Maternal & Family Health Services Sued Over Ransomware Attack and Data Breach
A lawsuit has been filed against Maternal & Family Health Services (MFHS) in Pennsylvania which alleges the healthcare provider failed to protect patient data and did not send timely breach notifications. In January 2023, MFHS, one of the largest healthcare providers in the state, notified approximately 461,000 current and former patients about a security breach. According to the notifications, unauthorized individuals gained access to its network and used ransomware to encrypt files. MFHS said the sophisticated ransomware attack was discovered in April 2022. The forensic investigation confirmed the attackers had access to its network between August 2021 and April 2022, during which time they had access to, and potentially stole, patient data such as names, addresses, dates of birth, Social Security numbers, driver’s license numbers, financial account/payment card information, medical information, and health insurance information. At the time of issuing notifications, misuse of patient data had not been detected; however, as a precaution, complimentary credit monitoring and...
HC3 Sheds Light on Data Exfiltration Trends in Healthcare Cyberattacks
The Health Sector Cybersecurity Coordination Center has issued a security advisory warning about data exfiltration in healthcare cyberattacks, highlighting the extent of the practice and sharing several recommended mitigations. Data exfiltration typically occurs once a threat actor has gained access to a network, elevated privileges, and moved laterally. Data exfiltration is one of the last stages of the cyber kill-chain and the primary objective in many cyberattacks. There are several reasons for data theft. Nation-state actors often steal data for espionage purposes, cybercriminal groups steal healthcare data as it can be easily monetized and as leverage for extortion, and insiders steal data for financial gain, competitive advantage, and blackmail. When ransomware first started to be used by cybercriminal groups, files were simply encrypted; however, data exfiltration is now common. Data theft allows ransomware actors to profit from attacks when ransoms are not paid, and oftentimes it is the threat of publication of stolen data that prompts victims to pay up. Such is the...
Ransomware Attack Announced by Codman Square Health Center
Codman Square Health Center in Boston, MA, has confirmed that it was the victim of a ransomware attack in November 2022 in which hackers gained access to the protected health information of 10,161 current and former patients. The incident was detected on November 28, 2022, and third-party digital forensics experts were engaged to investigate the security breach and determine the nature and scope of the attack. The investigation confirmed that unauthorized individuals gained access to parts of its network between November 23 and November 28, and during which time they may have viewed or acquired files containing patient data. Codman Square Health Center said it was confirmed on January 25, 2023, that a folder on the compromised part of its network contained patient data, although it was not possible to tell if that folder was accessed. The files in that folder included names, addresses, birth dates, medical record numbers, diagnoses, treatment information, and claims information. Notifications are being sent to affected individuals and steps have been taken to improve privacy and...
Pixel Use Results in Impermissible Disclosure of the PHI 3.1 Million Cerebral Platform Users
The telehealth company, Cerebral Inc., has confirmed that pixels and other tracking technology on its website resulted in the impermissible disclosure of the personal and protected health information of 3,179,835 patients. Cerebral is a fully remote telehealth provider that provides access to mental health services, including online therapy, mental health assessments, and visits with clinicians to treat mental health issues such as anxiety, depression, and insomnia. On January 3, 2023, Cerebral said it discovered pixels and other tracking technologies on its platform had collected and transferred sensitive HIPAA-protected information to third parties such as Meta (Facebook), Google, TikTok, and others. Cerebral said in its breach notice that tracking technologies have been used by many bricks and mortar healthcare providers, telehealth companies, and other businesses on their websites, but was made aware that these technologies could potentially capture and impermissibly disclose sensitive data to the companies that provided those tracking technologies. An investigation was...
Community Health Systems to Notify Up to 1 Million Individuals About GoAnywhere Data Breach
In mid-February, Community Health Systems filed a report with the U.S. Security and Exchange Commission (SEC) confirming it had been affected by a security incident involving its secure file transfer software, Fortra’s GoAnywhere MFT. The Clop ransomware gang claimed responsibility for the attack and claimed to have exfiltrated data from around 130 users of the software. As per the group’s modus operandi, ransom demands were issued along with threats to publish the stolen data; however, somewhat atypically, ransomware was not used to encrypt files. In the SEC filing, Community Health Systems explained that the protected health information of up to 1 million individuals was potentially compromised and stated that the investigation into the incident was ongoing. Community Health Systems has now released further information on the data breach and said it will start sending notification letters to all affected individuals in mid-March. Community Health Systems confirmed that Fortra contracts with CHSPSC, LLC, which is a professional services company that provides services...



