SundaySky Cyberattack Impacts 37,000 Health Plan Members
SundaySky, a New York-based provider of software solutions to businesses for creating marketing videos, has recently announced that unauthorized individuals gained access to servers in its cloud environment and may have obtained customer data. Unauthorized access was detected on January 8, 2023, and the forensic investigation confirmed that files were exfiltrated between January 6 and January 8, 2023. Those files contained customer-provided health plan information from December 2018 to January 2019. SundaySky worked with the health plan provider to determine the compromised information, and the review was completed on February 20, 2023. Notifications have now been sent to the 37,095 affected individuals. The types of data compromised included first names, personal email addresses, Healthcare Savings Account (HSA) effective date and deductible, and information related to copay. SundaySky said additional technical safeguards have now been implemented for its cloud environment to prevent similar breaches in the future. Postal Prescription Service Impermissibly Disclosed Patient Names...
FBI: Losses to Cybercrime Increased by 49% in 2022 to $10.3 Billion
The Federal Bureau of Investigation (FBI) has published its 2022 Internet Crime Report, which shows at least $10.3 billion was lost to cybercrime in 2022, up 49% ($3.4 billion) from 2021, despite a 5% reduction in complaints (800,944). Over the past 5 years, the FBI Internet Crime Complaint Center (IC3) has received reports of losses of more than $27.6 billion across 3.26 million complaints to IC3. FBI data show a 36% year-over-year decrease in ransomware attacks, which fell from 3,729 complaints in 2021 to 2,385 complaints in 2022. Despite this decrease, the FBI says ransomware still poses a significant threat, especially to the healthcare sector which ranked top out of 16 critical infrastructure sectors for ransomware attacks in 2022 and actually saw an increase in complaints. 210 ransomware complaints were filed with IC3 in 2022 by healthcare organizations compared to 148 in 2021. The FBI has observed an increase in double extortion tactics in ransomware attacks, where data are stolen in addition to file encryption and payment is required to obtain the decryption keys and to...
Class Action Lawsuit Filed Against Cardiovascular Associates Over 441K-Record Data Breach
Cardiovascular Associates in Alabama is facing a class action lawsuit over a recently reported hacking incident in which patients protected health information (PHI) was stolen. The security incident was detected on December 5, 2022, and the forensic investigation determined hackers had access to its network for a week and exfiltrated files containing the PHI of 441,640 individuals, including names, addresses, birth dates, Social Security numbers, driver’s license numbers and health, insurance, and billing/claims information. The lawsuit was filed on March 15, 2023, by the law firm Milberg Coleman Bryson Phillips Grossman PLLC on behalf of plaintiff, Samuel Lee. The lawsuit alleges Cardiovascular Associates “intentionally, willfully, recklessly, or negligently” failed to implement reasonable and appropriate safeguards to ensure the confidentiality, integrity, and availability of patient information, failed to meet its obligations under the Federal Trade Commission (FTC) Act and HIPAA, and did not implement cybersecurity measures to industry standards, such as those detailed in the...
February 2023 Healthcare Data Breach Report
The number of healthcare data breaches reported over the past three months has remained fairly flat, with only a small uptick in breaches in February, which saw 43 data breaches of 500 or more records reported to the HHS’ Office for Civil Rights (OCR), well below the 12-month average of 57.4 reported breaches a month. An average of 41 HIPAA breaches have been reported each month over the past 3 months, compared to an average of 50.6 breaches per month for the corresponding period last year. The downward trend in breached records did not last long. There was a sizeable month-over-month increase in breached records, jumping by 418.7% to 5,520,291 records. February was well above the monthly average of 4,472,186 breached records a month, with the high total largely due to a single breach that affected more than 3.3 million individuals. Largest Healthcare Data Breaches Reported in February 2023 17 healthcare data breaches of 10,000 or more records were reported in February, all of which were hacking incidents. The largest data breach affected 3,300,638 patients of 4 medical...
Feds Release Updated Threat Intelligence on LockBit 3.0 Ransomware
A joint cybersecurity advisory has been issued by the Federal Bureau of Investigation (FBI), the Cybersecurity and Infrastructure Security Agency (CISA), and the Multi-State Information Sharing & Analysis Center (MS-ISAC) about LockBit 3.0 ransomware, also known as LockBit Black. The LockBit ransomware group has been in operation since at least September 2019 and is one of the most prolific ransomware groups. The group conducted more attacks than any other ransomware operation in 2022 and it has been estimated that LockBit ransomware is involved in around 40% of all ransomware attacks worldwide. The group is believed to have conducted more than 1,000 attacks on organizations in the United States and has generated more than $100 million in ransom payments. LockBit is a ransomware-as-a-service operation that recruits affiliates to conduct attacks in return for a cut of the ransoms they generate. The group engages in double extortion tactics, where files are stolen prior to encryption and threats are issued to publish or sell the stolen data if the ransom is not paid. Victims are...



