Kroger Sued for Disclosing Pharmacy Patient Data via Meta Pixel Tool
The supermarket chain, Kroger, is being sued over the alleged unlawful practice of using tracking technologies on its website to collect the sensitive data of its customers and impermissibly disclosing that information to third parties such as Meta Platforms. The lawsuit was filed in the U.S. District Court of the Southern District of Ohio, Western Division, on behalf of the anonymous plaintiff, Jane Doe, and other similarly situated individuals whose privacy was violated. The lawsuit alleges that patients of the Kroger pharmacy were not made aware that their personal information was being collected and disclosed to third parties. According to the lawsuit, “[The website Kroger.com] surreptitiously manipulated their web browsers, thereby causing their communications with the Defendant via the Website to be shared and/or intercepted by unauthorized third parties.” Individuals who used the Kroger.com website to submit prescriptions disclosed confidential health information on the site such as the names of their prescription medications, the dosage and form of the medications, and...
Ardent Health Services Ransomware Attack Affects Hospitals in Multiple States
Brentwood, Tennessee-based Ardent Health Services, which operates 30 hospitals and has more than 200 sites of care in 6 U.S. states has suffered a ransomware attack that has impacted multiple hospitals. The attack has resulted in emergency rooms being placed on divert, with new emergency patients redirected to alternate healthcare facilities. Without access to IT systems, some non-urgent elective surgeries have been canceled and will be rescheduled when access is restored to IT systems. Several Ardent Health Services facilities had already announced over the Thanksgiving weekend that they were investigating network outages that started on Thanksgiving Day. Emergency downtime protocols had been implemented and patient information was being recorded using pen and paper due to the lack of access to IT systems and patient data. Ardent Health Services issued a statement on Monday confirming that the disruption had been caused by a ransomware attack. Unauthorized activity was first detected on the morning of November 23, 2023, and it was subsequently determined to have been caused by a...
What is a HIPAA Compliant Cloud Drive?
A HIPAA compliant cloud drive is a cloud-based file storage service that has the capabilities to support HIPAA compliance, that is configured to comply with the standards of the HIPAA Security Rule, and that is used compliantly by trained members of the workforce. Since the passage of HIPAA, many healthcare organizations have adopted cloud-based services; and, when these are used to create, receive, maintain, or transmit Protected Health Information, it is important they comply with HIPAA. HIPAA and Cloud Computing The Health Insurance Portability and Accountability Act was enacted just as the use of cloud-based services started to gain popularity in the 1990s. However, it was not until the early 2000s that cloud computing really took off – although healthcare organizations were slow to embrace the cloud. The situation is very different today. According to Market Data Forecast, in 2022 the healthcare cloud computing market was worth $5.22 billion and it is expected to reach $201.1 billion by 2032. 90% of healthcare organizations are already using cloud-based services or plan...
Multiple Healthcare Providers Affected by Thanksgiving Ransomware Attack
Cyber actors often time their attacks to coincide with holiday periods when IT staffing levels are likely to be reduced to increase the probability of being able to access networks and exfiltrate data undetected, especially during Thanksgiving weekend. This year is no exception. Several healthcare providers have announced that they are currently investigating potential cyberattacks that were detected on or just before Thanksgiving Day. Initially, the cause of the outages was unclear but it has since been determined that this was a ransomware attack on Ardent Health Services. At such an early stage in the investigations, it is unclear if patient data has been exposed or stolen. UT Health East Texas, Texas Tyler, TX-based UT Health East Texas, the operator of 10 hospitals and more than 90 healthcare clinics in East Texas, has confirmed that it experienced a network outage on Thursday, November 24, 2023. Steps were immediately taken to lock down its network to prevent any further unauthorized access. Without access to critical IT systems, ambulances were put on divert; however, care...
Mission Community Hospital Alerts Patients About May 2023 Cyberattack
Mission Community Hospital, an acute care hospital serving the patients of the San Fernando Valley in California, has started notifying patients that some of their personal and protected health information was exposed in a May 2023 cyberattack. Unauthorized access to its network was discovered on May 1, 2023, and the forensic investigation determined that an unauthorized third party accessed its network the same day, including files that contained patient data. The review of the files revealed they contained names, addresses, dates of birth, Social Security numbers, driver’s license numbers, financial account information, health insurance plan member IDs, claims data, and clinical information related to the care received at Mission Community Hospital. Affected individuals have been offered a complimentary one-year membership to a credit monitoring and identity theft protection service. Mission Community Hospital said it has implemented additional safeguards and technical security measures to further protect and monitor its systems. The HHS’ Office for Civil Rights breach portal...



