FTC Fines Genetic Testing Company for Data Privacy and Security Failures
A San Francisco-based company that sells DNA test kits and personalized diet and exercise plans based on genetic testing has been fined $75,000 by the Federal Trade Commission (FTC) and ordered to make improvements to its data privacy and security practices. The company is alleged to have left sensitive genetic and health data unsecured and deceived customers about its data-sharing practices. 1HEalth.io, which previously operated under the names Vitagene Inc. and Vitagene, is alleged to have violated the Federal Trade Commission Act by deceiving consumers about its data sharing, data deletion, and DNA sample destruction practices. According to the FTC’s complaint, consumers were informed on the Vitagene website that the company had “rock solid security,” and that the company “collects, processes, and stores your personal information in a responsible, transparent, and secure environment.” Between 2017 and 2020, Vitagene informed consumers that their sensitive health and personal information would only be shared in limited circumstances, such as with their doctor or the lab that was...
May 2023 Healthcare Data Breach Report
May 2023 was a particularly bad month for healthcare data breaches. 75 data breaches of 500 or more healthcare records were reported to the HHS’ Office for Civil Rights (OCR) in May. May – along with October 2022 – was the second-worst-ever month for healthcare data breaches, only beaten by the 95 breaches that were reported in September 2020. Month-over-month there was a 44% increase in reported data breaches and May’s total was well over the 12-month average of 58 data breaches a month. May was also one of the worst-ever months in terms of the number of breached records, which increased by 330% month-over-month to an astonishing 19,044,544 breached records. Over the past 12 months, the average number of records breached each month is 6,104,761 and the median is 5,889,562 records. 46.52 of the breached records in May came from one incident, which exposed the records of almost 8.9 million individuals, and 90.45% of the breached records came from just three security incidents. More healthcare records have been breached in the first 5 months of 2023 (36,437,539 records) than in...
TimisoaraHackerTeam Ransomware Group Linked with Recent Attack on U.S. Cancer Center
An alarm has been sounded about a relatively unknown threat group called TimisoaraHackerTeam following a recent attack on a U.S. medical facility. TimisoaraHackerTeam is believed to be a financially motivated threat group, which in contrast to many cybercriminal and ransomware groups, has no qualms about attacking the healthcare and public health (HPH) sector and appears to actively target HPH sector organizations, mainly conducting attacks on large organizations. The group was first identified in July 2018 but has largely stayed under the radar. According to the Healthcare Sector Cybersecurity Coordination Center (HC3), which issued the alert on June 16, the group has resurfaced and conducted a June 2023 ransomware attack on a U.S. cancer center which rendered its digital services unavailable, put the protected health information of patients at risk, and significantly reduced the ability of the medical center to provide treatment for patients. The group has exploited known vulnerabilities to gain initial access to HPH sector networks, then escalates privileges, moves laterally,...
24 State Attorneys General Confirm Support for Stronger HIPAA Protections for Reproductive Health Data
A coalition of 24 state attorneys general has written to the Department of Health and Human Services (HHS) to confirm their support for the proposed update to the Health Insurance Portability and Accountability Act (HIPAA) Privacy Rule to strengthen reproductive health information privacy. Background The decision of the Supreme Court in Dobbs v. Jackson Women’s Health Organization in June 2022 overturned Roe v. Wade and removed the federal right to abortion. Many states introduced their own laws banning or severely restricting abortions in their respective states, and those laws permit criminal or civil penalties for anyone that seeks, provides, or assists with the provision of an abortion. Currently, 15 states have introduced almost total bans on abortions and several others have restricted abortions or are in the process of introducing bans or restrictions. Idaho has also recently enacted an abortion trafficking law, which aims to restrict the ability of state residents to travel out of state to receive abortion care. Following the Supreme Court decision, the HHS’ Office for...
Kaiser Permanente Fined $450,000 for CMIA Violations Due to Mailing Error
Kaiser Permanente has been fined $450,000 by the California Department of Managed Care (CDMC) for impermissibly disclosing the confidential and protected health information (PHI) of up to 167,095 health plan members. Between October 2019 and December 2019, Kaiser Permanente sent 337,755 mailings to enrollees of its health plan; however, an error updating its electronic medical record system resulted in some mailings being sent to outdated addresses. Kaiser Permanente was contacted by 8 individuals who said they had opened the packets but realized that they were not the intended recipients and 1,788 of the packets were returned unopened as the recipients realized they had been sent to the wrong addresses. The mailings were sent to 167,095 enrollees and Kaiser Permanente could not be sure that those mailings had been received by the intended recipients, which meant thousands of enrollees’ PHI may have been impermissibly disclosed. CDMC investigated the reported breach and determined there had been an unauthorized disclosure of medical information and negligent maintenance or...



