Views on FTC’s Proposed Health Breach Notification Rule Update
In May 2023, the Federal Trade Commission (FTC) proposed changes to the Health Breach Notification Rule following a 10-year review of the rule. The proposed changes are intended to modernize the rule and make it fit for purpose in the digital age. A lot has changed since the Health Breach Notification Rule was introduced. Huge amounts of health data are now collected and shared by direct-to-consumer technologies such as health apps and wearable devices. These apps and devices can collect highly sensitive health data, yet the information collected is generally not protected by the HIPAA Rules. The proposed update to the Health Breach Notification Rule includes changes to definitions to make it clear that vendors of personal health records (PHRs) and related entities that are not covered by HIPAA are required to issue notifications after an impermissible disclosure of their health data. The definition of a ‘breach of security’ has been changed to make it clear that a breach includes the unauthorized acquisition of identifiable health information, either by a security breach or an...
Federal Judge Tentatively Advances Meta Pixel Medical Privacy Class Action
A class action lawsuit against Meta over the disclosure of health data to the social media giant has been allowed to proceed by a federal judge. The judge issued a tentative order allowing the lawsuit to advance for several of the claims made by the plaintiffs; however, the number of claims has been reduced by around half. The consolidated lawsuit, John Doe v Meta Platforms Inc., filed in the U.S. District Court for the Northern District of California, alleges the plaintiffs and class members had their medical privacy violated by Facebook’s Meta Pixel tracking tool. The lawsuit alleges that Meta knew, or should have known, that the Pixel tool was being used improperly on the websites of hospitals. The lawsuit alleges at least 664 hospital systems and medical providers were sending medical information to Facebook through the Meta Pixel tool. According to the lawsuit, the improper use of the tracking tool resulted in “the wrongful, contemporaneous, re-direction to Facebook of patient communications to register as a patient, sign-in or out of a supposedly “secure” patient portal,...
Cisco Umbrella Competitors
In this post we explore some of the main Cisco Umbrella competitors that should be considered when looking for a Cisco Umbrella alternative – each providing a similar level of protection against web-based threats and having equivalent content control capabilities, but available for less than the price of Cisco Umbrella. We have highlighted four Cisco Umbrella competitors that have developed highly accomplished web filtering products which, in many respects, can be considered a direct swap for Cisco Umbrella. The Importance of DNS Filtering Before listing some of the main Cisco Umbrella competitors, it is worthwhile explaining why DNS filtering is so important and why it is now an essential part of the security stack. Hackers and other cybercriminals are devising increasingly sophisticated ways of attacking SMBs and enterprises and the range of threats is far more diverse than in years gone by. Whereas for many SMBs, a firewall, spam filter, and antivirus software were once enough to keep networks secure, the threat landscape today requires additional protection from web-based...
Advocate Aurora Health Settles Pixel Lawsuit for $12.225 Million
Advocate Aurora Health has proposed a $12.225 million settlement to resolve a consolidated class action lawsuit filed over the impermissible disclosure of patient data to third parties via tracking technologies. Advocate Aurora Health was one of the first HIPAA-regulated entities to report a Pixel-related data breach to the HHS’ Office for Civil Rights (OCR) and notify patients that their protected health information had been impermissibly disclosed to unauthorized third parties via these tracking technologies. Advocate Aurora Health operates 17 hospitals and more than 500 facilities in Wisconsin and Illinois. Advocate Aurora Health used tracking technologies such as Meta Pixel, Google Analytics, and other third-party tools on its website, patient portal, and scheduling app. The tracking tools were used to gain insights into the use of its website and app to better understand patient needs to improve the services it provides. Advocate Aurora Health has since removed the tracking tools from its website, MyChart patient portal, and LiveWell App. The HIPAA Breach Notification Rule...
Hackers Backdoor 1,900 Citrix NetScaler Devices
Hackers have been conducting a mass exploitation campaign targeting Citrix NetScalers to exploit a critical vulnerability tracked as CVE-2023-3519. The automated exploitation campaign compromises NetScalers and installs web shells to provide a persistent backdoor into systems. The web shell allows the threat actor to execute arbitrary commands on compromised systems, even when the patch is applied to fix the vulnerability. The vulnerability affects Citrix Application Delivery Controller and Gateway appliances configured as gateway servers and was disclosed by Citrix on July 18, 2023. A patch was released to fix the vulnerability and Citrix warned at the time that there had been limited exploitation of the vulnerability in the wild, although no details were released about the extent of the exploitation. Since then, several security firms have reported cases of exploitation of the flaw. Researchers at the cybersecurity company Fox-IT, part of NCC Group, in collaboration with the Dutch Institute of Vulnerability Disclosure (DIVD), have been trying to identify the compromised systems...



