CISA Publishes Guidance on Securing Cloud Services
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has published guidance that details security and resilience best practices to adopt when utilizing cloud services. The new guidance can be followed by all organizations; however, the guidance is of particular importance for federal agencies and critical infrastructure entities. Cybercriminals and advanced persistent threat actors are increasingly targeting supply chains to attack federal government networks and critical infrastructure, and many attacks now target cloud-based environments. The latest guidance can be used by federal agencies, critical infrastructure entities, and others to secure cloud business application environments and protect information created, accessed, shared, and stored in those environments. The guidance was developed under CISA’s Secure Cloud Business Applications (SCuBA) project, which was established and funded through the American Rescue Plan Act of 2021. The aim of the project is to develop consistent, effective, modern, and manageable security configurations that will help secure agency...
15-Year Employee Privacy Breach Discovered by Metro Health System
Metro Health System in Cleveland, OH, has discovered an employee has accessed patient records without a valid work reason. The unauthorized access was discovered on April 27, 2023, and the subsequent investigation confirmed that patient records had been accessed without authorization at various times over the past 15 years. The earliest incident occurred in 2008. The information viewed included patient names, dates of birth, and clinical information. No Social Security numbers or financial information were accessed. A spokesperson for Metro Health said the employee has been disciplined per its sanctions policy and no evidence has been found to indicate redisclosure of patient data or any misuse of that information. Affected individuals are being notified by mail, steps are being taken to improve its privacy practices, and further HIPAA training has been provided to the workforce. COX Health Affected by Hacking of Fortra GoAnywhere File Transfer Solution Springfield, MO-based CoxHealth has recently confirmed that patient data was compromised in a January 2023 cyberattack on its...
Atlantic General Hospital Increases Ransomware Victim Count to Almost 140,000 Individuals
In March 2023, Atlantic General Hospital notified the Maine Attorney General that it had fallen victim to a ransomware attack in which the protected health information of 30,704 individuals was exposed; however, the ransomware attack was far more extensive than was previously thought and the total has been upwardly revised to 136,981 individuals. The attack was detected on January 29, 2023, and the forensic investigation confirmed hackers had access to its network between January 20 and January 29, 2023. The initial review of files that were potentially compromised in the breach was completed on March 6, 2023, and confirmed that names, medical record numbers, treating/referring physician names, health insurance information, subscriber numbers, medical history information, and diagnosis/treatment information may have been accessed or acquired. Notification letters were sent on March 24, 2023, and complimentary credit and identity monitoring services were offered to affected individuals. The investigation into the attack continued, and additional files were discovered to have been...
Interview: Wei Pan, Head of Engineering, Celo Health
As part of our interview series, we spoke with Wei Pan, Head of Engineering at Celo Health. Celo Health is the developer of a HIPAA-compliant secure messaging platform that enables healthcare teams to collaborate seamlessly and securely on patient care. Tell the readers about your career in the healthcare industry I hold more than 15 years of experience in software development, specifically in the area of healthcare security. I graduated from the University of Auckland with a bachelor’s and a master’s in computer science. My development expertise is focused on cloud software architectures and web applications, iOS, Android, and Microsoft technologies. A key part of my career over the years, has been managing development teams in different parts of the world. I’ve been able to manage these dynamics successfully primarily because of the type of development methodology I’ve implemented called Kanban. This is an agile development method focused on process improvement, managing workflow efficiently, fostering team collaboration and transparency, and reducing lead time for new ideas...
What is the Mission of OSHA?
The mission of OSHA is to ensure safe and healthy working conditions for workers in the United States by setting and enforcing workplace safety and health standards, and by providing training, outreach, education, and assistance to employers. OSHA fulfills its mission by: Developing workplace safety and health standards. Providing training programs and employer education. Enforcing OSHA standards via targeted inspections. Facilitating confidential worker complaints. Investigating fatalities, catastrophes, and complaints. Providing on-site and virtual compliance assistance. Mandating injury and illness recordkeeping and reporting. Offering grants for non-profit employee training. Publishing fact sheets – both online and in print. Organizing cooperative programs with labor groups. The Occupational Safety and Health Administration (OSHA) was formed as a result of the passage of the Occupational Safety and Health Act in 1970. The mission of OSHA – which operates under the auspices of the Department of Labor – is to protect the rights of workers to safe and healthy working...



