Reader Offer: Free HIPAA Compliance Checklist
As a Covered Entity or Business Associate, it is important to be aware of which HIPAA compliance standards apply to your organization. Do you have the correct procedures in place to avoid costly data breaches, HIPAA violations, and regulatory fines? Find out now with our comprehensive HIPAA Compliance Checklist that has been compiled by leading compliance experts. Use the form to download this checklist. Non Compliance Is Not An Option HIPAA compliance standards are enforced by HHS Office of Civil Rights, the Centres for Medicare and Medicaid, and the Federal Trade...
Feds Issue Snatch Ransomware Warning Following Attack on Hospital
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) and the Federal Bureau of Investigation (FBI) have issued a joint security advisory about Snatch ransomware. The Snatch ransomware group has recently conducted an attack on a hospital in Maine and has claimed responsibility for an attack on the Florida Department of Veterans Affairs. The group poses a significant threat to the healthcare and public health (HPH) sector. Snatch ransomware is not a new ransomware variant, having first been detected in 2018, but CISA and the FBI say the group has recently been observed using new tactics, techniques, and procedures (TTPs) in its attacks. The timing of the alert may also have been prompted by an uptick in attacks over the past few months. Snatch ransomware was used in the May 2023 attack on Mount Desert Island Hospital and the group recently leaked more than 260GB of data that was stolen in the attack, and the group has targeted several critical infrastructure sectors. Snatch ransomware is offered under the ransomware-as-a-service (RaaS) model, where affiliates are...
PurFoods Sued Over 1.2 Million-Record Mom’s Meal Data Breach
PurFoods LLC is being sued over a cyberattack that exposed the personally identifiable information (PII) and protected health information (PHI) of 1,237,681 individuals who used the services of its subsidiary, Mom’s Meals. Through Mom’s Meals, PurFoods provides a food delivery service for Medicare, Medicaid, and self-pay individuals with chronic health conditions. According to the Mom’s Meals data breach notifications, the company experienced a cyberattack that saw unauthorized individuals access its network between January 16 and February 22, 2023, and deploy software (ransomware) to encrypt files on the network. While data theft was not confirmed, the possibility of data exfiltration could not be ruled out. The review of the affected files was completed on July 10, 2023, and confirmed that names, Social Security numbers, driver’s license numbers, state identification numbers, financial account and payment card information, medical record numbers, health information, treatment information, diagnosis codes, meal categories and costs, health insurance information and patient...
Health Care Service Corporation Facing Class Action Data Breach Lawsuit
A lawsuit has been filed against the Chicago, IL-based health insurer and Blue Cross Blue Shield licensee, Health Care Service Corporation (HCSC), over a recently disclosed data breach that affected 192,231 of its members. HCSC experienced a cyberattack on or around June 21, 2023, and determined the threat actors had access to member information such as names, addresses, phone numbers, email addresses, dates of birth, Social Security numbers, claim numbers, bank account numbers, and medical service information. Notification letters were sent to the affected individuals on August 21, 2023. A lawsuit was recently filed in the Circuit Court of Cook County in Illinois on behalf of plaintiff Elizabeth Slaughter and other similarly situated individuals. The lawsuit alleges HCSC disregarded the rights of the plaintiff and class members by “intentionally, willfully, recklessly, or negligently failing to take and implement adequate and reasonable measures to ensure PHI/PII was safeguarded,” such as encrypting data on its network, and HCSC did not meet its data security obligations under the...
Is Airdroid Business HIPAA Compliant?
Airdroid is a HIPAA-compliant all-in-one Android Mobile Device Management (MDM) solution for small businesses and enterprises that can be used by HIPAA-covered entities and their business associates to improve privacy and comply with many provisions of the HIPAA Security Rule. Managing increasing numbers of mobile devices can be a major challenge for healthcare organizations. Mobile devices can be used to access and store protected health information and if a device is lost or stolen, sensitive data could easily be exposed. Vulnerabilities in mobile devices and mobile applications can easily be missed and can be exploited by malicious actors to gain access to PHI. Compromised devices may also be used as a stepping stone in a broader attack on the organization. The problem for IT teams is they often do not have visibility into mobile devices so ensuring the devices are kept up to date and secured can be a major challenge. An MDM solution makes managing mobile devices much more straightforward. These solutions provide IT teams with full visibility into their mobile devices, no...



