Even Well-Defended Companies are Vulnerable to Lapsus$ Attacks
The Cyber Safety Review Board (CSRB) has published an analysis of cyberattacks by the Lapsus$ threat group and has made recommendations for the public and private sectors on how to improve cybersecurity defenses against attacks by Lapsus$ and similar threat actors. The CSRB was established by President Biden’s Executive Order on Improving the Nation’s Cybersecurity and has been tasked with reviewing major cyber events and making recommendations on improvements that can be made by public and private sector organizations to better defend against attacks. The CSRB consists of 15 cybersecurity leaders from the federal government and private sector and is chaired by Robert Silvers, Under Secretary for Policy at the U.S. Department of Homeland Security. Lapsus$ is a cyber threat actor primarily focused on data theft and extortion and has been conducting attacks globally on large companies and government agencies around the world since 2021. The group breaches defenses to gain access to internal networks, steals sensitive data such as source code, and demands payment, although rarely...
Dentist Ordered to Pay $20,000 After Terminating Whistleblower for Raising Health and Safety Concerns
A Peoria, AZ-based dentist has been ordered to pay $20,000 in back wages to an employee who was terminated for making allegations of unsafe work practices at the practice. The Occupational Safety and Health Act (OSH Act) has whistleblower provisions that protect employees from retaliation after raising concerns about workplace health and safety issues and reporting injuries sustained in the workplace. Employers are not permitted to take unfavorable employment actions against employees, such as demoting, denying overtime or promotion, disciplining, intimidating, making threats, or firing employees who raise safety concerns with their employers or report safety and health complaints to the Occupational Safety and Health Administration (OSHA). In March 2020, a dental assistant at the practice of Dr. Monzer K. Al-Dadah LLC and Dr. Al-Dadah filed a complaint with OSHA about unsafe working practices related to COVID-19. The employee complained about the risk of contracting COVID-19 and refused a work assignment due to fears of contracting COVID-19. The worker also discussed workplace...
NIST Releases Draft Version of Cybersecurity Framework 2.0 for Public Comment
The National Institute of Standards and Technology (NIST) has published a draft version of an updated version of its popular Cybersecurity Framework (CSF) – version 2.0. This is the first major update to the NIST CSF since its release in 2014. The NIST CSF helps organizations to understand and reduce cybersecurity risks, improve their security posture, and monitor progress, and has been downloaded more than 2 million times. The NIST CSF was initially released to help critical infrastructure entities improve their security posture and reduce and manage risks; however, the framework has been adopted by a much broader range of entities such as small- and medium-sized organizations that lack internal resources for cybersecurity. The framework is based on five key pillars: identity, protect, detect, respond, and recover, and provides high-level guidance for managing cybersecurity risk. The framework uses a common language and systematic methodology for managing risk and aiding communication between technical and non-technical staff and can easily be tailored to suit the needs of...
OCR’s COVID-19 Telehealth Enforcement Discretion Transition Period Ends
At 11.59 pm on August 9, 2023, the transition period for ensuring telehealth services are fully HIPAA-compliant came to an end. Healthcare providers must now ensure that their telehealth services are provided using platforms that are fully compliant with the HIPAA Rules. The enforcement discretion policy was initiated for telehealth in response to the COVID-19 pandemic. OCR announced that it would not impose sanctions and penalties for HIPAA violations in connection with the good faith provision of telehealth services, provided non-public facing remote communications technologies were used for providing telehealth services. That meant that communications platforms that would not normally be permitted under HIPAA could be used for providing telehealth services, such as platforms provided by vendors who would not sign business associate agreements covering their products. The enforcement discretion period was in effect for the duration of the COVID-19 Public Health Emergency (PHE); however, when the PHE came to an end, OCR announced there would be a 90-day transition period to give...
Ottumwa Fire Department Fires Employees for Misconduct and HIPAA Violations
The Ottumwa Fire Department in Iowa has recently fired employees for alleged violations of the HIPAA Rules and other misconduct. The City of Ottumwa launched an investigation of three members of the fire department, two of whom have been terminated and one left the department in lieu of termination for “behaviors that violated department rules, safe practices, and the values and standards of the City of Ottumwa”. The city engaged the law firm, Dentons Davis Brown, to investigate allegations of misconduct, which included sexual activity while on duty, disclosures of sensitive information to unauthorized individuals, and allowing unauthorized individuals to ride in fire vehicles. Firefighters Derek Fye and Dillon McPherson were discovered to have violated the HIPAA rules by divulging patient information obtained by the fire department when responding to incidents, which included medical histories, conditions, and other information. Captain Bill Keith was similarly fired for HIPAA violations, allowing unauthorized individuals to ride in fire vehicles, failing to report instances of...



