Regal Medical Group Ransomware Attack Affects 3.3 Million Patients
Regal Medical Group, a San Bernardino, CA-based affiliate of the Heritage Provider Network, recently announced that it was attacked with ransomware. On December 2, 2022, employees experienced difficulty accessing data. Third-party cybersecurity experts were engaged to investigate the attack and assist with the HIPAA breach response and confirmed that malware had been used to encrypt files on some of its servers. The forensic investigation confirmed that the attackers gained access to the email servers on or around December 1 and exfiltrated files before the ransomware was deployed. The review of those files confirmed they contained the protected health information of patients of Regal Medical Group, Lakeside Medical Organization, ADOC Medical Group, and Greater Covina Medical. The files contained information such as names, phone numbers, addresses, dates of birth, diagnosis and treatment information, laboratory test results, prescription data, radiology reports, health plan member numbers, and Social Security numbers. Regal Medical Group said additional security measures have been...
Highmark Health Phishing Attack Affects 275,000 Patients
Pittsburg, PA-based Highmark Health, the second largest integrated delivery and financing system in the U.S., has recently announced that an unauthorized individual has accessed the email account of one of its employees following a response to a phishing email. After the employee clicked the link in the email and disclosed their credentials, the account was accessed remotely by an unauthorized third party who potentially viewed and exfiltrated emails and attachments from the account. The unauthorized account activity was detected by Highmark Health on December 15, 2022, with the initial compromise occurring on December 13, 2022. A review of the emails and attachments revealed they contained the protected health information of health plan members, such as group name, identification numbers, claim numbers, dates of service, procedures, prescription information, addresses, phone numbers, email addresses, and financial information. The Social Security numbers of a subset of individuals were also exposed. When the breach was detected, the affected mailbox was immediately deactivated,...
Tallahassee Memorial HealthCare Diverts Ambulances Due to Cyberattack
Last Thursday, Tallahassee Memorial HealthCare (TMH) in Florida was forced to take its IT systems online, divert ambulances, and suspend all non-emergency medical procedures due to a cyberattack. The hospital issued a statement confirming that it would only be accepting patients with Level 1 traumas from its immediate service area while the cyberattack is investigated and systems are restored. The hospital said the attack only affected specific systems, but other, unaffected systems were taken offline to contain the attack. Systems are being prioritized and will be brought back online one by one when it is safe to do so. On Thursday, the hospital could not provide any information on the likely timeframe for recovery but said updates will continue to be provided on its website. On Sunday, a statement was issued confirming progress is being made restoring systems, that TMH Physician Partners are still operational, and they will start seeing patients as scheduled from Monday, February 6, 2023; however, all non-emergency surgeries and outpatient procedures scheduled for Monday had been...
Banner Health Settles Alleged HIPAA Security Rule Violations for $1.25 Million
The HHS’ Office for Civil Rights has announced its second financial penalty of 2023 to resolve alleged violations of the Health Insurance Portability and Accountability Act (HIPAA). Banner Health has agreed to pay a financial penalty of $1,250,000 and adopt a corrective action plan to resolve the alleged HIPAA Security Rule violations. Phoenix, AZ-based Banner Health is one of the largest non-profit health systems in the United States. The health system includes 30 hospitals and more than 69 affiliated healthcare facilities in 6 U.S. states and employs more than 50,000 individuals. On July 13, 2016, Banner Health detected a security breach, with the subsequent investigation confirming hackers gained access to its systems on June 17, 2016. The hackers were able to access systems containing the protected health information (PHI) of 2.81 million individuals, including names, addresses, dates of birth, Social Security numbers, claims information, lab results, medications, diagnoses, and health insurance information. After being informed about the impermissible disclosure of PHI, OCR...
FTC Issues First Financial Penalty for a Health Breach Notification Rule Violation
The Federal Trade Commission’s Health Breach Notification Rule requires vendors of personal health records and related entities to issue notifications to consumers in the event of a breach of unsecured personal records. The rule took effect in 2009, yet compliance has not been enforced. That has now changed. Yesterday, the FTC issued its first penalty for noncompliance with the Health Breach Notification Rule to the prescription drug provider, GoodRx Holdings Inc, which has been ordered to pay a financial penalty of $1.5 million. In September 2021, the FTC issued a policy statement announcing its intention to start actively enforcing the Health Breach Notification Rule with a focus on health apps, which are generally not covered by HIPAA and data breaches are therefore not subject to the notification requirements of the HIPAA Breach Notification Rule. Two guidance documents – Health Breach Notification Rule: The Basics for Business – and Complying with FTC’s Health Breach Notification Rule – were published in January 2022 that clearly explained which entities are covered by...



