Utah Updates Data Breach Notification Requirements
Utah has updated its data breach regulations and from May 3, 2023, will require a breached entity to send a notification to the Utah Attorney General in the event of a breach of the personal information of 500 or more Utah residents. The new law applies to persons who own or license computerized data that includes the personal information of Utah residents. If a system security breach is discovered, a prompt investigation should be conducted to determine the likelihood that personal information has been or will be misused for identity theft or fraud. If it is determined that identity theft or fraud has occurred, or is likely to occur, notifications must be issued to each affected Utah resident and a notification must be sent to the Utah Attorney General and the newly created Utah Cyber Center. If the investigation determines that 1,000 or more individuals have experienced identity theft or fraud or are reasonably likely to experience fraud as a result of the security breach, then notifications must be provided to each national consumer reporting agency that maintains data on...
Healthcare Ransomware Attacks Threaten Up to 30% of Operating Income
Ransomware attacks increased by 91% in March 2023, according to a new analysis by NCC Group. There were 459 confirmed attacks in March which is a 62% increase from March last year. The massive increase was due to the zero-day vulnerability (CVE-2023-0669) in Fortra’s GoAnywhere MFT file management solution, which was exploited by the Clop ransomware group in 130 attacks on companies over a 10-day period. The Clop ransomware group explained that ransomware could have been deployed in those attacks; however, the decision was made to go extortion only. Even discounting those attacks since ransomware was not actually used, attacks are still occurring at a higher rate than in 2022. According to NCC Group, hacking and data leak incidents are also occurring at a much higher rate – more frequently than at any time in the past 3 years. ThreatConnect Quantifies the Cost of a Healthcare Ransomware Attack Ransomware attacks can be costly to resolve, especially for small organizations, but the true cost of the attacks is difficult to determine. IBM Security calculated the average cost of a data...
One-Fifth of Healthcare Organizations Do Not Enforce Cybersecurity Protocols
A recent Salesforce survey revealed some of the security gaps that exist in healthcare organizations, even those that have a security-first culture. The survey revealed only one-fifth of healthcare organizations enforce their cybersecurity protocols and only two-fifths of healthcare workers look at their security protocols before using new tools or technology. The Salesforce survey was conducted on April 13, 2023, on 400 healthcare workers in the United States who were asked questions about cybersecurity and policies and procedures at their organizations. 57% of surveyed workers said their job has become more digitized over the past two years, which means more data than ever now needs to be protected. There is a common myth that cybersecurity is the sole responsibility of the IT department; however, a majority of the respondents were aware that cybersecurity is a shared responsibility. 76% of healthcare respondents agreed that it is their responsibility to keep data safe, yet despite being aware of the need to protect data, many workers admitted to not always following...
One Brooklyn Health Notifies Patients About November 2022 Cyberattack
One Brooklyn Health System, which operates three hospitals in Brooklyn, NY, has started notifying patients affected by a November 19, 2022, cyberattack. One Brooklyn Health made a public announcement in late November confirming that it was dealing with a cyberattack, and said it had shut down IT systems to contain the incident and had launched an investigation into the breach. Those systems remained offline for more than a week. In late January, One Brooklyn Health confirmed that patient data had been compromised, and the attackers had access to information such as names, dates of birth, billing and claims data, treatment details, medical record numbers, prescriptions, health insurance information, and Social Security numbers. The review of the affected files was a time-consuming process, which took until March 21, 2023, to complete. Contact information then needed to be verified to allow breach notification letters to be mailed. One Brooklyn Health said it started mailing notification letters to affected patients on April 20, 2023. One Brooklyn Health said the investigation...
Major Massachusetts Health Insurer Suffers Ransomware Attack
Point32 Health, the second-largest health insurer in the state of Massachusetts, has announced it has experienced a ransomware attack that has resulted in system outages, including systems that are used to service its members, accounts, brokers, and providers. Point32 Health is the parent company of Tufts Health Plan and Harvard Pilgrim Health Care and serves more than 2 million individuals in New England. Point32 Health said the outages have mainly affected Harvard Pilgrim Health Care customers, in particular, those with commercial or New Hampshire Medicare plans. Tufts Health Plan members are not understood to have been affected. Point32 Health said it detected the presence of a malicious actor within its network on April 17, 2023, and took immediate action to contain the threat, which involved taking multiple systems offline while the attack was investigated and remediated. Efforts are underway to restore systems as soon as possible, and the staff and third-party cybersecurity experts are working around the close to bring systems back online. The attack has caused disruption to...



