Singing River Health System Confirms Ransomware Attack Affected 895,000 Patients
Singing River Health System has confirmed that 895,204 individuals were affected by an August 2023 ransomware attack. Data breaches have also been reported by Highlands Oncology Group, Fincantieri Marine Group, Senior Scripts, and Family Healthcare. Singing River Health System Singing River Health System in Mississippi experienced a ransomware attack in August 2023 that took its IT systems out of action for several days, including its electronic medical record system. Without access to patient data and essential IT systems, operations were disrupted, although care continued to be provided to patients throughout. The Rhysida ransomware group claimed responsibility for the attack. The attack was detected on August 19, 2023, and the forensic investigation confirmed there had been unauthorized network access between August 16 and August 18, 2023. When the initial announcement about the attack was made, it was unclear if any patient data had been compromised and as the deadline for reporting the breach to the HHS’ Office for Civil Rights approached it was still unclear exactly how many...
Electrostim Medical Services Data Breach Impacts 543,000 Patients
The Florida medical device company Electrostim Medical Services, Inc., which does business as EMSI, has recently confirmed that it suffered a cyberattack in May 2023 which involved access to parts of the network containing patient data. The Electrostim Medical Services data breach has recently been reported to the HHS’ Office for Civil Rights as affecting 542,990 patients. Suspicious activity was detected within its network on May 13, 2023, and after securing its systems, third-party cybersecurity specialists were engaged to assess the nature and scope of the incident. The investigation confirmed that unauthorized individuals had access to its network for around two weeks between April 27, 2023, and May 13, 2023. While data theft was not confirmed, the unauthorized individuals had access to parts of the network containing patients’ protected health information and that information may have been copied. Electrostim Medical Services said it has not learned of any instances of attempted or actual misuse of patient data as a result of the security incident. The breach notifications...
ConsensioHealth Ransomware Attack Affects 61,000 Patients
The Wisconsin-based medical billing service, ConsensioHealth, has recently notified 60,871 individuals about a July 2023 ransomware attack. The attack was discovered on July 3, 2023, when staff were prevented from accessing files on the network. Steps were immediately taken to prevent further unauthorized access and third-party cybersecurity experts were engaged to assist with the investigation and to help determine whether patient data was accessed or copied from its systems. The investigation confirmed that data had been stolen, and on November 7, 2023, it was confirmed that some of those files contained the data of patients of the following covered entities: Emergency Medicine Specialists, S.C. Ascension Wisconsin Wisconsin Urgent Care Kenosha Urgicare Fox Valley Emergency Medicine Dr. Linda Jingle Woundcare Innovations of Golf Land The impacted data varied from individual to individual and may have included the following data types: Name, address, date of birth, driver’s license or other state identification number, Social Security number, account access credentials, health...
What is Healthcare Compliance Policy Management?
Healthcare compliance policy management is an important part of healthcare administration because it helps healthcare organizations and their workforces comply with applicable regulations, standards, and best practices that govern the healthcare industry. However, the effective management of healthcare compliance policies is not without its challenges. Healthcare compliance consists of complying with mandatory standards of federal laws such as HIPAA, OSHA, and the conditions for participation in Medicare and Medicaid, state privacy regulations (i.e., the Texas Medical Records Privacy Act), and voluntary standards such as the Joint Commission Accreditation Standards and the HITRUST Common Security Framework. To support compliance activities, healthcare organizations develop compliance policies that cover elements of their activities such as patient care, data security, workplace safety, and workforce conduct. Systems are put in place to monitor workforce compliance with the policies, and sanctions are applied to workforce members who violate the compliance policies. The Importance...
FTC Prohibits Data Broker from Selling Sensitive Location Data
The Federal Trade Commission (FTC) has announced its first settlement with a data broker over the sale of the precise geolocation data of consumers. Under the terms of the settlement, X-Mode Social is prohibited from selling or sharing sensitive location data with third parties unless it obtains consent from consumers or de-identifies the data. Virginia-based X-Mode Social, now Outlogic LLC, works with app developers and provides a software development kit (SDK) that can be integrated into smartphone apps that allows data to be collected via the apps, including precise geolocation data. Precise geolocation data can identify where an individual lives and works, the residences of friends and family members, and other locations they visit. Some of those locations may be highly sensitive, such as places of worship, domestic violence centers, addiction treatment centers, places offering services to the LGBTQIA+ community, and reproductive health facilities. If precise geolocation data is collected that confirms consumers’ visits to sensitive locations such as reproductive health clinics...



