Round Up of Recent Hacking Incidents and Email Account Breaches
West Oaks Eyecare – Ransomware Attack West Oaks Eyecare in Texas has notified 1,045 Texas residents that a malicious actor gained access to its network and installed malware that rendered files inaccessible. The attack was detected on November 7, 2022, and steps were taken to contain the attack and secure its systems. The affected system contained billing information that was potentially accessed and obtained in the attack. The files included patients’ names along with one or more of the following types of information: address, date of birth, email address, phone number, patient ID number, Social Security number, optical scan images, exam results, insurance information, and billing information. Notification letters were mailed to affected individuals on January 6, 2022. Complimentary credit monitoring and identity protection services have been offered to individuals whose Social Security numbers were involved. The Kelberman Center – Email Account Breach The Kelberman Center, a Utica, NY-based provider of services to individuals with autism, has notified 3,501 patients about a...
Password Management Howlers Identified at U.S. Department of the Interior
The Office of Inspector General of the U.S. Department of the Interior (DOI OIG) has identified bad password management and enforcement practices at the Department of the Interior that are placing critical IT systems at risk. These basic password errors are all too common in the healthcare industry and make it far too easy for malicious actors to gain initial access to networks for ransomware attacks and other nefarious purposes. An inspection was conducted of the password complexity requirements of the department to determine if its password management and enforcement controls were effective and would likely prevent malicious actors from using brute force tactics to gain unauthorized access to accounts. The DOI OIG identified several password management weaknesses and many weak passwords. 4.75% of accounts were secured using variants of ‘password’, which could be cracked instantly by a malicious actor. Password-1234 was being used to protect 478 unique, unrelated accounts, with 5 of the 10 most reused passwords including the word password and the number sequence 1234....
Leading Healthcare CISOs Join Forces to Solve Third Party Risk Management Challenges
A group of 20 security and risk executives from leading healthcare provider organizations have come together to share their insights and guidance with less well-resourced healthcare organizations to improve information risk management in the healthcare industry, including addressing one of the most urgent healthcare cybersecurity challenges – third-party risk management. Cyberattacks on vendors have increased sharply with these attacks impacting many healthcare organizations. In 2023, virtually all of the top ten data breaches occurred at vendors. An attack on a vendor can give a threat actor access to the networks and data of many different healthcare organizations, and many vendors have insufficient security measures in place. A recent survey conducted for the Healthcare and Public Health Sector Coordinating Councils (HSCC) found that healthcare organizations of all sizes are struggling to manage third-party risks, especially small- and medium-sized healthcare organizations, which typically have limited budgets and resources to devote to third-party risk management. The HSCC...
Interview: John Jessop, Sr. Director, HIPAA Security & Regulatory Compliance, PPFA
HIPAA Journal is conducting interviews with healthcare professionals and service providers to find out more about their compliance journeys, how the HIPAA Rules have affected their working lives, and the successes and challenges they have faced with HIPAA compliance. John Jessop, MHA, CISSP, CHPS, HCISPP, CISA, CMPE, Sr. Director, HIPAA Security & Regulatory Compliance, PPFA has shared his thoughts. Tell the readers about your career in the healthcare industry I started my healthcare career as a lab tech back in 1982. Since then I received a Masters in Healthcare Administration from Baylor University, have worked in hospitals in a variety of roles from Facilities Management and Safety Management to Family Medicine Residency Program Administrator to VP of Physician Services, managed a number of physician practices, functioned as a healthcare software salesperson, worked as a consultant, was a VP of IT, and finally ended up as a Senior Director, HIPAA Security and Regulatory Compliance for a national corporation. What was your first position? My first position in healthcare was...
Consolidated Class Action Lawsuit Filed Against Shields Health Care Group Over 2 Million-Record Data Breach
Multiple lawsuits have been filed against Massachusetts-based Shields Health Care Group, which suffered one of the largest healthcare data breaches of the year, affecting more than 2 million individuals. Seven of the lawsuits have recently been consolidated into a single lawsuit – Biscan v. Shields Health Care Group Inc. – that was filed in a Massachusetts federal court this week. The lawsuit covers all individuals affected by the data breach who did not live in Massachusetts at the time of the breach. A second lawsuit has been filed in state court that covers Massachusetts residents. Shields Health Care Group provides MRI, PET/CT, radiation oncology, and surgical services to healthcare practices, around 60 of which were affected by the breach. Hackers gained access to its network and stole the protected health information of patients over a two-week period in March 2022. The stolen data included names, contact information, Social Security numbers, insurance information, billing information, and clinical information such as diagnoses and treatment information. Affected...



