Colorado Attorney General Settles Data Breach Investigation with Broomfield Skilled Nursing and Rehabilitation Center
A settlement has been reached between the Colorado Attorney General and Broomfield Skilled Nursing and Rehabilitation Center that resolves alleged violations of Colorado’s data protection laws and the Health Insurance Portability and Accountability Act (HIPAA). Colorado Attorney General, Phil Weiser, launched an investigation of Broomfield Skilled Nursing and Rehabilitation Center in response to a 2021 data breach that exposed the personally identifiable information of hundreds of its patients and employees. Broomfield Skilled Nursing and Rehabilitation Center discovered there had been a security breach on March 3, 2021, when two employee email accounts were found to have email forwarding rules configured that sent emails to an external email address. Broomfield Skilled Nursing and Rehabilitation Center’s forensic investigation determined in April 2021 that an unknown third party had gained access to the email accounts after compromising the employees’ credentials and had set up forwarding rules on both accounts. A vendor was engaged to conduct a review of the accounts, and...
DHS Makes Recommendations to Harmonize Reporting of Cyber Incidents to the Federal Government
The U.S. Department of Homeland Security (DHS) has issued a report to Congress that includes recommendations on how the reporting of cyber incidents to the Federal government can be harmonized to better protect the nation’s critical infrastructure. The Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA) directs the U.S. Cybersecurity and Infrastructure Security Agency (CISA) to develop new cyber incident reporting requirements. Currently, there is a patchwork of cyber incident reporting requirements across the Federal government and the larger ecosystem. Some of the reporting requirements are focused on national security, others on economic security or public safety, and some have consumer, investor, or privacy considerations. To avoid duplication and harmonize cyber incident reporting, CIRCIA established a Cyber Incident Reporting Council (CIRC) which was tasked with coordinating, deconflicting, and harmonizing Federal incident reporting requirements and calls for the Secretary of the DHS to provide a report to Congress that identifies duplicative reporting...
Ransomware Groups are Increasingly Targeting Small Businesses
A new report from Trend Micro shows ransomware attacks have increased by 47% since 2H 2022. While the most prolific ransomware-as-a-service operations continue to go big game hunting, the majority of attacks have been on small businesses where defenses are weaker. Throughout H1, 2023, the most active ransomware groups were LockBit, Clop, and BlackCat, with LockBit behind 1 in 6 ransomware attacks on government agencies on H1 2023. Trend Micro has tracked 522 attacks involving LockBit ransomware, which accounted for 26.09% of all attacks. BlackCat ransomware was used in 212 attacks in H1 2023 (10.59%), and Clop ransomware was used in 202 attacks (10.09%). While there have reportedly been 202 Clop ransomware attacks in H1, 2023, Trend Micro said it has not detected any attempted Clop ransomware attacks on its customers in the first half of the year. Clop was behind two mass exploitation events in H1 2023. The first series of attacks exploited a vulnerability in Fortra’s GoAnywhere file transfer solution in late January, and a second wave of attacks exploited a zero-day vulnerability...
Healthcare Cloud Usage Grows But Protecting PHI Can Be a Challenge
The cloud is taking over from on-premises infrastructures, but healthcare still lags other sectors for cloud adoption. Cloud adoption has accelerated in healthcare since the pandemic as hybrid working gained significant ground. To support a hybrid workforce, improve efficiency, and cut costs, increasing numbers of healthcare organizations have started their transition to cloud infrastructure and data storage. According to Skyhigh Security’s Cloud Adoption Report – Healthcare Edition, around 50% of organizations across all industry sectors have embraced cloud-based services but the figure drops to 25% of healthcare organizations. Across all industries, healthcare organizations store the least amount of sensitive data in the cloud, with only 47% of healthcare organizations using the cloud for sensitive data storage compared to 61% across all industries. The healthcare industry collects huge volumes of sensitive data that information is extremely valuable to cybercriminals and cyberattacks have been increasing. The latest figures from the HHS’ Office for Civil Rights breach portal...
Snatch Ransomware Group Behind Mount Desert Island Hospital Cyberattack
Mount Desert Island Hospital, Inc. (MDIH) in Bay Harbor, ME, has provided a supplemental data breach notification to the Maine Attorney General about a data security incident first reported on July 17, 2023. Suspicious activity was detected within its network on May 7, 2023, and the forensic investigation determined that an unauthorized third party had access to its network between April 28, 2023, and May 7, 2023. MDIH said it initiated a review of the files on the compromised parts of its network and has now confirmed that they contained the personal and protected health information of 32,661 individuals, including 26,046 Maine residents. The exposed information included employee data: names in combination with one or more of the following data elements: date of birth, driver’s license/state identification number, Social Security number, and financial account information. Patient data was also exposed: name, address, date of birth, driver’s license/state identification number, Social Security number, financial account information, medical record number, Medicare or Medicaid...



