Advent Health Partners Proposes $500,000 Settlement to Resolve Class Action Data Breach Lawsuit
The Nashville, TN-based health system, Advent Health Partners, has proposed a $500,000 settlement to resolve claims related to a September 2021 HIPAA data breach involving the protected health information of 61,072 patients. Advent Health Partners detected a breach of its email environment in early September 2021. The investigation confirmed hackers had access to, and potentially stole, the protected health information of patients such as names, Social Security numbers, driver’s license information, dates of birth, health insurance, medical treatment information, and financial account information. Affected individuals were notified about the breach in March 2022, and were offered credit monitoring services for 12 months. A lawsuit – McHenry v. Advent Health Partners, Inc. – was filed in the U.S. District Court for the Middle District of Tennessee against Advent Health Partners over the breach. The lawsuit alleged the health system failed to implement reasonable and appropriate cybersecurity measures, despite being aware of the high risk of phishing attacks on healthcare...
Louisiana Health Systems Sued for Pixel-Related Disclosures of Patient Information
Two Louisiana health systems are being sued over the use of pixels on their websites, which allegedly captured and impermissibly disclose patient data to third parties such as Facebook and Instagram. New Orleans-based LCMC Health System operates 9 hospitals in Southern Louisiana and Shreveport-based Willis-Knighton Health System operates 5 hospitals in Northwestern Louisiana. Both health systems are named as defendants in a lawsuit recently filed by law firm Herman Herman & Katz on behalf of plaintiff John Doe, and similarly situated individuals. The lawsuit alleges the health systems added Metal Pixel code to their websites, which allows the sensitive personal and protected health information of website users to be captured. The code is typically used for tracking user activity on websites to improve website performance and the user experience; however, the tracking code also transmits data to Meta and that information is potentially made available to third parties for advertising purposes on its Facebook and Instagram social media platforms. The Department of Health and Human...
Mscripts Cloud Storage Misconfiguration Exposed PHI for 6 Years
The mobile pharmacy solution provider, mscripts, has recently announced that a misconfiguration of its cloud storage environment has exposed client data online for the past 6 years. The misconfiguration was detected and remediated on November 18, 2022, with the third-party forensics investigation confirming the cloud storage environment had been unsecured since September 30, 2016. A review of the files stored in that environment confirmed they contained the protected health information of 66,372 patients of participating pharmacies. The information related to locker pickups at pharmacy locations, and also included images of prescription bottles and insurance cards, which had been submitted via the mscripts web or mobile app. The information potentially accessed during that time includes names, dates of birth, phone numbers, addresses, prescription numbers, medication names, originating pharmacy information, health insurance company names, member IDs, group numbers, and, in certain cases, dependents’ names. mscripts said the issue has now been resolved and security procedures have...
Rise Interactive Media & Analytics, DotHouse Health, and Reventics Hacked
Reventics Reventics, a Greenwood Village, CO-based clinical documentation improvement and revenue cycle management company, has recently confirmed that hackers gained access to its computer environment and accessed and stole patient data. The cyber intrusion was detected by Reventics on or around December 15, 2022, when suspicious activity was identified on some of its servers. A third-party cybersecurity and digital forensics company was engaged to investigate the breach, and determined on December 27, 2022, that the files exfiltrated from its systems contained HIPAA-protected data, including names, birth dates, Social Security numbers, financial information, healthcare provider details, health plan names, clinical data, and service/procedure codes and a brief description of those codes. Reventics said it has implemented additional safeguards to prevent further cyberattacks and data breaches, including new encryption controls. A new, comprehensive security risk analysis has also been performed and further training has been provided to the workforce. Affected individuals are now...
PHI Compromised in 4 Recent Ransomware and Malware Attacks
Teijin Automotive Technologies Says Welfare Plan Data Compromised in December Ransomware Attack Teijin Automotive Technologies has recently confirmed the protected health information of 25,464 members of its welfare plan has potentially been accessed and stolen in a December 1, 2022, ransomware attack. Teijin Automotive Technologies has been transparent about the attack and its cause, confirming that its security systems were circumvented in a phishing attack. An employee clicked on a link in a phishing email on November 30, which allowed the threat actor to steal credentials, compromise the company’s servers, and deploy ransomware the following day. The attack was contained by December 5, 2022. Prompt action was taken by the IT team to prevent any further unauthorized access and law enforcement and the FBI were immediately notified and provided assistance with the investigation. The review of the compromised servers revealed they contained information related to the company’s welfare plan such as names, addresses, birth dates, Social Security numbers, health insurance policy...



