Users of Progress Software WS_FTP Server Urged to Immediately Upgrade
Progress Software, the company behind the MOVEit Transfer file transfer solution that was recently subject to mass hacking and data theft attacks by the Clop threat group, has issued a warning to all users of its WS_FTP Server file transfer software to apply patches to fix 8 vulnerabilities, including two critical flaws that can be exploited in low-complexity attacks that require no user interaction. The vulnerabilities affect the WS_FTP Server Ad hoc Transfer Module and the WS_FTP Server Manager interface. CVE-2023-40444 (CVSS: 10) is a maximum-severity remote code execution vulnerability that affects all versions of WS_FTP Server prior to 8.7.4 and 8.8.2. A pre-authenticated attacker could exploit a .NET deserialization vulnerability in the Ad hoc Transfer Module and remotely execute commands on the underlying WS_FTP Server operating system. CVE-2023-42657 (CVSS: 9.9) is a critical directory traversal vulnerability that affects all versions of WS_FTP Server prior to 8.7.4 and 8.8.2. Successful exploitation of the vulnerability would allow an attacker to perform file operations...
The HIPAA Journal’s Response to Sen. Cassidy’s RFI on Health Data Privacy
Dear Sen. Cassidy, The HIPAA Journal appreciates the opportunity to submit comments per your September 7, 2023, request for information on improving health data privacy while balancing the need to support medical research and medical technology innovation, specifically with respect to potential Health Insurance Portability and Accountability Act (HIPAA) updates. While HIPAA is not perfect, it has served as an effective framework that restricts uses and disclosures of protected health information (PHI) while allowing legitimate uses of healthcare data, and requires covered entities and their business associates that collect, store, maintain, and transmit PHI implement appropriate safeguards to ensure the privacy of PHI. It has been two decades since the HIPAA Privacy and Security Rules were signed into law, during which time the amount of health information collected by non-HIPAA-regulated entities has been increasing to a point where the health data collected by non-HIPAA-covered entities through fitness trackers, mobile devices, and health apps likely exceeds the data collected by...
Interview: Rachel Sheley, Security Strategist/vCISO, GreyCastle Security
The HIPAA Journal has spoken with Rachel Sheley, Security Strategist and Virtual Chief Information Security Officer (vCISO) at GreyCastle Security to find out about her career in the healthcare industry, her current role in cybersecurity, and her experiences with HIPAA compliance. Tell the readers about your career in the healthcare industry. My career in the healthcare industry has been centered around ensuring the confidentiality, integrity, and availability of healthcare data while navigating the complex landscape of healthcare regulations. My expertise in information security, risk management, and compliance is crucial in safeguarding patient information and maintaining the trust of healthcare organizations and their patients. Obtaining the Healthcare Information Security & Privacy Practitioner (HCISPP) certification in 2019 indicates my knowledge of healthcare information security and privacy. This certification is highly relevant in the healthcare sector, as it demonstrates expertise in safeguarding sensitive healthcare data, complying with regulations like HIPAA, and...
Community First Medical Center Suffers 216K-Record Data Breach
Community First Medical Center in Chicago, IL, has started notifying 216,047 patients about a cyberattack that saw an unauthorized third party gain access to its computer systems on July 12, 2023. According to the September 26, 2023, breach notifications, a forensic investigation was launched that determined on July 28, 2023, that the third party had accessed files that contained patients’ protected health information. The types of information compromised in the incident varied from individual to individual and may have included full names, telephone numbers, email addresses, Social Security numbers, medical record numbers, and Medicare numbers. Community First Medical Center said it is unaware of actual or attempted misuse of patient information; however, as a precaution, individuals who had their Social Security numbers exposed have been offered complimentary credit monitoring services. Community First Medical Center said many precautions had been taken prior to the cyberattack to secure patient data and that it will evaluate and modify its security practices to prevent...
CareSource Facing Multiple Class Action Lawsuits Over MOVEit Data Breach
The Dayton, OH-based Medicaid and Medicare plan provider, CareSource, is facing multiple class action lawsuits over a recent cyberattack and data breach. The Clop threat group exploited a zero-day vulnerability in the MOVEit Transfer file transfer solution and obtained the protected health information of 3,180,537 individuals, including names, addresses, date of birth, Social Security Numbers, health plan information, medications, and other health information. CareSource was notified by Progress Software about the vulnerability on May 31, 2023, and patched the flaw on June 1, 2023; however, the vulnerability had already been exploited. CareSource confirmed the breach on June 27, 2023, and notified the affected individuals on August 24, 2023. 2 years of complimentary credit monitoring and identity theft protection services were offered to the affected individuals. Several lawsuits have now been filed against CareSource in response to the data breach. On September 13, 2023, a lawsuit was filed in the U.S. District Court for the Southern District of Ohio Western Division on behalf of...



