CommonSpirit Health Increases Ransomware Attack Cost Estimate to $160 Million
The Chicago, IL-based Catholic health system, CommonSpirit Health, has reported an operating loss of $1.4 billion for fiscal year 2023, up slightly from the $1.3 billion operating loss reported for fiscal year 2022. The CommonSpirit Health ransomware attack in October 2022 was a significant factor in the $1.4 billion operating loss as it caused significant disruption to its billing and collection activities. CommonSpirit Health has estimated the financial losses caused by the attack have now reached 160 million, which includes losses caused by business disruption, remediation costs, and other business expenses. The latest figure is $10 million greater than its previous estimate issued in May 2023. While the attack only caused short-term disruption to patient services, significant disruptions were experienced with claims processing and collections, and the records of 624,000 patients, family members, and caregivers were exposed and potentially stolen. CommonSpirit Health has previously stated that it anticipates its cybersecurity insurance to cover a significant percentage of the...
Insider Security Threat Costs up 40% in 4 Years
The average annual cost of insider security threats has increased by 40% in 4 years to $16.2 million per organization, according to the 2023 Cost of Insider Risks Report from DTEX Systems. This is the fifth year that DTEX Systems has conducted its insider threat benchmark study to gain insights into the financial consequences that result from insider risks. This year the study was conducted by the Ponemon Institute on 1,075 IT and IT security professionals at organizations with 500-75,000 employees in North America, Africa, the Middle East, and the Asia-Pacific region. Insider risks are classified as malicious and non-malicious. Malicious incidents are caused by insiders wishing to cause harm and include espionage, IP threats, unauthorized disclosures, fraud, sabotage, and workplace violence. Non-malicious insider incidents include negligent incidents, where harm was caused through carelessness or inattentiveness such as ignoring warnings, non-careless mistakes, and incidents where non-malicious insiders were outsmarted by an adversary, such as phishing and BEC attacks that have...
Healthcare Industry Sees Sharp Increase in Advanced Email Attacks
The healthcare industry has seen a sharp increase in advanced email attacks this year, according to new data from Abnormal Security. In the year to August 2023, advanced email attacks are up 167% on 2022 levels and business email compromise (BEC) attacks have increased by 279%. Healthcare organizations are attractive targets for cybercriminals as they store large volumes of highly sensitive data and they are heavily reliant on access that that information. Attacks that prevent access to IT systems and protected health information put patient safety at risk and downtime causes significant financial losses, which makes the industry a prime target for extortion. There was a significant increase in advanced email attacks early in 2023, which include BEC, malware, social engineering, and phishing attacks. The year started with an average of 55.66 attacks per 1,000 mailboxes in January and increased to more than 100 attacks per 1,000 mailboxes in March, before falling to a consistent average of 61.16 attacks per 1,000 mailboxes for the rest of the year. Based on last year’s data,...
When was OSHA Created?
OSHA was created in 1971, one year after Congress had enacted the Occupational Safety and Health Act (the OSH Act) “to assure safe and healthful working conditions for working men and women; by authorizing enforcement of the standards developed under the Act; [and] by assisting and encouraging the States in their efforts to assure safe and healthful working conditions.” Key Moments in OSHA’s Journey 1970 – Enactment of the OSH Act by Congress. 1971 – OSHA adopts inaugural safety and health regulations. 1972 – The OSHA Training Institute is launched. 1972 – First OSHA State Plans receive approval. 1978 – Introduction of the Field Sanitation Standards. 1983 – Publication of the Hazard Communication Standard. 2002 – Standards for Exit Routes, Emergency Action, and Fire Prevention Plans unveiled. 2010 – OSHA announces a Severe Violator Enforcement Program to monitor non-compliant employers. 2016 – A new rule mandates electronic submission of Form 300A to bolster workplace injury and illness tracking. OSHA’s Early History While 1971...
Colorado Attorney General Settles Data Breach Investigation with Broomfield Skilled Nursing and Rehabilitation Center
A settlement has been reached between the Colorado Attorney General and Broomfield Skilled Nursing and Rehabilitation Center that resolves alleged violations of Colorado’s data protection laws and the Health Insurance Portability and Accountability Act (HIPAA). Colorado Attorney General, Phil Weiser, launched an investigation of Broomfield Skilled Nursing and Rehabilitation Center in response to a 2021 data breach that exposed the personally identifiable information of hundreds of its patients and employees. Broomfield Skilled Nursing and Rehabilitation Center discovered there had been a security breach on March 3, 2021, when two employee email accounts were found to have email forwarding rules configured that sent emails to an external email address. Broomfield Skilled Nursing and Rehabilitation Center’s forensic investigation determined in April 2021 that an unknown third party had gained access to the email accounts after compromising the employees’ credentials and had set up forwarding rules on both accounts. A vendor was engaged to conduct a review of the accounts, and...



