One Brooklyn Health Notifies Patients About November 2022 Cyberattack
One Brooklyn Health System, which operates three hospitals in Brooklyn, NY, has started notifying patients affected by a November 19, 2022, cyberattack. One Brooklyn Health made a public announcement in late November confirming that it was dealing with a cyberattack, and said it had shut down IT systems to contain the incident and had launched an investigation into the breach. Those systems remained offline for more than a week. In late January, One Brooklyn Health confirmed that patient data had been compromised, and the attackers had access to information such as names, dates of birth, billing and claims data, treatment details, medical record numbers, prescriptions, health insurance information, and Social Security numbers. The review of the affected files was a time-consuming process, which took until March 21, 2023, to complete. Contact information then needed to be verified to allow breach notification letters to be mailed. One Brooklyn Health said it started mailing notification letters to affected patients on April 20, 2023. One Brooklyn Health said the investigation...
Major Massachusetts Health Insurer Suffers Ransomware Attack
Point32 Health, the second-largest health insurer in the state of Massachusetts, has announced it has experienced a ransomware attack that has resulted in system outages, including systems that are used to service its members, accounts, brokers, and providers. Point32 Health is the parent company of Tufts Health Plan and Harvard Pilgrim Health Care and serves more than 2 million individuals in New England. Point32 Health said the outages have mainly affected Harvard Pilgrim Health Care customers, in particular, those with commercial or New Hampshire Medicare plans. Tufts Health Plan members are not understood to have been affected. Point32 Health said it detected the presence of a malicious actor within its network on April 17, 2023, and took immediate action to contain the threat, which involved taking multiple systems offline while the attack was investigated and remediated. Efforts are underway to restore systems as soon as possible, and the staff and third-party cybersecurity experts are working around the close to bring systems back online. The attack has caused disruption to...
March 2023 Healthcare Data Breach Report
Our monthly data breach reports are based on data breaches of 500 or more records that have been reported to the Department of Health and Human Services’ Office for Civil Rights (OCR) each month. The monthly reports provide an indication of the extent to which healthcare data breaches are increasing, decreasing, or remaining flat. To view longer-term healthcare data breach trends, visit our healthcare data breach statistics page. Healthcare Data Breaches Reported in March 2023 In March, 63 breaches of 500 or more records were reported to OCR, which is a 46.51% increase from February, 6.92% more than the 12-month average, and 40% more breaches than in March 2022. There was a 15.62% month-over-month increase in breached records, with 6,382,618 records exposed or impermissibly disclosed across the 63 data breaches. That’s 36% more records breached than the 12-month average and 76.46% more breached records than in March 2022. Largest Healthcare Data Breaches In March, 22 healthcare data breaches were reported that impacted more than 10,000 individuals, up from 17 such breaches in...
Medtronic Alerts InPen App Users About Disclosures of Personal Data to Google
The medical device manufacturer Medtronic – dba Medtronic MiniMed and MiniMed Distribution Corp (Medtronic Diabetes) – has recently confirmed that the personal information of users of its InPen Diabetes Management App on iOS and Android have had some of their personal information disclosed to Google due to the use of tracking and authentication code within the InPen App. The app utilized Google Analytics for Firebase, Crashlytics for Firebase, and Firebase Authentication. These tools disclosed certain information about app users to Google, especially when users were logged into their Google accounts at the same time that they used the InPen App. As a result, their identities and information about online activities were shared with Google. The tools were used by Medtronic Diabetes to gather information about the use of the app, identify technical issues, assess app performance, and understand user needs to provide care to customers and improve services. Medtronic Diabetes said the data collected by these tools is analyzed at a consolidated rather than individual level...
Veterans’ Healthcare Facility in Arizona Exposed Employees to Potentially Deadly Hazards
A U.S. Department of Labor investigation of an Arizona Department of Veteran Affairs (VA) healthcare facility found workers had been put at risk by exposing them to potentially deadly hazards on steam lines. Employees were allowed to work on the steam lines without ensuring they followed the required safety procedures. Federal agencies such as the VA are required to comply with the same safety and health standards as private sector employers that are covered by the Occupational Safety and Health (OSH) Act and must ensure that employees conduct their work duties safely and are not exposed to grave danger from hazards. Federal safety inspectors visited the VA’s Prescott facility, operated by the Northern Arizona Veterans Affairs Health Care System, in October 2022 to assess compliance and determined that the facility lacked energy-isolating procedures known as lockout/tagout, which prevents the release of hazardous energy during the maintenance and servicing of steam lines. Employees were found to be using ad-hoc methods that did not meet Occupational Safety and Health...



