Lawsuit Seeks Damages for GoodRx Users for Invasion of Privacy
Last week, the Federal Trade Commission (FTC) announced its first-ever financial penalty for a violation of the FTC Health Breach Notification Rule. GoodRx was alleged to have failed to issue notification letters to customers whose PHI was disclosed to third parties such as Google and Facebook via tracking technologies on its website and mobile app. GoodRx said it decided to settle the case and pay a $1.5 million financial penalty to avoid the time and expense of protracted litigation, and that proactive steps were taken to address the issue prior to the FTC investigation. The settlement has yet to be approved by a federal judge. Several healthcare data breaches have been reported over the past few months that involved impermissible disclosures of protected health information to third parties such as Google, Meta, and others due to the use of tracking technologies on websites and mobile apps. Multiple lawsuits have been filed over those impermissible disclosures, and the GoodRx data breach is no exception. A lawsuit was filed in the U.S. District Court of the Northern District of...
Regal Medical Group Ransomware Attack Affects 3.3 Million Patients
Regal Medical Group, a San Bernardino, CA-based affiliate of the Heritage Provider Network, recently announced that it was attacked with ransomware. On December 2, 2022, employees experienced difficulty accessing data. Third-party cybersecurity experts were engaged to investigate the attack and assist with the HIPAA breach response and confirmed that malware had been used to encrypt files on some of its servers. The forensic investigation confirmed that the attackers gained access to the email servers on or around December 1 and exfiltrated files before the ransomware was deployed. The review of those files confirmed they contained the protected health information of patients of Regal Medical Group, Lakeside Medical Organization, ADOC Medical Group, and Greater Covina Medical. The files contained information such as names, phone numbers, addresses, dates of birth, diagnosis and treatment information, laboratory test results, prescription data, radiology reports, health plan member numbers, and Social Security numbers. Regal Medical Group said additional security measures have been...
Highmark Health Phishing Attack Affects 275,000 Patients
Pittsburg, PA-based Highmark Health, the second largest integrated delivery and financing system in the U.S., has recently announced that an unauthorized individual has accessed the email account of one of its employees following a response to a phishing email. After the employee clicked the link in the email and disclosed their credentials, the account was accessed remotely by an unauthorized third party who potentially viewed and exfiltrated emails and attachments from the account. The unauthorized account activity was detected by Highmark Health on December 15, 2022, with the initial compromise occurring on December 13, 2022. A review of the emails and attachments revealed they contained the protected health information of health plan members, such as group name, identification numbers, claim numbers, dates of service, procedures, prescription information, addresses, phone numbers, email addresses, and financial information. The Social Security numbers of a subset of individuals were also exposed. When the breach was detected, the affected mailbox was immediately deactivated,...
Tallahassee Memorial HealthCare Diverts Ambulances Due to Cyberattack
Last Thursday, Tallahassee Memorial HealthCare (TMH) in Florida was forced to take its IT systems online, divert ambulances, and suspend all non-emergency medical procedures due to a cyberattack. The hospital issued a statement confirming that it would only be accepting patients with Level 1 traumas from its immediate service area while the cyberattack is investigated and systems are restored. The hospital said the attack only affected specific systems, but other, unaffected systems were taken offline to contain the attack. Systems are being prioritized and will be brought back online one by one when it is safe to do so. On Thursday, the hospital could not provide any information on the likely timeframe for recovery but said updates will continue to be provided on its website. On Sunday, a statement was issued confirming progress is being made restoring systems, that TMH Physician Partners are still operational, and they will start seeing patients as scheduled from Monday, February 6, 2023; however, all non-emergency surgeries and outpatient procedures scheduled for Monday had been...
Banner Health Settles Alleged HIPAA Security Rule Violations for $1.25 Million
The HHS’ Office for Civil Rights has announced its second financial penalty of 2023 to resolve alleged violations of the Health Insurance Portability and Accountability Act (HIPAA). Banner Health has agreed to pay a financial penalty of $1,250,000 and adopt a corrective action plan to resolve the alleged HIPAA Security Rule violations. Phoenix, AZ-based Banner Health is one of the largest non-profit health systems in the United States. The health system includes 30 hospitals and more than 69 affiliated healthcare facilities in 6 U.S. states and employs more than 50,000 individuals. On July 13, 2016, Banner Health detected a security breach, with the subsequent investigation confirming hackers gained access to its systems on June 17, 2016. The hackers were able to access systems containing the protected health information (PHI) of 2.81 million individuals, including names, addresses, dates of birth, Social Security numbers, claims information, lab results, medications, diagnoses, and health insurance information. After being informed about the impermissible disclosure of PHI, OCR...



