San Andreas Regional Center Agrees to Settle 2021 Ransomware Attack Lawsuit
San Andreas Regional Center has agreed to settle a class action lawsuit that was filed in response to a July 2021 ransomware attack in which hackers gained access to the personal information of more than 57,000 patients The San Jose, CA-based healthcare provider supports individuals with developmental disabilities through its facilities in the Santa Clara, Santa Cruz, San Benito, and Monterey counties. The ransomware attack occurred on or around July 5, 2021, and prior to encrypting files, the threat actor potentially accessed and exfiltrated sensitive patient data such as names, addresses, dates of birth, telephone numbers, Social Security numbers, email addresses, health plan beneficiary numbers, health insurance information, full-face photos, and medical information. Affected individuals were notified about the cyberattack in August 2021 and were offered complimentary credit monitoring and identity theft protection services. A lawsuit – Lopez, et al. v. San Andreas Regional Center – was filed in the Superior Court of California in response to the breach alleging the...
Pro-Russian Hacking Group Conducting DDoS Attacks on U.S. Hospitals
The pro-Russian hacking group, Killnet, is conducting a campaign of Distributed Denial of Service (DDoS) attacks on U.S. hospitals in apparent retaliation for U.S. support of Ukraine. The attacks started a few days after the United States and other countries agreed to provide tanks to Ukraine to help with the fight against the Russian invasion. Killnet is a hacktivist group that has been active since at least January 2022 and its activities are connected to the Russian invasion of Ukraine. While the group’s views align with Russia, connections to the Russian Federal Security Service (FSB) and Russian Foreign Intelligence Service (SVR) have not been confirmed. The group is known for conducting denial of service (DoS) and DDoS attacks on government institutions and private organizations in countries providing support to Ukraine. The attacks involve flooding hospital servers and websites with thousands of connection requests and packets per minute, causing the systems to slow down. In some cases, the attacks have rendered servers and websites temporarily unavailable. DDoS attacks are...
Katherine Shaw Bethea Hospital Proposes $380K Settlement to Resolve Data Breach Lawsuit
Katherine Shaw Bethea (KSB) Hospital in Dixon, IL, has proposed a $380,000 settlement to resolve claims related to a September 2021 data breach at a business associate of the hospital. KSB Hospital used the Scottsbluff, NE-based healthcare accounts receivables service provider, Magnet Solutions, for billing-related services. Between September 17 and September 20, 2021, Magnet Solutions processed and mailed billing statements to KSB patients; however, a software error caused statements to be mailed to incorrect individuals. The statements included names, encounter numbers, names of treating physicians, dates of service, and locations of service. According to the breach notice submitted to the HHS’ Office for Civil Rights, the breach affected 1,553 individuals, who were notified about the breach by Magnet Solutions in November 2021. Complimentary credit monitoring and identity theft protection services were offered to affected individuals. A lawsuit – John Doe, et al. v. Katherine Shaw Bethea Hospital, et al – was filed in response to the breach. The plaintiff alleged that his...
Multiple Vulnerabilities Identified in OpenEMR Health Record and Practice Management Software
Multiple vulnerabilities have been identified in the popular open source electronic health record and medical practice management software, OpenEMR. OpenEMR is used by healthcare organizations around the world for recording and managing sensitive patient data, and patients used the software for scheduling appointments online, communicating with their healthcare providers, and paying medical bills. OpenEMR is used by more than 100,000 healthcare providers worldwide that serve more than 200 million patients. Three vulnerabilities were discovered last year by security researcher Dennis Brinkrolf. Brinkrolf analyzed the open source code using Sonar’s static application security testing (SAST) engine. Three vulnerabilities were identified that could be chained together to achieve remote code execution, take control of vulnerable OpenEMR instances, and steal sensitive patient data. The first vulnerability – an unauthenticated file read vulnerability – could be exploited by a malicious actor using a rogue MySQL server to read arbitrary files in OpenEMR systems. Those files contain...
How Long is PHI Protected after Death?
The question of how long is PHI protected after death is often answered with “fifty years”, but that answer refers to how long is PHI protected after death by HIPAA – and, even in this context, “fifty years” is not necessarily the correct answer. The HIPAA Privacy Rule places a limit of fifty years on how long covered entities have to protect the privacy of individually identifiable health information after an individual`s death. The time period was chosen to balance the privacy interests of surviving relatives and the demands of archivists, biographers, and other interested parties who wish to access records of deceased individuals for historical purposes. During the fifty years following an individual’s death, the same protections must be applied to the deceased individual`s Protected Health Information (PHI) as if the individual were still alive. Additionally, during this period, the decedent’s personal representatives have the right to request copies of the decedent’s PHI and authorize uses and disclosures of the decedent’s PHI not otherwise required or permitted by the HIPAA...



