January 2023 Healthcare Data Breach Report
January is usually one of the quietest months of the year for healthcare data breaches and last month was no exception. In January, 40 data breaches of 500 or more records were reported to the HHS’ Office for Civil Rights, the same number as in December 2022. January’s total is well below the 53 data breaches reported in January 2022 and the 12-month average of 58 data breaches a month. For the second successive month, the number of breached records has fallen, with January seeing just 1,064,195 healthcare records exposed or impermissibly disclosed – The lowest monthly total since June 2020, and well below the 12-month average of 4,209,121 breached records a month. Largest Healthcare Data Breaches in January 2023 In January there were 13 data breaches involving 10,000 or more records, 8 of which involved hacked network servers and email accounts. The largest HIPAA compliance data breach of the month affected Mindpath Health, where multiple employee email accounts were compromised. 5 unauthorized access/disclosure incidents were reported that impacted more than 10,000...
CentraState Medical Center Facing Class Action Lawsuit Over December 2022 Ransomware Attack
A lawsuit has been filed against Freehold Township, NJ-based CentraState Healthcare System over its December 2022 ransomware attack, a few days after the health system started sending notification letters to around 617,000 affected patients. The lawsuit alleges CentraState Medical Center was negligent for failing to implement adequate and reasonable safeguards to protect the sensitive data of its patients. On February 10, 2023, CentraState confirmed it had suffered a ransomware attack that disrupted its computer systems. The health system detected the attack on December 29, 2022, blocked the unauthorized access, and launched an investigation to determine the nature and scope of the breach. CentraState confirmed that the hackers gained access to part of its systems that contained an archived database, and stole that database. The database included names, addresses, dates of birth, Social Security numbers, health insurance information, medical record numbers, and patient account numbers. Complimentary credit monitoring and identity theft protection services were offered to...
Biden Administration Considers HIPAA Update to Better Protect Reproductive Health Information
The Biden Administration is considering new rulemaking to update HIPAA to better protect reproductive health information, following the Supreme Court Decision in Dobbs v. Jackson Women’s Health Organization, which removed the federal right to abortion and left it to individual states to decide on the legality of abortions for state residents. Currently, at least 24 U.S. states have implemented bans on abortions or are likely to do so, with 12 states already having a near-total ban. The Health Insurance Portability and Accountability Act classes reproductive health information as protected health information (PHI), so uses and disclosures are restricted by the HIPAA Privacy Rule. Following the Supreme Court decision, the HHS issued guidance to HIPAA-regulated entities on how the HIPAA Privacy Rule applies to reproductive healthcare data, confirming uses and disclosures of reproductive health information are restricted, and that the information can only be used or disclosed without a valid patient authorization for purposes related to treatment, payment, or healthcare operations. The...
Hacking and Data Theft Incident Reported by CentraState Healthcare System
Freehold Township, NJ-based CentraState Healthcare System has recently confirmed that its network was compromised by unauthorized individuals in December 2022. Unusual activity was detected within its computer systems on December 29, and immediate action was taken to isolate the network and block unauthorized access. CentraState has been working with the Federal Bureau of Investigation and independent cybersecurity experts to investigate the breach and has determined that the unauthorized party exfiltrated a copy of an archived database that contained the protected health information of patients. The database included the following information: names, addresses, dates of birth, Social Security numbers, health insurance information, medical record numbers, and patient account numbers. Additionally, some information related to care received at CentraState, such as date(s) of service, physician names and departments, treatment plans, diagnoses, visit notes, and prescription information. CentraState said it continually enhances the security of its electronic systems and will continue...
Lehigh Valley Health Network and MKS Instruments Recovering from Ransomware Attacks
Lehigh Valley Health Network (LVHN) in Pennsylvania has confirmed that it is dealing with a ransomware attack that was detected on February 6, 2023. An announcement was made on Monday confirming the Russian-speaking ransomware gang, BlackCat, was behind the attack and demanded a ransom, but no payment was made. Brian A. Nester, LVHN President and CEO, said the attack has not affected its operations and care continues to be provided to patients. While the attack is still being investigated, Nester has confirmed that the attack was conducted on a network supporting an unnamed physician practice in Lackawanna County and that the network housed a system that was used to store “clinically appropriate patient images for radiation oncology treatment,” and other sensitive information. That practice appears to be Delta Medix in Scranton, PA. It is currently unclear if other physician practices have been affected. The LVHN technology team launched an investigation when suspicious network activity was detected, its network was immediately secured, and third-party cybersecurity experts were...



