADC and NetScaler Gateway 13.1-49.15 and later releases of 13.1 NetScaler ADC and NetScaler Gateway...



