Marietta Area Health Care Settles Class Action Data Breach Lawsuit for $1.75 Million
Marietta Area Health Care, an Ohio-based not-for-profit health system that does business as Memorial Health System, has proposed a $1.75 million settlement to resolve a class action lawsuit that alleged it failed to protect patient health information, resulting in a cyberattack and data breach. Malware was detected within its network on August 14, 2021, and the investigation determined hackers had access to its IT systems between July 10, 2021, and Aug. 15, 2021, and it was confirmed in mid-September that patient data had potentially been viewed or acquired in the attack. The review of the affected files was completed on November 1, 2021, when it was confirmed that the HIPAA protected health information of more than 215,000 patients had been exposed, including names, addresses, Social Security numbers, medical/treatment information, and health insurance information. Affected patients were notified in January 2022 and were offered complimentary credit monitoring services. A lawsuit – Tucker v. Marietta Area Health Care d/b/a Memorial Health System – was filed in the U.S....
Top Ten Cybersecurity Misconfigurations and Recommended Mitigations
The National Security Agency (NSA) and the Cybersecurity and Infrastructure Security Agency (CISA) have shared the top ten cybersecurity misconfigurations and the tactics, techniques, and procedures used by malicious actors to exploit these misconfigurations. Cyber threat actors search for and exploit unpatched vulnerabilities in software and operating systems to gain initial access to internal networks, but there are often much easier ways to breach defenses. Organizations of all sizes make mistakes that leave holes in their defenses that are easy to exploit, and poor cybersecurity practices can be exploited once initial access has been gained to move freely inside networks undetected. The NSA and CISA identified the top ten cybersecurity misconfigurations through their red and blue team assessments and incident response activities. These misconfigurations were found in organizations of all sizes, even large enterprises with mature cybersecurity postures. Default configurations of software and applications Improper separation of user/administrator privilege Insufficient internal...
23andMe User Data Stolen in Credential Stuffing Attack
The San Francisco, CA-based direct-to-consumer genetic testing company, 23andMe, confirmed on Friday that the sensitive of some of its users has been stolen, following reports that user data was being offered for sale online. 23andMe confirmed that its systems were not breached and said users’ genetic data remains secure; however, there has been unauthorized access to some customer accounts. Individual accounts were compromised in what appears to have been a credential stuffing campaign that exploited users’ poor password practices, based on 23andMe’s preliminary investigation. 23andMe said it is currently working on confirming the preliminary results of its investigation, and third-party digital forensics experts have been engaged to ensure that its systems are secure. The compromised user accounts were scraped, and the threat actor obtained data from 23andMe profiles, including data from its DNA Relatives feature. This opt-in feature allows users to share their information with other users of the platform to find distant genetic relatives and includes broad descriptions of users’...
Quest Diagnostics Facing Lawsuit for Disclosing Medical Information to Third Party Debt Collectors
Quest Diagnostics and its revenue operations management company, Optum360, were affected by the 2019 cyberattack on the medical billing collection company, American Medical Collection Agency (AMCA). Almost 12 million Quest Diagnostics patients had their protected health information exposed in the incident. Following the attack, Quest Diagnostics and Optum360 faced several class action lawsuits over the data breach, and the legal problems are continuing. Another lawsuit has been filed against Quest Diagnostics and Optum360, not for the data AMCA breach itself, but for the decision to provide confidential medical information to AMCA and other third-party debt collectors, which the lawsuit alleges did not need to be provided to those third parties to allow them to complete their contracted duties. The lawsuit alleges the provision of unnecessary medical information to debt collection companies is in violation of the California Confidentiality of Medical Information Act (CMIA), which mandates providers only share medical information if they obtain authorization from patients, except...
What is a HIPAA Compliant Phone Service?
A HIPAA compliant phone service is any voice communication technology that supports compliance with the Administrative Simplification Regulations of the Health Insurance Portability and Accountability Act (HIPAA) when compliance is necessary. Because there are different circumstances in which compliance with this section of HIPAA may or may not be necessary, this article explains: Who does HIPAA apply to, and when does it apply? What does HIPAA say about phone communications? What is a HIPAA compliant phone service? How to make a phone service HIPAA compliant. Conclusion: Be sure to use a HIPAA compliant phone service. Who Does HIPAA Apply To, and When Does It Apply? The Administrative Simplification Regulations of HIPAA apply to health plans, health care clearinghouses, and healthcare providers (“covered entities”) that conduct electronic transactions for which the Department of Health and Human Services (HHS) has published standards. The standards can be found in Part 162 of the Administrative Simplification Regulations. Some Administrative Simplification Regulations of HIPAA...



