Cummins Behavioral Health Reports 157K Record Data Breach
Cummins Behavioral Health Systems Inc. in Avon, IN, has recently reported a data security incident to the Maine Attorney General that has affected 157,688 patients. On March 9, 2023, a ransom note was detected within its computer environment that had been placed there by an unauthorized individual. No file encryption occurred; however, the attacker claimed to have infiltrated sensitive data. The forensic investigation confirmed that an unauthorized individual had access to its network between February 2, 2023, and March 9, 2023. The information removed from its systems included names, addresses, dates of birth, Social Security numbers, driver’s license/State ID numbers, financial account information, payment card information, usernames/passwords, health insurance information, and medical information. System security has been strengthened to prevent similar incidents in the future, and affected individuals have been offered complimentary credit monitoring and identity theft protection services. Email Encryption Failure Exposed Client Data at Redwood Coast Regional Center Redwood...
Frontline Healthcare Workers Increasingly Concerned About Workplace Violence
Incidents of workplace violence are on the rise and frontline workers do not feel safe at work, according to a recent survey commissioned by the security management company, Verkada. The survey was conducted on a nationally representative sample of 1,000 Americans who work on-location in critical sectors such as healthcare, hospitality, and retail that have regular contact with patients, customers, clients, or guests. One in three workers said they have felt unsafe at work in the past year and 58% feel the threat of physical harm at work is increasing. 40% of respondents said they feel more concerned about their personal safety at work than they did a year ago. 69% of healthcare workers expressed concern about aggressive and erratic behavior by patients and 59% said they regularly worry about being physically assaulted at work. 54% of healthcare workers said they are likely to resign in the next 12 months if physical safety at work does not improve. The findings tie in with a recent National Nurses United survey where half of nurses reported an increase in workplace violence in the...
Tift Regional Medical Center Patients Notified About August 2022 Cyberattack
Tift Regional Medical Center in Georgia has started notifying 180,142 patients that their personal and protected health information was compromised in a cyberattack that was detected on or around August 16, 2022. According to the notification letters, there was no encryption of systems, access was not gained to its electronic medical record system, and the network remained available to staff and patients. The forensic investigation of the incident indicated files “were or may have been accessed or copied without authorization between August 11, 2022, and August 17, 2022.” The attack was conducted by the Hive ransomware group, which was the subject of a law enforcement takedown in January 2023. The Hive group claimed to have stolen 1TB of data in the attack, some of which was released on its data leak site. The affected patients were informed that the files contained names, dates of birth, Social Security numbers, and medical information. Complimentary credit monitoring services have been offered for 12 months. The HIPAA Breach Notification Rule requires notifications to be...
What is OSHA Training?
OSHA training is the training on safety and health that employers are required to provide for members of their workforces. Training requirements vary according to the nature of each business’s activities and the OSHA standards that apply. For example, in the healthcare industry, an OSHA required training checklist could include many of the following subjects: OSHA Required Training Checklist General safety and health guidelines (i.e., preventing slips, trips, and falls) Emergency action plans (see note below on CMS Emergency Preparedness) Fire prevention, response, and evacuation training (inc. CMS training) Fire extinguisher use (when fire extinguishers are provided for employee use) Safe patient handling (for staff with direct patient handling duties) PPE training (essential before working in an environment in which PPE is required) Occupational noise safety (typically in laundry, engineering, and heliport environments) Workplace violence prevention (tailored to each healthcare environment) Respiratory protection training (in both routine and emergency scenarios) Bloodborne...
HC3 Provides Guidance on Multifactor Authentication and Highlights Smishing Risks
The Health Sector Cybersecurity Coordination Center has published guidance on multifactor authentication (MFA) that explains why MFA is important for security, some of the problems that can arise from implementing MFA, and how threat actors can successfully bypass MFA controls. Multifactor authentication involves a knowledge factor, a possession factor, and an inherence factor for authentication – something someone knows, has, and is unique to the user. Multifactor authentication eliminates password risks – such as weak passwords being set, or passwords being obtained – and makes it harder for unauthorized individuals to gain access to accounts, networks, and sensitive data. In contrast to 2-factor authentication, which requires a user to prove their identity twice, MFA requires identity to be proven multiple times. In addition to a password, authentication occurs through one-time passwords (OTPs) sent to a mobile device, hardware tokens, software tokens, biometrics, and push notifications. While any form of multifactor authentication is better than single-factor...



