HC3: Ransomware Groups are Exploiting GoAnywhere and PaperCut Vulnerabilities
The Health Sector Cybersecurity and Coordination Center (HC3) has issued a fresh ransomware warning to the healthcare and public health (HPH) sector following a spate of attacks on the HPH sector in April by the Clop and LockBit ransomware groups. HC3 has issued multiple alerts about the Clop and LockBit ransomware-as-a-service groups which have conducted multiple attacks on the healthcare sector. Clop was behind the attacks on Fortra’s GoAnywhere MFT solution in January/February 2023 and the 2022 attacks on the Accellion File Transfer Application (FTA), both of which exploited zero-day vulnerabilities in those solutions. The latest alert about LockBit was issued in December 2022 following multiple attacks on HPH sector organizations. The Clop group exploited the GoAnywhere MFT vulnerability (CVE-2023-0669) and stole data from around 130 organizations, and both groups have been observed exploiting two other recently disclosed vulnerabilities – CVE-2023-27350 and CVE-2023-27351 – which are authentication bypass vulnerabilities in the widely used print management software,...
90 Degree Benefits Facing Class Action Lawsuit Over 181,500-Record Data Breach
A lawsuit has been filed against 90 Degree Benefits over a breach of the HIPAA protected health information of 181,543 individuals. Unauthorized system activity was detected on or around December 10, 2022, and the forensic investigation determined its systems had been accessed by unauthorized individuals between December 5, 2022, and December 10, 2022. During that time, the attackers had access to parts of its network that contained patients’ and health plan members’ names, addresses, dates of birth, Social Security numbers, health information, and payment information. Affected individuals were notified about the breach by mail on or around April 7, 2023. The lawsuit alleges 90 Degree Benefits knew or should have been aware that it was a target for hackers, given the extent to which the healthcare industry has been targeted in recent years, especially considering 90 Degree Benefits experienced a similar data breach in February 2022. The February data breach should have made it clear that its data security measures were not sufficient and needed to be improved, yet despite that...
House Democrats Reintroduce Protecting America’s Workers Act on Worker’s Memorial Day
The Protecting America’s Workers Act was reintroduced by Reps. Joe Courtney (D-CT) and Bobby Scott (D-VA) on Worker’s Memorial Day and seeks to expand the coverage of the Occupational Safety and Health (OSH) Act to include the estimated 8 million state and local government workers in 24 states that are not currently covered by the act and increase the financial penalties for “high gravity” OSHA violations. The Protecting America’s Workers Act also seeks to reinstate the Volks Rule, which was repealed from OSHA by President Trump in 2017. The Volks Rule gave OSHA the authority to enforce recordkeeping requirements for work-related injuries and illnesses for five-and-a-half years rather than the 6-month statute of limitations established by OSHA. The Protecting America’s Workers Act has 12 co-sponsors and seeks to improve safety and health in the workplace by addressing the current shortfalls in OSHA. “Millions of workers still fall outside the law’s protections, weak sanctions fail to provide meaningful incentives for those employers tempted to cut corners on compliance with safety...
Organizations Face Increased Scrutiny of Health Data Breaches
Healthcare hacking incidents are increasing, there are new regulatory requirements and compliance initiatives due to Dobbs and Pixel use, and lawsuits against healthcare organizations over privacy violations are soaring. HIPAA-regulated entities and other organizations that operate in the healthcare space are now facing increased scrutiny of their data security practices and compliance programs, and the coming 12 months will likely see an increase in enforcement actions and lawsuits over privacy violations. The recently published BakerHostetler Data Security Incident Response Report (DSIR) draws attention to these issues and provides insights into the threat landscape to help organizations determine how to prioritize their efforts and investments. The report, now in its 9th year, was based on 1,160 security incidents managed by BakerHostetler’s Digital Assets and Data Management Practice Group in 2022. After a surge in ransomware attacks in 2021, 2022 saw a reduction in attacks; however, there was a surge in ransomware activity toward the end of the year and that surge has...
Mailing Error at CMS Vendor Affects 10,000 Medicare Beneficiaries
The Centers for Medicare & Medicaid Services (CMS) has started notifying certain Medicaid beneficiaries about an impermissible disclosure of some of their protected health information due to a mailing error at one of its contractors. The incident occurred at Palmetto GBA, which the CMS uses to handle claims. Between January 8 and January 29, 2023, Palmetto GBA mailed Medicare Summary Notices (MSNs) to Medicare recipients; however, a computer programming issue with its print mail services resulted in MSNs for the final quarter of 2022 being mailed to other Medicare beneficiaries within the same zip code. The programming error was discovered by Palmetto GBA on February 7, 2023, and reported the incident to the CMS the same day. The CMS then worked with Palmetto GBA to identify the individuals affected and determined the error had resulted in 10,011 MSNs intended for Medicare beneficiaries in Alabama, Georgia, and Tennessee being sent to incorrect individuals. The MSNs contained the Medicare beneficiary’s name, address, claim number, dates of service, the last four digits of their...



