Credential Stuffing Attack Exposed United HealthCare Member Data
United HealthCare (UHC) has started notifying certain members that some of their protected health information may have been disclosed to unauthorized individuals as a result of credential stuffing attacks on the UHC mobile application. Credential stuffing is a type of attack where username and password combinations obtained in a breach at one platform are used to access accounts on an unrelated platform. These attacks can only succeed if usernames and passwords have been reused on multiple platforms. The accounts subjected to unauthorized access included information such as names, birthdates, addresses, health insurance member ID numbers, service dates, provider names, claim details, and group names and numbers. No Social Security numbers, financial information, or driver’s license numbers were exposed. The attacks occurred between February 19 and February 25, 2023. UHC took its portal offline immediately when the attacks were detected to prevent further unauthorized access and a password reset was performed. The investigation found no evidence to suggest the credentials had been...
HC3: Ransomware Groups are Exploiting GoAnywhere and PaperCut Vulnerabilities
The Health Sector Cybersecurity and Coordination Center (HC3) has issued a fresh ransomware warning to the healthcare and public health (HPH) sector following a spate of attacks on the HPH sector in April by the Clop and LockBit ransomware groups. HC3 has issued multiple alerts about the Clop and LockBit ransomware-as-a-service groups which have conducted multiple attacks on the healthcare sector. Clop was behind the attacks on Fortra’s GoAnywhere MFT solution in January/February 2023 and the 2022 attacks on the Accellion File Transfer Application (FTA), both of which exploited zero-day vulnerabilities in those solutions. The latest alert about LockBit was issued in December 2022 following multiple attacks on HPH sector organizations. The Clop group exploited the GoAnywhere MFT vulnerability (CVE-2023-0669) and stole data from around 130 organizations, and both groups have been observed exploiting two other recently disclosed vulnerabilities – CVE-2023-27350 and CVE-2023-27351 – which are authentication bypass vulnerabilities in the widely used print management software,...
90 Degree Benefits Facing Class Action Lawsuit Over 181,500-Record Data Breach
A lawsuit has been filed against 90 Degree Benefits over a breach of the HIPAA protected health information of 181,543 individuals. Unauthorized system activity was detected on or around December 10, 2022, and the forensic investigation determined its systems had been accessed by unauthorized individuals between December 5, 2022, and December 10, 2022. During that time, the attackers had access to parts of its network that contained patients’ and health plan members’ names, addresses, dates of birth, Social Security numbers, health information, and payment information. Affected individuals were notified about the breach by mail on or around April 7, 2023. The lawsuit alleges 90 Degree Benefits knew or should have been aware that it was a target for hackers, given the extent to which the healthcare industry has been targeted in recent years, especially considering 90 Degree Benefits experienced a similar data breach in February 2022. The February data breach should have made it clear that its data security measures were not sufficient and needed to be improved, yet despite that...
House Democrats Reintroduce Protecting America’s Workers Act on Worker’s Memorial Day
The Protecting America’s Workers Act was reintroduced by Reps. Joe Courtney (D-CT) and Bobby Scott (D-VA) on Worker’s Memorial Day and seeks to expand the coverage of the Occupational Safety and Health (OSH) Act to include the estimated 8 million state and local government workers in 24 states that are not currently covered by the act and increase the financial penalties for “high gravity” OSHA violations. The Protecting America’s Workers Act also seeks to reinstate the Volks Rule, which was repealed from OSHA by President Trump in 2017. The Volks Rule gave OSHA the authority to enforce recordkeeping requirements for work-related injuries and illnesses for five-and-a-half years rather than the 6-month statute of limitations established by OSHA. The Protecting America’s Workers Act has 12 co-sponsors and seeks to improve safety and health in the workplace by addressing the current shortfalls in OSHA. “Millions of workers still fall outside the law’s protections, weak sanctions fail to provide meaningful incentives for those employers tempted to cut corners on compliance with safety...
Organizations Face Increased Scrutiny of Health Data Breaches
Healthcare hacking incidents are increasing, there are new regulatory requirements and compliance initiatives due to Dobbs and Pixel use, and lawsuits against healthcare organizations over privacy violations are soaring. HIPAA-regulated entities and other organizations that operate in the healthcare space are now facing increased scrutiny of their data security practices and compliance programs, and the coming 12 months will likely see an increase in enforcement actions and lawsuits over privacy violations. The recently published BakerHostetler Data Security Incident Response Report (DSIR) draws attention to these issues and provides insights into the threat landscape to help organizations determine how to prioritize their efforts and investments. The report, now in its 9th year, was based on 1,160 security incidents managed by BakerHostetler’s Digital Assets and Data Management Practice Group in 2022. After a surge in ransomware attacks in 2021, 2022 saw a reduction in attacks; however, there was a surge in ransomware activity toward the end of the year and that surge has...



