Dental Health Management Solutions Notified Patients About Historic Data Breach
Cedar Park, TX-based Dental Health Management Solutions (DHMS), a provider of dental services to the government/military and private patients has recently announced – via its legal counsel – that the protected health information of certain patients was exposed in a 2021 hacking incident. In a February 2023 notification to the Maine Attorney General, DHMS said it detected a network intrusion on or around August 20, 2021, with the forensic investigation confirming its network was compromised on July 17, 2021. A comprehensive review was conducted of all files that were potentially accessed or acquired in the attack and confirmed that 3,205 individuals have been affected. The types of information exposed varied from individual to individual and may have included names, addresses, medical information, health insurance information, Medicaid identification numbers, driver’s licenses, account and routing numbers, and Social Security numbers. DHMS said it has changed passwords and implemented multifactor authentication and offered affected individuals complimentary credit monitoring and...
Losses to Phishing Attacks Increased by 76% in 2022
Losses to phishing attacks increased by 76% last year, with almost one-third of companies losing money to successful phishing attacks according to Proofpoint’s recently published 2023 State of the Phish Report. In 2022, more than 4 out of 5 surveyed organizations experienced at least one successful phishing attack, with more than half of those organizations experiencing at least three successful phishing attacks. The data for the report came from a global survey of 7,500 working adults, 1,050 IT security professionals, and the results of more than 135 million simulated phishing emails over 12 months. Phishing is one of the most commonly used initial access vectors in cyberattacks, commonly leading to costly account compromises, data breaches, and ransomware attacks. Phishing is usually associated with email, but 2022 saw a marked increase in telephone-oriented attack delivery (TOAD). These attacks typically involve emails urging the recipient to call a customer service hotline to resolve a security or account issue. Call centers are established – often in India – and the operators...
Biden Administration Announces New National Cybersecurity Strategy
The Biden Administration has announced a long-awaited new national cybersecurity strategy for tackling the growing threat of cyberattacks on critical infrastructure, disrupting cyber threat operations, and improving cyber resilience against malicious cyber activity from cybercriminal groups and nation-state actors. The aim is to ensure a safe and secure digital ecosystem for all Americans and that requires fundamental shifts in roles, responsibilities, and resources in cyberspace and a shifting of the burden of cyber resilience away from individuals, small businesses, and local governments onto the multi-billion dollar technology companies that provide software and information technology. The new strategy will involve a more intentional, better coordinated, and more well-resourced approach and a realigning of incentives to favor long-term investments in cybersecurity to achieve a better balance between defending against current threats and planning for and investing in a cyber-resilient future. The new cybersecurity strategy sets a path to address current and future threats to...
Settlement Reached in Preferred Home Care Data Breach Lawsuit
AssistCare Home Health Services has agreed to settle a class action lawsuit, filed on behalf of individuals affected by a cyberattack and HIPAA data breach in January 2021. In March 2021, AssistCare Home Health Services, which does business as Preferred Home Care of New York, notified more than 92,000 patients that their protected health information had been exposed in a cyberattack. Unauthorized individuals gained access to its network between January 8 and January 10, 2021, and exfiltrated files containing patient data. The attack was conducted by the Sodinokibi ransomware group, which published some of the stolen data on its data leak site. The compromised data included names, personal information, health information, and Social Security numbers. A class action lawsuit – Simmons v. AssistCare Home Health Services LLC, was filed in the New York Superior Court for Kings County covering the 92,283 individuals that were notified about the data breach. The lawsuit alleged negligence for failing to implement reasonable cybersecurity measures to protect against a known risk of...
BetterHelp Settlement Agreed with FTC to Resolve Health Data Privacy Violations
The Federal Trade Commission (FTC) has announced a settlement has been reached with the California-based online counseling service provider, BetterHelp Inc., to resolve allegations of violations of the FTC Act. The proposed BetterHelp settlement requires $7.8 million to be paid to consumers as refunds due to deceptive trading practices. This is the first such FTC settlement to require refunds to be paid to consumers whose health information was compromised. FTC Cracks Down on Deceptive Privacy Practices by Online Healthcare Service Providers This is the second such settlement to be announced by the FTC in the past month and is part of its current crackdown on deceptive trading practices by online providers of healthcare services. The announcement was made just a few days after a $1.5 million settlement with GoodRx was signed off by a judge to resolve alleged FTC Act and Health Breach Notification Rule violations. These settlements are intended to send a message to providers of online health services – which are often not bound by the protections of HIPAA – that they must ensure...



