Atlantic General Hospital Increases Ransomware Victim Count to Almost 140,000 Individuals
In March 2023, Atlantic General Hospital notified the Maine Attorney General that it had fallen victim to a ransomware attack in which the protected health information of 30,704 individuals was exposed; however, the ransomware attack was far more extensive than was previously thought and the total has been upwardly revised to 136,981 individuals. The attack was detected on January 29, 2023, and the forensic investigation confirmed hackers had access to its network between January 20 and January 29, 2023. The initial review of files that were potentially compromised in the breach was completed on March 6, 2023, and confirmed that names, medical record numbers, treating/referring physician names, health insurance information, subscriber numbers, medical history information, and diagnosis/treatment information may have been accessed or acquired. Notification letters were sent on March 24, 2023, and complimentary credit and identity monitoring services were offered to affected individuals. The investigation into the attack continued, and additional files were discovered to have been...
Interview: Wei Pan, Head of Engineering, Celo Health
As part of our interview series, we spoke with Wei Pan, Head of Engineering at Celo Health. Celo Health is the developer of a HIPAA-compliant secure messaging platform that enables healthcare teams to collaborate seamlessly and securely on patient care. Tell the readers about your career in the healthcare industry I hold more than 15 years of experience in software development, specifically in the area of healthcare security. I graduated from the University of Auckland with a bachelor’s and a master’s in computer science. My development expertise is focused on cloud software architectures and web applications, iOS, Android, and Microsoft technologies. A key part of my career over the years, has been managing development teams in different parts of the world. I’ve been able to manage these dynamics successfully primarily because of the type of development methodology I’ve implemented called Kanban. This is an agile development method focused on process improvement, managing workflow efficiently, fostering team collaboration and transparency, and reducing lead time for new ideas...
What is the Mission of OSHA?
The mission of OSHA is to ensure safe and healthy working conditions for workers in the United States by setting and enforcing workplace safety and health standards, and by providing training, outreach, education, and assistance to employers. OSHA fulfills its mission by: Developing workplace safety and health standards. Providing training programs and employer education. Enforcing OSHA standards via targeted inspections. Facilitating confidential worker complaints. Investigating fatalities, catastrophes, and complaints. Providing on-site and virtual compliance assistance. Mandating injury and illness recordkeeping and reporting. Offering grants for non-profit employee training. Publishing fact sheets – both online and in print. Organizing cooperative programs with labor groups. The Occupational Safety and Health Administration (OSHA) was formed as a result of the passage of the Occupational Safety and Health Act in 1970. The mission of OSHA – which operates under the auspices of the Department of Labor – is to protect the rights of workers to safe and healthy working...
Senators Demand Answers on Amazon Clinic’s Uses of Customer Data
Two Democratic senators have demanded answers from Amazon about how it uses the data of customers of Amazon Clinic after an investigation by the Washington Post revealed individuals wishing to enroll in Amazon Clinic are required to sign away some of their privacy rights in order to use the service. Amazon Clinic was launched in November 2022 and provides virtualized healthcare services. Amazon advertises the service as “a virtual healthcare storefront through which telehealth services are offered,” with those telehealth services provided by third-party healthcare providers. The Washington Post was contacted by a reader who requested an investigation of Amazon Clinic over the terms and conditions of its sign-up form. When enrolling for Amazon Clinic, users are required to provide consent to allow the use and disclosure of their protected health information. The form states that after providing consent Amazon will be authorized to have access to a complete patient file, may re-disclose information contained in that file and that the information disclosed will no longer be subject to...
Healthcare Organizations Warned of Risk of Cyberattacks via SEO Poisoning
In a recently published analyst note, the Health Sector Cybersecurity Coordination Center (HC3) draws attention to the practice of SEO poisoning – a tactic often used by malicious actors to trick individuals into disclosing sensitive information or downloading malware. Phishing is one of the most common ways that malicious cyber actors target individuals to gain initial access to healthcare networks; however, contact may be made with healthcare employees over the Internet. SEO poisoning is a technique used to drive traffic to attacker-controlled websites where instead of distributing links to malicious websites via phishing emails or SMS/instant messaging services, search engine optimization (SEO) techniques are used to get the malicious websites to appear high in the search engine listings for key search terms. The goal is to get the websites to appear in the first few results for specific search terms. The top few results in the search engine listings attract the highest number of clicks and users tend to view the top results as the most relevant and trustworthy, and will often...



