NY AG Fines Medical Management Company $550,000 for Patch Management Failures
A medical management company has been fined $550,000 by the New York Attorney General for failing to prevent a cyberattack that exposed the personal and protected health information of 1.2 million individuals, including 428,000 New Yorkers. Professional Business Systems Inc, which does business as Practicefirst Medical Management Solutions and PBS Medcode Corp, had its systems hacked in November 2020. The threat actor exfiltrated sensitive data from its systems and then deployed ransomware to encrypt files. As proof of data theft and to pressure Practicefirst into paying the ransom, files were uploaded to the threat actor’s dark web data leak site. The leaked data included screenshots of 13 patients’ protected health information. Practicefirst’s investigation confirmed the threat actor exfiltrated approximately 79,000 files from its systems, which contained names, dates of birth, driver’s license numbers, Social Security numbers, diagnoses, medication information, and financial information. The investigation conducted by the Office of the New York Attorney General determined that...
April 2023 Healthcare Data Breach Report
There was a 17.5% month-over-month fall in the number of reported healthcare data HIPAA compliance breaches with 52 breaches of 500 or more records reported to the HHS’ Office for Civil Rights (OCR) – less than the 12-month average of 58 breaches per month, and one less than in April 2022. One of the largest healthcare data breaches of the year was reported in April, but there was still a significant month-over-month reduction in breached records, which fell by 30.7% to 4,425,891 records. The total is less than the 12-month average of 4.9 million records a month, although more than twice the number of records that were breached in April 2022. Largest Healthcare Data Breaches Reported in April 2023 As previously mentioned, April saw a major data breach reported that affected 3,037,303 individuals – The third largest breach to be reported by a single HIPAA-covered entity so far this year, and the 19th largest breach to be reported by a single HIPAA-regulated entity to date. The breach occurred at the HIPAA business associate, NationsBenefits Holdings, and was a data theft and...
Updated Pennsylvania Breach of Personal Information Notification Act Now in Effect
the 2022 update to the Pennsylvania Breach of Personal Information Notification Act (BPINA) is now in effect. The update broadened the definition of personal information to include medical information, health insurance information, and usernames in combination with a password or security question/answer that allows an account to be accessed. The update to BPINA was signed into law on November 3, 2022, and took effect on May 2, 2023. Medical information is defined as any individually identifiable information contained in an individual’s current or historical record of medical history or medical treatment or diagnosis created by a health care professional. Health insurance information is defined as a health insurance policy number or subscriber identification number in combination with an access code or other medical information that permits misuse of an individual’s health insurance benefits. The updated BPINA applies to state agencies, political subdivisions of the Commonwealth, and individuals or businesses that do business in the Commonwealth of Pennsylvania. A state agency...
Apria Healthcare Breach Affects Up to 1.8 Million Individuals
Apria Healthcare LLC, an Indianapolis-based provider of home medical equipment for sleep apnea, has recently sent notifications to individuals about a historic data breach. Apria was alerted about unauthorized access to some of its systems on September 1, 2021. According to the breach notification letters, steps were immediately taken to mitigate the incident, and Apria worked with a third-party forensics team and the Federal Bureau of Investigation. The investigation confirmed its systems were accessed by an unauthorized individual between April 5, 2019, and May 7, 2019, and again from August 27, 2021, to October 10, 2021. The investigation determined that access was gained to its systems primarily to obtain funds from Apria, rather than to obtain the personal information of patients or employees. While the investigation confirmed that some files containing protected health information were accessed, no evidence of data theft was found; however, data theft could not be ruled out. According to the breach notification sent to the Maine Attorney General, the files on its system that...
Bipartisan Legislation Introduced to Address Rural Hospital Cybersecurity Skill Gaps
New bipartisan legislation has recently been introduced to help address the current shortage of cybersecurity skills at rural hospitals. The Rural Hospital Cybersecurity Enhancement Act was introduced by Sen. Gary Peters (D-MI), chair of the Senate Homeland Security and Governmental Affairs Committee, and Sen. Josh Hawley (R-MO), committee member. Cyberattacks on healthcare organizations have increased significantly over the past few years. These attacks cause considerable disruption to patient care and can put lives at risk and while health systems have increased investment in cybersecurity, many small and rural hospitals lack the necessary resources and struggle to hire skilled cybersecurity professionals. At a recent Senate Homeland Security and Governmental Affairs Committee hearing, cybersecurity experts testified about the current healthcare cybersecurity challenges. Kate Pierce, former CIO and CISO at North County Hospital in Vermont and executive at Fortified Health Security said cybercriminals have shifted their focus and are now actively targeting small and rural...



