FDA Releases Guidance on Managing Legacy Medical Device Cybersecurity Risks
The U.S. Food and Drug Administration (FDA) has published a report it commissioned that makes recommendations on how to manage the cybersecurity risks of legacy medical devices. Legacy medical devices are classed as devices that can no longer be reasonably protected against current cybersecurity threats, even though they may still adequately perform their primary function and have a useful life beyond the declared end-of-support or end-of-life date. When medical devices reach end-of-life, patches stop being released to fix vulnerabilities, and unpatched vulnerabilities can be exploited to gain access to the devices and networks to which they are connected. In many cases, the vendors of the devices cannot continue to issue software patches due to outdated technology and compatibility issues and healthcare delivery organizations (HDOs) may not be able to replace them due to the high cost of doing so. If the devices were to be removed from use, it could have serious implications for patient safety and clinical operations. Medical devices are regulated by the FDA, which was tasked by...
Is Zelle HIPAA Compliant?
By default, Zelle is HIPAA compliant for receiving payments initiated by patients and plan members because payment processors are exempted from HIPAA compliance by Section 1179 of the HIPAA Act. However, there are concerns that users of this payment service have been targeted in phishing attacks, and it advisable to warn users of this threat. Zelle is a person-to-person money transfer service – similar to PayPal or Venmo – that is only just starting to branch out into payment processing for businesses. The service enables businesses to accept payments via money transfer from any customer with a Zelle account or who has a Zelle payment option in their existing online banking app. In the context of is Zelle HIPAA compliant, if a covered entity wants to offer the service as a payment option, HIPAA compliance is not a factor. HIPAA (section 1179) excludes financial institutions from Privacy Rule standards when “authorizing, processing, clearing, settling, billing, transferring, reconciling or collecting, a payment for, or related to, health plan premiums or health care”. This...
Healthcare Data Breach Round-Up: November 16, 2023
Medical Eye Services (CA), Prospect Medical Services (CA), McAlester Regional Health Center (OK), PeakMed (CO), Catholic Charities of Long Island (NY), & The Endocrine and Psychiatry Center (TX) have recently notified patients that their personal and health information has been exposed. Medical Eye Services Says PHI of 370,000 Patients Stolen in MOVEit Transfer Hack California-based Medical Eye Services, Inc. has recently confirmed that the protected health information of 346,828 individuals was stolen from the MOVEIt Transfer server used by the vision benefits management provider, MESVision, between May 28, 2023, and May 31, 2023. In total, the sensitive data of 664,824 individuals was compromised, according to the breach report submitted to the Maine Attorney General. A zero-day vulnerability was exploited by the Clop cyber threat group, as part of a series of attacks on more than 2,300 organizations globally. MESVision discovered it had been affected on August 23, 2023, and has since rebuilt its MOVEit server and implemented additional technical safeguards to prevent further...
Feds Issue Updated Mitigations for Blocking Rhysida Ransomware Attacks
A joint cybersecurity advisory has been issued by the U.S. Cybersecurity and Infrastructure Security Agency (CISA), Federal Bureau of Investigation (FBI), and the Multi-State Information Sharing and Analysis Center (MS-ISAC) about Rhysida ransomware. Rhysida ransomware is a ransomware-as-a-service (RaaS) operation that first emerged in May 2023. The group engages in double extortion tactics, involving data theft and encryption, with ransom payment required to obtain the keys to decrypt files and prevent the public release of stolen data. Researchers at Check Point identified significant similarities between Rhysida ransomware and Vice Society, one of the most prolific ransomware groups since 2021 that aggressively targeted the education and healthcare sectors. In August 2023, the HHS’ Health Sector Cybersecurity Coordination Center (HC3) issued its own advisory about Rhysida ransomware following several attacks on the healthcare sector, including the attack on Prospect Medical Holdings, which affected 17 hospitals and 166 clinics across the United States. The latest cybersecurity...
OSHA Publishes 7 Year Lookback Report
The Occupational Safety and Health Administration (OSHA) has published a 7-Year Lookback Report that summarizes employer-reported inpatient hospitalizations, amputations, and eye losses from 2015 to 2021. Since 2015, employers have been required to submit a Severe Injury Report to OSHA within twenty-four hours if an employee is admitted to hospital, has a body part amputated, or loses an eye due to a workplace accident. Since the reporting requirement began, federal OSHA has received 70,206 Severe Injury Reports. The agency has now compiled the reports into a 7-Year Lookback Report which analyzes the injuries by industry, geography, and injury type. COVID-19 Impacts Data Analysis Hospitalizations attributable to workplace-acquired COVID-19 are mostly excluded from the 7-Year Lookback Report because employers are only required to report hospitalizations that occur within twenty-four hours of the work-related incident responsible for the hospitalization, and the mean incubation period for COVID-19 is three to six days. Nonetheless, the virus had an impact on the number of Severe...



