Phoenician Medical Center Cyberattack Affects Up to 162,500 Patients
Phoenician Medical Center, Inc. (PMC) has recently reported a security incident that disrupted some of its IT systems. The incident was detected on March 31, 2023, although it is unclear from the breach notifications when hackers first gained access to its network. The forensic investigation confirmed that there had been unauthorized access to files containing the protected health information of patients, some of which may have been obtained by the hackers. On April 25, 2023, PMC confirmed the affected information included names, contact information, demographic information, date of birth, state identification numbers, medical record numbers, diagnosis and treatment information, provider name(s), date(s) of service, prescription information, and/or health insurance information. Affected patients had received medical services at PMC or its affiliated companies, Phoenix Neurological & Pain Institute, and/or Laser Surgery Center between 2016 and 2023. The HIPAA breach was reported to the HHS’ Office for Civil Rights as affecting up to 162,500 current and former patients. PMC said...
Naked Patient Photos Published After Ransomware Attack on Plastic Surgery Clinic
Legal counsel for the Hollywood, CA-based plastic surgeon, Gary Motykie, M.D, recently notified patients about a cyberattack and data theft incident. According to the notification letters, Dr. Gary Motykie was recently contacted by a cyber threat actor who claimed to have accessed his IT systems and was in possession of sensitive patient information. The notification was received on May 9, 2023, and a third-party incident response firm was engaged to investigate and determine the validity of the threat actor’s claims. A data breach was confirmed on or around June 6, 2023, with the review of the affected files confirming they contained information such as first and last name, address, driver’s license/identification card number, financial account information, payment card number and CVV code, Social Security Number, health insurance information, intake forms, which may include medical information and medical history, and images taken in connection with the services provided. The types of data varied from individual to individual and may have included only some of the above...
Office 365 Spam Filter and Phishing Protection
If you work in healthcare and regularly receive spam and malicious emails in your Office 365 inbox there is a strong probability that you only have the basic Microsoft spam filter – Exchange Online Protection (EOP) in place. Given the extent to which healthcare organizations are being targeted by cybercriminals and the high cost of an email data breach, the basic Microsoft spam filter provided with Office 365 licenses as standard is unlikely to provide sufficient protection and could be exposing your organization to an excessive level of risk. Office 365 is an Excellent Software Suite, but Office 365 Anti Spam Protections are not a Strong Point Microsoft has an extensive range of products within its Office 365 suite and actively markets those products to healthcare organizations, including email services. There are now in excess of 1 million companies globally using Office 365 and well over 600,000 companies in the United States use Office 365. In October 2019, Microsoft broke the 200 million active monthly user mark and the number is increasing at a rate of around 3 million per...
White House Publishes National Cybersecurity Strategy Implementation Plan
The White House has published a roadmap for implementing President Biden’s March 2023 National Cybersecurity Strategy to ensure transparency and a continued path for coordination. The National Cybersecurity Strategy Implementation Plan (NCSIP) includes more than 65 federal initiatives that aim to improve resilience against cyber threats and disrupt cyber threat operations, and changes how the United States allocates roles, responsibilities, and resources in cyberspace. Two major shifts include ensuring that the biggest, most capable, and best-positioned entities in both the public and private sectors assume a greater share of the burden for mitigating cyber risk and increasing the incentives to favor long-term investments in cybersecurity. The initiatives are based on five pillars and aim to achieve 27 strategic objectives. The first pillar is concerned with defending critical infrastructure against cyberattacks that are increasing in number and sophistication. Cybersecurity requirements will be established to support national security and public safety across all critical...
First Lawsuit Filed Against HCA Healthcare Over 11 Million-Record Data Breach
Lawsuits against HCA Healthcare were an inevitability following a data breach that affected approximately 11 million individuals and saw the stolen data listed for sale on a dark web forum. The breach was announced by HCA Healthcare on July 10, 2023, and while the total number of affected individuals affected has yet to be confirmed, 27 million lines of data were compromised, which equates to around 11 million individuals. Since the investigation is still in the early stages, little information has been released so far about the nature of the cyberattack, other than an unauthorized individual gaining access to an external storage location used for formatting emails. HCA Healthcare said highly sensitive information such as Social Security numbers, financial information, and clinical information does not appear to have been compromised, only information such as names, dates of birth, email addresses, phone numbers, and next appointment dates. The first lawsuit in relation to the breach was filed in the Tennessee Middle District Court on Wednesday by the law firms Shamis & Gentile...



