CISA & HHS Release Healthcare Cybersecurity Toolkit
The Cybersecurity and Infrastructure Security Agency (CISA) and the Department of Health and Human Services (HHS) have collaborated and produced a cybersecurity toolkit for the U.S. healthcare and public health (HPH) sector. The toolkit consolidates key resources such as CISA’s Cyber Hygiene Services, the HHS Health Industry Cybersecurity Practices, and the HHS and Health Sector Coordinating Council’s (HSCC) HPH Sector Cybersecurity Framework Implementation Guide. The toolkit includes resources, tools, training material, and information for HPH sector organizations at every level, from fundamental cybersecurity hygiene best practices to advanced and complex cybersecurity tools for strengthening security posture and keeping up to date on current and emerging threats. The toolkit was released ahead of a roundtable discussion co-hosted by CISA and the HHS on the threats faced by the U.S. healthcare sector and to identify ways that the federal government and the healthcare industry can work together to close gaps in resources and cyber capabilities. Cyberattacks on hospitals and health...
Cyberattacks Reported by Brooklyn Premier Orthopedics & Atlas Healthcare
Brooklyn Premier Orthopedics (BPO) in New York has confirmed the protected health information of 48,459 patients may have been viewed or obtained in a recent cyberattack. According to BPO’s October 5, 2023, breach notice, unauthorized individuals gained access to parts of its network where patient data was stored, including names, addresses, dates of birth, Social Security numbers, and medical treatment information. The investigation did not uncover any evidence to indicate any of that information has been misused; however, the affected patients have been advised to be vigilant and monitor their accounts carefully. Complimentary credit monitoring and identity theft protection services have been offered. BPO has reviewed and enhanced its security policies and practices to reduce the likelihood of similar incidents occurring in the future. Almost 11,000 Atlas Healthcare Residents and Patients Affected by Cyberattack The Connecticut senior living and care provider, Atlas Healthcare, has warned 10,831 of its assisted living residents and rehabilitation patients that some of their HIPAA...
HIPAA Data Security Requirements
The HIPAA data security requirements for electronic PHI require covered entities and business associates to ensure the confidentiality, integrity, and availability of ePHI, protect against reasonably anticipated threats, uses, and disclosures, and ensure the workforce complies with the Security Rule. In order to comply with the HIPAA data security requirements, healthcare organizations should have a solid understanding of the HIPAA Security Rule. The HIPAA Security Rule contains the administrative, physical and technical safeguards that stipulate the mechanisms and procedures that have to be in place to ensure the integrity of Protected Health Information (PHI). The Administrative Safeguards primarily concern the requirement to conduct ongoing risk assessments in order to identify potential vulnerabilities and risks to the integrity of PHI. The Physical Safeguards concentrate on the measures that should be implemented to prevent unauthorized access to PHI, and to protect data from fire and other environmental hazards. The Technical Safeguards relate to the controls that have to be...
Wright & Filippis Proposes $2.9 Million Class Action Data Breach Settlement
Wright & Filippis, a Michigan-based provider of prosthetics, orthopedics, and accessibility solutions, has proposed a $2.9 million settlement to resolve claims it failed to protect the personal information of 877,584 individuals. In January 2022, Wright & Filippis fell victim to a ransomware attack. Its security software detected the attack but was unable to prevent file encryption. The forensic investigation confirmed the attackers had access to parts of its network containing the protected health information of more than 877,500 individuals, including names, dates of birth, Social Security numbers, financial account numbers, and health insurance information. Wright & Filippis discovered on or around May 2, 2023, that protected health information had been exposed, and issued notifications to the affected individuals. In the days and weeks following notification, 8 putative class action lawsuits were filed, which were later consolidated into a single lawsuit – In Re Wright & Filippis, LLC Data Security Breach Litigation – that was heard in the U.S....
City of Philadelphia Says PHI Potentially Compromised in May 2023 Email Breach
The City of Philadelphia is investigating a breach of its email environment. Suspicious activity was detected in its email environment on May 24, 2023; however, according to a recent announcement, unauthorized activity continued for a further two months after the breach was first identified. The forensic investigation confirmed there was continued unauthorized access to email accounts until July 28, 2023. Almost a month after the breach was contained, city officials confirmed that some of the compromised email accounts contained personal and protected health information. While the investigation is ongoing and a manual and programmatic review of the email accounts has not yet concluded, affected individuals are known to have had a combination of the following information exposed: names, addresses, dates of birth, other demographic and contact information, Social Security numbers, medical information such as diagnoses and treatment information, and limited financial information, such as claims information. City officials said they will issue notifications to the affected individuals...



