34K-Record Data Breach Reported by Aesthetic Dermatology Associates
Pennsylvania-based Aesthetic Dermatology Associates has recently confirmed that its network has been accessed by unauthorized individuals who potentially viewed and/or acquired files containing the personal and protected health information of 33,793 current and former patients. The cyberattack was detected on August 15, 2022, when suspicious activity was detected within its network. An investigation was launched to determine the nature and scope of the attack, which confirmed that unauthorized individuals had accessed its network, although the nature of the attack and length of time its network was compromised were not disclosed. A comprehensive review of all files on the compromised parts of the network was completed on September 3, 2022, and confirmed the breach was limited to names, addresses, dates of birth, diagnosis codes, and health insurance information. Aesthetic Dermatology said a review is being conducted of its policies, procedures, and controls and updates will be made, as appropriate, to improve security. At the time of issuing notifications, no reports had been...
Email Breaches Reported by Cardiac Imaging Associates & Centerstone of Tennessee
Cardiac Imaging Associates in Los Angeles, CA, has discovered an unauthorized individual has accessed an employee’s email account. The incident was detected in April 2022, and immediate action was taken to secure its email environment to prevent further unauthorized access. The forensic investigation confirmed the incident was confined to a single employee email account, which was accessed between March 30, 2022, and April 6, 2022. It was not possible to determine if any emails or file attachments were opened or acquired by the attacker. A review of all emails and file attachments confirmed they contained protected health information such as names, dates of birth, Social Security numbers, driver’s license numbers, financial account information, payment card information, medical diagnosis, and condition information, medical laboratory results information, medication and prescription information, and medical treatment information. The review of emails was completed on August 17, 2022, and notification letters started to be sent to affected patients on October 7, 2022. Steps...
Doctor Pleads Guilty to Criminal Violations of HIPAA for Providing PHI to Pharma Sales Rep
A former physician with practices in New Jersey, New York, and Florida has pleaded guilty to criminal violations of HIPAA for disclosing patients’ protected health information to a sales representative of a pharmaceutical firm, according to the U.S. Attorney’s Office of the District of New Jersey. The Frank Alario, 65, of Delray Beach, Florida, pleaded guilty to disclosing patient information to sales rep, Keith Ritson, who promoted compound prescription medications and other medications to the patients. Compound prescription medications are medications mixed specifically for individual patients when standard FDA-approved medications are determined to not be appropriate, due to an allergy for example. Compound prescription medications are not approved by the FDA but can be legally prescribed by physicians. The HIPAA Privacy Rule permits disclosures of patients’ protected health information for the purposes of treatment, payment, or healthcare operations; however, other disclosures are only permitted if consent to share information is provided by each patient. Ritson was an outside...
HHS Warns HPH Sector About Abuse of Legitimate Software and Security Tools by Threat Actors
It has become increasingly common for threat actors to use living-off-the-land techniques for conducting reconnaissance, privilege escalation, persistence, and moving laterally within networks undetected. The same software and security tools used by network administrators and red team professionals for legitimate purposes are abused and used to conduct attacks on victims’ infrastructure. Threat actors leverage software tools that have already been installed to avoid having to download files via the Internet, malicious activities can be hidden within the logs along site legitimate use of these tools, and these tools are used to conduct malicious activities in the memory to evade security solutions. Traditional approaches to security such as blocking hashes of malicious files and malicious domains are ineffective against these tools, as they are already installed on the network. Recently, the Health Sector Cybersecurity Coordination Center (HC3) issued a white paper warning the healthcare and public health sector (HPH) about these living-off-the-land techniques to raise...
Wisconsin Department of Health Services Reports Breach of 12,000 Records
A round-up of healthcare data breaches that have recently been reported to the HHS’ Office for Civil Rights, state attorneys general, and the media. Wisconsin Department of Health Services: Accidental Disclosure of PHI via Email The Wisconsin Department of Health Services (DHS) has recently confirmed that there has been an accidental disclosure of protected health information via email. According to the breach notice, a presentation was emailed to the DHS Children’s Long-Term Support Council in April 2021 that contained protected health information. The presentation was then forwarded by the Council to employees working for certain county government agencies and the presentation was posted to the DHS website as part of the meeting minutes. The error was detected on August 8, 2022, and the file was removed from the meeting minutes and replaced with a file that did not provide access to PHI. Steps were also taken to recover all distributed copies of the presentation. The presentation contained the following types of information: first and last names, date of birth, gender, county...



