Nurse Sentenced to 37 Months in Jail for Tampering with and Stealing Medications
A former nurse employed by the Roswell Park Comprehensive Cancer Center in Buffalo, NY, has been sentenced to 37 months in prison for tampering with and stealing controlled medications intended for cancer patients. Kelsey A. Mulvey, 30, of Grand Island, NY, worked as a registered nurse at Roswell Park between February 2018 and June 2018. On June 27, 2018, Mulvey was observed accessing a medication dispensing machine in a room to which she was not assigned and left carrying a backpack. She was placed on administrative leave pending an investigation and later resigned. The investigation concluded Mulvey had stolen hydromorphone, methadone, oxycodone, and lorazepam from the automated medication dispensing systems. In June and July 2018, six patients at Roswell Park became ill with waterborne infections. The investigation concluded that Mulvey had replaced the hydromorphone in the vials with water to hide the theft. Roswell Park has a zero-tolerance policy and immediately notified the New York State Department of Health, the NYS Department of Education, the Bureau of Narcotics and...
Up to 254,000 Medicare Beneficiaries Affected by Ransomware Attack on CMS Subcontractor
On November 14, 2022, Fairmont, WV-based Health Care Management Solutions (HMS) reported a data breach to the HHS’ Office for Civil Rights that affected up to 500,000 individuals. At the time, few details about the breach were released. It has now been confirmed that HMS suffered a ransomware attack on October 8, 2022. HMS is a subcontractor of ASRC Federal Data Solutions, LLC (ASRC Federal), which is a business associate of the HHS’ Centers for Medicare and Medicaid Services (CMS). The services provided include resolving system errors related to beneficiary entitlement and premium payment records, as well as supporting the collection of Medicare premiums from the direct-paying beneficiary population. The CMS said the HMS does not handle Medicare claims information so no claims data was affected and CMS systems were not breached; however, the cybercriminals behind the attack may have accessed Medicare beneficiaries’ personally identifiable information (PII) and/or protected health information (PHI). The CMS says up to 254,000 Medicare beneficiaries have potentially been affected...
OCR Fines California Dental Practice for PHI Disclosures on Yelp
The HHS’ Office for Civil Rights (OCR) has announced a settlement has been reached with a Californian dental practice to resolve multiple HIPAA violations that were identified during investigations of a complaint about impermissible disclosures of protected health information on the review platform Yelp. New Vision Dental is a Californian general dental practice with offices in South Pasadena and Glendora. On November 29, 2017, OCR received a complaint alleging Dr. Brandon Au, owner and CEO of New Vision Dental, had posted responses to several reviews by patients on Yelp and frequently disclosed protected health information in the responses. In some of the posts, patients were identified and their full names were disclosed, when they had chosen to only use a moniker on the platform. Other information allegedly posted by Dr. Au included detailed information about the patients’ visits, treatment, and insurance, when that information had not been posted publicly by the patients. The investigation into the impermissible disclosures also included an on-site visit to New Vision Dental....
Automation Can Help Network Defenders Achieve More in Less Time and Stay One Step Ahead of Hackers
Automation cuts costs and improves productivity, and it is as important in cybersecurity as it is in manufacturing. Many labor-intensive security tasks can be automated to allow network defenders to do more in less time, including monitoring, port scanning, vulnerability scanning, and patching. There is a wide range of security tools that can be used to automate tasks to allow security teams to identify and address vulnerabilities more quickly and rapidly detect intrusions and investigate suspicious activity. Many security tools have been created for blue team use that can save a considerable amount of time. For example, tools are available that can scan for vulnerabilities, automate mitigation, and make suggestions about recommended actions. Manually performing these tasks is time-consuming and extends the window of opportunity for hackers to exploit the flaws. A great deal of threat intelligence is available to network defenders – far too much to sift through manually. Cyber intelligence tools automate the process of checking threat intelligence and can filter out...
Data Breaches Reported by CareFirst Administrators, Legacy Health & Blakehurst
CareFirst Administrators (CFA) has notified 14,538 individuals about a phishing attack on its revenue cycle management vendor, Conifer. CFA was one of several healthcare organizations to be affected by the incident. A security breach was identified by Conifer in late March, with the investigation determining several Microsoft 365 had been accessed by unauthorized individuals between March 17 and March 22, 2022. CFA was informed about the breach on June 23, 2022. One of the compromised email accounts was determined to contain the protected health information of CFA members, including names, addresses, birth dates, Social Security numbers, health insurance information, medical information, and billing and claims information. Conifer said it has implemented additional security measures to better protect its Microsoft 365 email environment to reduce the risk of further breaches. Legacy Health Identifies Insider Breach Legacy Health in Oregon has recently reported a breach of the protected health information of 7,983 patients. According to the substitute breach notice, the Privacy...



