Cyberattack Affects Multiple Residential Care Facilities in Pennsylvania
The Williamsport Home, a retirement village in Pennsylvania, and Senior Choice, Inc., a provider of skilled nursing care at three inpatient facilities in Pennsylvania – The Atrium in Johnstown, Beacon Ridge in Indiana, and The Patriot in Somerset – have been affected by a cyberattack that was detected on April 24, 2023. Steps were immediately taken to secure the network when the security breach was detected and while the investigation into the cyberattack is ongoing, it has been determined that unauthorized individuals gained access to certain business operation systems between April 18 and April 24, 2023. The systems used directly for residential care do not appear to have been compromised; however, the business systems compromised in the attack contained protected health information that was potentially accessed or obtained. The types of information that were exposed varied from individual to individual and may have included one or more of the following: Name, address, birth date, admission date, discharge date, death date, medical record number, provider or facility name,...
Cisco Umbrella Alternatives
To best answer the questions what is Cisco Umbrella – and why you may wish to look for Cisco Umbrella alternatives – it is necessary to go back to before the Umbrella brand existed to look at how the current suite of security solutions evolved. The Cisco Umbrella suite of security solutions evolved from a free-to-use recursive DNS resolver that was launched in 2006 under the name OpenDNS. Originally funded by advertising revenues, the OpenDNS service enabled users to optionally block access to adult websites and benefit from a collaborative anti-phishing database that could prevent users visiting suspected phishing sites. As the demand for Internet filtering solutions grew, OpenDNS launched Family Shield – a home Internet filtering service through which parents could control the content children could access on the Internet – and OpenDNS Enterprise, a subscription-based Internet filtering service for businesses that later supported integrations with management tools such as Active Directory. The security capabilities of OpenDNS Enterprise expanded rapidly to include...
Activate Healthcare Reports Security Breach Affecting up to 93,761 Patients
The Illinois-based healthcare provider, Activate Healthcare, LLC, has recently confirmed that it suffered a security breach that resulted in the theft of patient data. Suspicious activity was detected within its IT systems on April 27, 2023, and the subsequent forensic investigation confirmed that an unauthorized third party had access to its network between April 22, 2023, and April 28, 2023. On April 29, 2023, it was confirmed that files had been exfiltrated that included patient information such as names, dates of birth, addresses, Social Security numbers, driver’s license numbers, and clinical information, such as provider names, dates of service, and/or diagnoses. At the time of issuing notification letters, no evidence of misuse of patient data had been detected; however, as a precaution, affected individuals have been offered complimentary credit monitoring and identity protection services. Activate Healthcare said steps will continue to be taken to enhance the security of its computer systems. The breach has been reported to the HHS’ Office for Civil Rights as affecting up...
Critical RCE Vulnerability Identified in Medtronic Paceart Optima System
A critical vulnerability has been identified in the Medtronic Paceart Optima System, which is used to compile and manage patients’ cardiac data. The vulnerability is tracked as CVE-2023-31222 and is due to the deserialization of untrusted data. The vulnerability has been assigned a CVSS v3 base score of 9.8 out of 10. The vulnerability affects all versions of Paceart Optima up to and including version 1.11 and can be exploited remotely by an unauthorized user by sending specially crafted messages to the Paceart Optima system. Successful exploitation of the flaw would allow an attacker to remotely execute arbitrary code and gain a foothold for network penetration. The flaw could also be exploited to trigger a denial-of-service condition resulting in the Paceart Optima system becoming slow and unresponsive, preventing healthcare delivery organizations from using the system. The flaw can only be exploited if the Paceart Messaging Service is enabled in the Paceart Optima system, which is an optional service. An immediate mitigation to prevent the flaw from being exploited is to disable...
HHS-OIG Final Rule Authorizes Information Blocking Penalties of up to $1 Million for Health IT Vendors
The civil monetary penalties for health IT companies that are found to be engaging in information blocking have been finalized. Fines of up to $1 million can be imposed per violation. In 2016, the 21st Century Cures Act made sharing electronic health information the expected norm in healthcare and authorized the Secretary of the Department of Health and Human Services (HHS) to identify reasonable and necessary activities that do not constitute information blocking. In 2020, the Department of Health and Human Services’ Office of the National Coordinator for Health Information Technology (ONC) established information blocking provisions and exceptions in the 21st Century Cures Act Final Rule, and new civil monetary penalties were proposed for enforcement. The HHS’ Office of Inspector General (HHS-OIG) has now issued a final rule enacting those penalties for health IT developers of certified health IT and other entities offering certified health IT, health information exchange (HIEs), and health information networks (HINs). Financial penalties can also be imposed on healthcare...



