US Wellness Inc & Blue Shield of California Victims of GoAnywhere Hack
Data breaches have recently been reported by Blue Shield of California, US Wellness Inc., Health Plan of San Mateo, and the California Department of Health Care Services. Blue Shield of California – GoAnywhere Hack Blue Shield of California (BSC) has confirmed that the protected health information of 63,341 individuals has been stolen in a hacking incident that exploited a zero-day vulnerability in Fortra’s GoAnywhere Managed File Transfer-as-a-service (MFTaaS) application. BSC said it was notified on February 5, 2023, about the data breach by its provider, Brightline Medical Associates, which provides virtual behavioral health coaching and therapy for families and children, and confirmed that the file transfer application was compromised between January 28, 2023, and January 31, 2023. During that time, the threat actor responsible downloaded files that contained sensitive information. The following types of information were present in the files: name, address, birth date, gender, Blue Shield subscriber ID number, phone number, e-mail address, plan name, and plan group number. When...
Hacking Incidents Reported by Atlantic General and Lawrence General Hospitals
A round-up of data breaches that have recently been reported to the HHS’ Office for Civil Rights, state Attorneys General, and the media. Atlantic General Hospital – Ransomware Attack Atlantic General Hospital (AGH) in Berlin, MD, has recently reported a ransomware attack to the Maine Attorney General that has affected up to 30,704 individuals. The attack was detected on January 29, 2023, when files were discovered to have been encrypted. A third-party computer forensics firm was engaged to assist with the investigation and determined that there was unauthorized access to files containing patient information from January 20, 2023. The review of those files was completed on March 6, 2023, and confirmed they contained names, Social Security numbers, financial account information, and one or more of the following data types: medical record number, treating/referring physician, health insurance information, subscriber number, medical history information, or diagnosis/treatment information. Notification letters were mailed to the affected individuals on March 24, 2023. Affected...
New York Law Firm Pays $200,000 to State AG to Resolve HIPAA Violations
A New York law firm that suffered a LockBit ransomware attack has agreed to pay a financial penalty of $200,000 to the New York Attorney General to resolve alleged violations of New York General Business Law and the Privacy and Security Rules of the Health Insurance Portability and Accountability Act (HIPAA). Heidell, Pittoni, Murphy & Bach LLP (HPMB) is a New York City-based medical malpractice law firm. On or around Christmas Day 2021, the LockBit ransomware gang gained access to its network and encrypted files. The investigation confirmed that files were exfiltrated in the attack, including legal documents, patient lists, and medical records. The patient information included names, birthdates, medical histories, treatment information, Social Security numbers, and health insurance information. The incident was reported to the HHS’ Office for Civil Rights on May 16, 2022, as affecting 114,979 individuals. HPMB engaged a third-party ransomware remediation firm to negotiate with the threat actor and ended up paying $100,000 for the keys to decrypt files and to prevent the...
Improve Mobile Device Security with this HC3 Checklist
The Health Sector Cybersecurity Coordination Center (HC3) has published a mobile device security checklist to help healthcare organizations address a common cybersecurity weak point and better protect patient data. Healthcare organizations employ a wide range of mobile devices, many of which are networked and collect, store, and transmit patient information. These devices are often a critical part of healthcare operations and may number in the thousands at large hospitals. While these devices perform essential functions, they increase the attack surface considerably and they often contain vulnerabilities that can potentially be exploited to gain access to patient data and the healthcare networks to which they connect. The risks associated with the devices vary based on the nature of the devices and their use. Devices can be lost or stolen, they may connect to unsecured Wi-Fi networks, and software and applications may have vulnerabilities that can be exploited, resulting in unauthorized network access or the downloading of malware or ransomware. HC3 has published a simple and...
Ransomware Attacks Increased by More Than 51% in February
Ransomware activity increased in February according to the latest GRIT Ransomware Report from GuidePoint Security. The report is based on data collected by the GuidePoint Research and Intelligence Team, which reports a 51.5% increase in attacks compared to January and a 15.8% increase in attacks compared to February 2022. The LockBit 3.0 ransomware group was particularly active in February, posting more than twice the number of victims (129) on its leak site as January (50), accounting for virtually all of the monthly increase in attacks. ALPHV/BlackCat also listed more victims (30) on its data leak site than January (21), with Royal and BinLian in the third and fourth spots. Medusa completed the top 5. There was a 21% decrease in Royal ransomware victims compared to January, but a massive 400% increase in BianLian victims. According to the cybersecurity firm Redacted, the BianLian group appears to have changed tactics and is now increasingly monetizing its breaches without using file encryption and is concentrating on extortion after stealing data. While the healthcare industry is...



