Essential Elements of the MSP Security Stack
Managed service providers are being increasingly used by healthcare providers to help them achieve HIPAA Security Rule compliance. Here we explore the essential elements of the MSP security stack that are needed to meet the needs of healthcare organizations. Growing Demand for MSP Security Services The healthcare industry has long been a target for cybercriminals and cyberattacks and data breaches are increasing each year, with threat actors developing increasingly sophisticated ways of breaching defenses and gaining access to sensitive healthcare data. To protect against these threats, healthcare organizations need to adopt a defense-in-depth strategy, where multiple cybersecurity solutions are deployed to protect their network, applications, and data, along with monitoring solutions to rapidly detect breaches of their defenses. They also need to implement and test an incident response plan for when hackers succeed. That is a massive job for any healthcare organization and one that many small- and medium-sized healthcare organizations struggle with. It is therefore no surprise...
Orrick, Herrington & Sutcliffe Sued Over Ransomware Attack and Data Breach
The San Francisco, CA-based law firm, Orrick, Herrington & Sutcliffe LLP, is facing a class action lawsuit over a ransomware attack and data breach that was detected on March 13, 2023. The law firm determined that part of its network had been compromised by an unauthorized third party, which gained access to a file share that was used to store client files. The unauthorized access was immediately blocked; however, the forensic investigation confirmed that files containing personal information had been exfiltrated from its servers between February 28 and March 13, 2023. The compromised information included names, addresses, dates of birth, and Social Security numbers. The law firm offered the affected individuals complimentary credit monitoring and identity theft protection services. On August 11, 2023, a lawsuit was filed in the U.S. District Court for the Northern District of California on behalf of plaintiff Dennis R Werley, and more than 152,818 similarly situated individuals who had their personal information compromised in the attack. The lawsuit alleges the law firm...
PHI Included in Mom’s Meals Data Breach
The parent company of the Mom’s Meals home delivery meal service – PurFood LLC – has published a Notice of Data Event on its website and filed a Data Breach Notification with the Maine Attorney General following a cyberattack earlier this year in which personal information relating to 1,237,681 customers, employees, and contractors is believed to have been stolen, and according to the HHS’ Office for Civil Rights breach portal, the protected health information of up to 1,229,233 individuals was involved. PurFood LLC – trading as Mom’s Meals – delivers refrigerated ready-to-eat meals nationwide to customers with special nutritional requirements. As well as supplying private customers, the company works with more than five hundred health plans, managed care organizations, and other agencies to provide access to meals for people covered by Medicare and Medicare. According to a Notice of Data Event on the company’s website, Mom’s Meals experienced a cyberattack between January 16, 2023, and February 22, 2023, that resulted in customer, employee, and contractor data being...
Study Reveals State of External Exposure Management
CyCognito has published its latest State of External Exposure Management Report, which highlights the extent to which vulnerabilities affect organizations and how easy it is for hackers to exploit those vulnerabilities. For the report, CyCognito’s researchers aggregated and analyzed 3.5 million digital assets across its customer base between June 2022 and May 2023, which includes small, medium, and large enterprises, including Fortune 500 companies. The study found that 70% of web applications had severe security gaps, such as lacking web application firewall (WAF) protection and not using encrypted connections such as HTTPS, with 25% of web applications lacking both protections. A typical enterprise has more than 12,000 web apps such as APIs, SaaS applications, databases, and servers. The researchers found at least 30% of those web apps have more than 3,000 assets and had at least one exploitable or high-risk vulnerability. The study confirmed the extent to which personally identifiable information (PII) is put at risk. 74% of assets containing PII were found to be exposed to at...
Lawsuit Alleges Unum Group at Fault for MOVEit Data Breach
A Florida resident is taking legal action against the employee benefits provider, Unum Group, over its MOVEit Transfer data breach and alleges a failure to safeguard the personal information stored within its network. Unum Group was one of hundreds of victims of the mass exploitation of a zero-day vulnerability in the MOVEit Transfer solution. Progress Software issued a security alert about the vulnerability on May 31, 2023, and released a patch the same day; however, the vulnerability had already been exploited in attacks by the Clop group, resulting in the theft of sensitive data. Unum Group announced on August 3, 2023, that it had been affected and there had been unauthorized access to the protected health information of former and current customers of its subsidiary insurance companies, including names, birth dates, addresses, Social Security numbers, and health insurance claim information. The breach was reported to the HHS’ Office for Civil Rights as affecting 531,732 individuals. The lawsuit argues that Unum Group had an obligation to keep consumers’ data private and...



