Data Breaches Reported by Peerstar, La Red Health Center, Fredericksburg Foot & Ankle Center
Peerstar LLC, a Pennsylvania-based provider of mental health support services, said 11,438 patients have been notified about the exposure and potential theft of their protected health information. Suspicious activity was detected on its network on March 7, 2023, and third-party security experts were engaged to investigate the incident and assess the security of its systems. On May 17, 2023, it was confirmed that an unauthorized third party had access to its systems between February 22, 2023, and March 3, 2023, and protected health information had been exposed. Peerstar said it is unaware of any actual or attempted misuse of patient data. The types of information exposed varied from individual to individual and may have included the following: first and last name, address, phone number, email address, Social Security number, date of birth, admission date, discharge date, physical or mental health condition, treatment and diagnosis information, driver’s license number or government-issued identification number, financial account number, credit or debit card number, digital signature,...
Senate HELP Committee Senator Demands Answers from 23andMe about Data Breach
Earlier this month, the direct-to-consumer genetic testing company 23andMe issued a security alert after the genetic ancestry information of its customers was stolen and listed for sale on hacking forums. A high-ranking member of the Senate Committee on Health, Education, Labor, and Pensions is demanding answers as to how such large-scale data theft was possible and what data protection measures 23andMe had in place. According to 23andMe, its investigation into a security breach found no evidence to indicate its systems were compromised and it concluded that data was stolen in a credential stuffing attack. Credential stuffing involves taking usernames and passwords stolen in a breach on one platform and using those usernames and passwords to try to access accounts on another platform. These attacks are made possible due to users reusing usernames and passwords on multiple platforms. A credential stuffing attack suggests users of the platform are at fault for the exposure of their data due to poor password practices; however, that has not prevented multiple lawsuits from being filed...
Is Calendly HIPAA Compliant?
Calendly is not HIPAA compliant and cannot be used to create, collect, maintain, or transmit Protected Health Information as these uses would be violations of Calendly’s terms of service. Calendly also refuses to enter into Business Associate Agreements with covered entities and upstream business associates. Businesses can waste a considerable amount of time scheduling appointments and meetings. Lengthy email exchanges and phone tag are commonplace. Calendly aims to eliminate the time wasted attempting to connect with others and the platform can reduce no-show rates through automated email and text reminders. The solution integrates with Google Calendar, iCloud calendar, Office 365, Salesforce, and GoToMeeting and other popular software platforms and can also be integrated directly into business websites to allow customers to schedule appointments directly. The platform is used by healthcare organizations for scheduling internal meetings, but in order to use Calendly with any electronic protected health information, healthcare organizations would first need to enter into a...
12 Million Medical Laboratory Records Exposed Online
Hackers can exploit unpatched vulnerabilities and trick employees into providing access, but sometimes huge amounts of sensitive health information are much easier to obtain, as security researcher, Jeremiah Fowler, recently confirmed. One of India’s largest diagnostic centers, Noida, Uttar Pradesh-based Redcliff Labs, serves more than 2.5 million individuals in more than 220 Indian cities and provides a wide range of diagnostic testing services. Fowler found an unsecured Redcliff Labs database that contained the medical test results of more than 12 million individuals. The database had been exposed on the Internet and could be accessed without a password using a web browser, and the contents could be viewed using an open—source viewer or the native viewer provided by the cloud service provider. The 7-terabyte database contained 12,347,297 records that included the names of patients and physicians, the location where the test was performed, test results, and other sensitive data, and a database folder was identified that contained more than 6 million PDF documents of test results....
PHI of University of Michigan Health Service and School of Dentistry Patients Exposed
The University of Michigan (UM) has recently announced it fell victim to a cyberattack in the summer that resulted in unauthorized access to the sensitive data of students, applicants, alumni, donors, employees, contractors, University Health Service and School of Dentistry patients, and research study participants. UM detected suspicious activity within its computer network on August 23, 2023, and took immediate action to contain the incident and prevent further unauthorized access. Third-party cybersecurity experts were engaged to assist with the investigation and confirmed that an unauthorized third party had access to its network between August 23, 2023, and August 27, 2023. A review was conducted to identify files that may have been accessed and the types of data involved. The exposed data varied from individual to individual and may have included the following: Students, applicants, alumni, donors, employees, and contractors: Name, Social Security number, driver’s license or other government-issued ID number, financial account or payment card number, and/or health...



