NextGen Healthcare Facing Multiple Class Action Data Breach Lawsuits
A healthcare data breach of 1 million+ records is certain to result in multiple lawsuits, and the data breach experienced by NextGen Healthcare is no exception. The data breach was only disclosed by NextGen on May 5, but at least a dozen lawsuits have already been filed in federal court in Georgia over the breach. The data breach was the result of a hacking incident involving stolen credentials, which allowed unauthorized individuals to access a database that contained sensitive patient data such as names, addresses, dates of birth, and Social Security numbers. The investigation determined that the credentials stolen by the hackers came from other sources and did not appear to have been stolen from NextGen. The breach was detected by NextGen on March 30, 2023, and the forensic investigation confirmed hackers had access to its network between March 29, 2023, and April 14, 2023. This was the second data breach to be reported by NextGen this year, with the earlier incident being a BlackCat ransomware attack. NextGen told the Maine Attorney General that 1,049,375 individuals had been...
FBI and CISA Issue Warning About BianLian Ransomware and Extortion Group
A joint cybersecurity alert has been issued by the Federal Bureau of Investigation (FBI), Cybersecurity and Infrastructure Security Agency (CISA), and Australian Cyber Security Centre (ACSC) about the BianLian ransomware and data extortion group. The BianLian group has been conducting attacks in the United States since at least June 2022 and has actively targeted critical infrastructure organizations, including the healthcare and public health sector. The BianLian group is a ransomware actor that develops and uses ransomware in its attacks, typically engaging in double extortion tactics, where sensitive private data is exfiltrated from victims’ networks before files are encrypted. The group threatens to leak the stolen data if the ransom is not paid. This year, the group has largely switched to extortion-only attacks where files are not encrypted after exfiltration. These attacks have proven to be effective as the release of stolen data can cause significant damage to an organization’s reputation and legal complications. The BianLian group primarily gains access to victims’...
What is a HIPAA Compliant Phone Number?
A HIPAA-compliant phone number is most often a secondary phone number used by healthcare providers for communications in which Protected Health Information (PHI) may be disclosed. In many cases, the HIPAA-compliant phone number is a virtual phone number used by systems with secure voice, messaging, and video capabilities that are configured to comply with HIPAA. What is a HIPAA-compliant phone number? Why have a secondary phone number? What is a virtual phone number? Which HIPAA-compliant systems use virtual phone numbers? How do secondary phone numbers support HIPAA compliance? What else may healthcare providers need to consider? What is a HIPAA Compliant Phone Number? A HIPAA-compliant phone number is a number linked to a communication system that complies with the administrative, physical, and technical safeguards of the Security Rule. Because the system complies with HIPAA, it can be used to make calls, send secure messages, conduct telemedicine consultations, and much more without risking the confidentiality of PHI. This article explains why a HIPAA-compliant phone number is...
Almost 6 Million Individuals Affected by PharMerica Data Breach
In late March 2023, the Money Message ransomware group announced it had breached the systems of PharMerica and its parent company, BrightSpring Health Services, and added both to its data leak site. The group claimed to have exfiltrated databases containing 4.7 terabytes of data which included the records of more than 2 million individuals. PharMerica has now confirmed the extent of the data breach. PharMerica is one of the largest providers of pharmacy services in the United States, operating more than 2,500 facilities and over 3,100 pharmacy and healthcare programs. PharMerica and BrightSpring have now completed their investigation and have confirmed that there was unauthorized accessing of sensitive patient information and reported the data breach to the Maine Attorney General and HHS’ Office for Civil Rights as affecting 5,815,591 individuals. That makes it the largest healthcare data breach to be reported by a single HIPAA-covered entity so far in 2023. PharMerica explained in its notification letters that suspicious activity was detected within its computer network on...
EyeMed Vision Care Settles Multistate Data Breach Investigation for $2.5 Million
In June 2020, the Luxottica Group PIVA-owned vision insurance company, EyeMed Vision Care, experienced a data breach involving the protected health information (PHI) of 2.1 million patients. An unauthorized individual gained access to an employee email account that contained approximately 6 years of personal and medical information including names, contact information, dates of birth, Social Security numbers, vision insurance account/identification numbers, medical diagnoses and conditions, and treatment information. The unauthorized third party then used the email account to distribute around 2,000 phishing emails. State attorneys general have the authority to investigate data breaches and can fine organizations for HIPAA violations. A multi-state investigation was launched by state attorneys general in Oregon, New Jersey, and Florida into the EyeMed data breach, and Pennsylvania later joined the multistate action. The state attorneys general sought to establish whether the data breach was preventable and if it was the result of a failure to comply with the HIPAA Security Rule and...



