Healthcare Data Potentially Compromised in 5 Hacking Incidents
NYSARC Columbia County Chapter Notifies Individuals About July 2022 Ransomware Attack NYSARC Columbia County Chapter (COARC) has started notifying certain individuals that some of their protected health information has potentially been obtained by unauthorized individuals in a July 2022 ransomware attack. According to the notifications, suspicious activity was detected within its network on July 19, 2022, that was consistent with a ransomware attack. Steps were immediately taken to contain the incident and an investigation was launched, which confirmed that the attacker had access to certain COARC systems for a limited period in July. The attack appears to have been conducted with the sole purpose of encrypting data for extortion purposes. It is not known if data exfiltration occurred but it could not be ruled out. COARC did not say if the ransom was paid. COARC said the types of information involved included names and one or more of the following: address, social security number, financial account, credit card information, medical information, student information, driver’s...
Credential Stuffing Attack Exposed United HealthCare Member Data
United HealthCare (UHC) has started notifying certain members that some of their protected health information may have been disclosed to unauthorized individuals as a result of credential stuffing attacks on the UHC mobile application. Credential stuffing is a type of attack where username and password combinations obtained in a breach at one platform are used to access accounts on an unrelated platform. These attacks can only succeed if usernames and passwords have been reused on multiple platforms. The accounts subjected to unauthorized access included information such as names, birthdates, addresses, health insurance member ID numbers, service dates, provider names, claim details, and group names and numbers. No Social Security numbers, financial information, or driver’s license numbers were exposed. The attacks occurred between February 19 and February 25, 2023. UHC took its portal offline immediately when the attacks were detected to prevent further unauthorized access and a password reset was performed. The investigation found no evidence to suggest the credentials had been...
HC3: Ransomware Groups are Exploiting GoAnywhere and PaperCut Vulnerabilities
The Health Sector Cybersecurity and Coordination Center (HC3) has issued a fresh ransomware warning to the healthcare and public health (HPH) sector following a spate of attacks on the HPH sector in April by the Clop and LockBit ransomware groups. HC3 has issued multiple alerts about the Clop and LockBit ransomware-as-a-service groups which have conducted multiple attacks on the healthcare sector. Clop was behind the attacks on Fortra’s GoAnywhere MFT solution in January/February 2023 and the 2022 attacks on the Accellion File Transfer Application (FTA), both of which exploited zero-day vulnerabilities in those solutions. The latest alert about LockBit was issued in December 2022 following multiple attacks on HPH sector organizations. The Clop group exploited the GoAnywhere MFT vulnerability (CVE-2023-0669) and stole data from around 130 organizations, and both groups have been observed exploiting two other recently disclosed vulnerabilities – CVE-2023-27350 and CVE-2023-27351 – which are authentication bypass vulnerabilities in the widely used print management software,...
90 Degree Benefits Facing Class Action Lawsuit Over 181,500-Record Data Breach
A lawsuit has been filed against 90 Degree Benefits over a breach of the HIPAA protected health information of 181,543 individuals. Unauthorized system activity was detected on or around December 10, 2022, and the forensic investigation determined its systems had been accessed by unauthorized individuals between December 5, 2022, and December 10, 2022. During that time, the attackers had access to parts of its network that contained patients’ and health plan members’ names, addresses, dates of birth, Social Security numbers, health information, and payment information. Affected individuals were notified about the breach by mail on or around April 7, 2023. The lawsuit alleges 90 Degree Benefits knew or should have been aware that it was a target for hackers, given the extent to which the healthcare industry has been targeted in recent years, especially considering 90 Degree Benefits experienced a similar data breach in February 2022. The February data breach should have made it clear that its data security measures were not sufficient and needed to be improved, yet despite that...
House Democrats Reintroduce Protecting America’s Workers Act on Worker’s Memorial Day
The Protecting America’s Workers Act was reintroduced by Reps. Joe Courtney (D-CT) and Bobby Scott (D-VA) on Worker’s Memorial Day and seeks to expand the coverage of the Occupational Safety and Health (OSH) Act to include the estimated 8 million state and local government workers in 24 states that are not currently covered by the act and increase the financial penalties for “high gravity” OSHA violations. The Protecting America’s Workers Act also seeks to reinstate the Volks Rule, which was repealed from OSHA by President Trump in 2017. The Volks Rule gave OSHA the authority to enforce recordkeeping requirements for work-related injuries and illnesses for five-and-a-half years rather than the 6-month statute of limitations established by OSHA. The Protecting America’s Workers Act has 12 co-sponsors and seeks to improve safety and health in the workplace by addressing the current shortfalls in OSHA. “Millions of workers still fall outside the law’s protections, weak sanctions fail to provide meaningful incentives for those employers tempted to cut corners on compliance with safety...



