VisionWeb Data Breach Affects Up to 35,900 Individuals
Austin, TX-based VisionWeb Holdings, a provider of Internet-delivered software solutions for the eye care industry for improving practice efficiency, has recently reported a data breach to the HHS’ Office for Civil Rights that has affected up to 35,900 patients. According to the breach report sent to the HHS on October 3, 2022, unauthorized individuals gained access to its email environment which contained patient information. The breach was also reported to the Texas Attorney General, with that report stating that names, Social Security numbers, government-issued identification numbers, medical information, and health insurance information had potentially been compromised. Individual notifications started to be sent to affected individuals on October 3, 2022, along with information on the steps they can take to protect against identity theft and fraud. This post will be updated when further information about the breach becomes available. Eventus WholeHealth Announces Email Account Breach Durham, NC-based Eventus WholeHealth has recently confirmed that the email account of an...
Radiology Associates of Albuquerque Notifies Patients About Security Breach That Started in December 2020
Radiology Associates of Albuquerque (aka RAA Imaging/Advanced Imaging, LLC) has recently notified patients that some of their protected health information was stolen in a cyberattack that was detected more than 12 months previously. RAA said suspicious activity was detected within its environment in August 2021. Prompt action was taken to secure its systems and prevent further unauthorized access, and an investigation was launched to determine the nature and scope of the incident. The forensic investigation confirmed that unauthorized individuals had access to certain systems between July 22, 2021, and August 3, 2021, and copied files from its network that contained patient data. The investigation also uncovered unauthorized access to email accounts, with the email accounts accessed by unauthorized individuals at various points over the preceding 8 months, between December 22, 2020, and July 15, 2021. RAA explained in a substitute breach notice on its website that the delay in issuing notifications was due to the time taken to investigate the incident. RAA said the review and...
70,000 Valle del Sol Community Health Patients Affected by Cyberattack
Phoenix, AZ-based Valle del Sol Community Health has notified 70,268 patients that some of their protected health information has been exposed. Valle de Sol did not state in its notification letters when hackers gained access to its network, or for how long they had access, but did confirm that the unauthorized activity was detected on January 25, 2022. Valle del Sol immediately took steps to secure its network and prevent further unauthorized access and engaged an independent cybersecurity firm to investigate the breach to determine if patient data had been accessed. Valle de Sol said the investigation indicated unauthorized individuals had access to files containing sensitive patient data and that patient information may have been acquired. A comprehensive review was conducted of all files that may have been accessed, which was completed on July 18, 2022. The delay in sending notification letters was due to the length of the investigation, then having to verify up-to-date contact information. The verification of addresses concluded on September 1, 2022. Valle de Sol explained in...
What Federal Department Regulates HIPAA?
Healthcare providers, health plans, healthcare clearinghouses, and business associates of those organizations must comply with the Health Insurance Portability and Accountability Act (HIPAA), but what federal department regulates HIPAA and takes action against organizations that fail to comply with HIPAA Rules? What Federal Department Regulates HIPAA? HIPAA is regulated by the Department of Health and Human Services’ Office for Civil Rights (OCR). Since the introduction of the HIPAA Enforcement Rule in March 2006, OCR was given the power to investigate complaints about HIPAA violations. OCR was also given the right to issue civil monetary penalties if HIPAA-covered entities were found to have violated HIPAA Rules. While OCR had the power to issue financial penalties, it is relatively rare for HIPAA violations to result in financial penalties. Over the years since the Enforcement Rule was passed, OCR has steadily increased enforcement of HIPAA Rules, although it has only been in the past four years that financial penalties for HIPAA violations have become more common. Since the...
Study Suggests Businesses Are Not Prepared for the Escalation in Cyberattacks
Businesses are appreciating the importance of cybersecurity and realizing that they need to invest more heavily in cybersecurity as threats are evolving at such a rapid pace. The challenge for businesses is ensuring that their defenses allow them to stay one step ahead of cybercriminals, but the frequency at which data breaches are being reported suggests many businesses are struggling to keep up the pace. In order to understand how to keep their businesses secure, IT leaders need to know how cybercriminals are bypassing defenses. They can then make informed decisions about the security solutions they need to invest in that will give them the best ROI in terms of security. Keeper Security recently conducted a survey to explore how cybersecurity is transforming and where businesses are investing in cybersecurity tools. The survey was conducted on 516 IT decision-makers in the United States and the findings were published in Keeper’s 2022 U.S. Cybersecurity Census Report. The report delves into the threats that businesses face and the strategies that can be adopted by businesses to...



