Data Breaches Reported by Neurology and Fertility Centers in Nevada and California
Neurology Center of Nevada Cyberattack Impacts 11,700 Patients The Neurology Center of Nevada (NCNV), in Henderson, NV, has confirmed a data security event was detected on July 17, 2022, which rendered certain computer systems inaccessible. Prompt action was taken to secure its systems and an investigation was launched to determine the nature and scope of the security breach, with assistance provided by third-party cybersecurity experts. The investigation confirmed that the threat actors behind the attack had access to its systems for more than a month between June 12, 2022, and July 17, 2022, and during that time, files on its systems were subjected to unauthorized access. The compromised files contained full names, addresses, dates of birth, gender, driver’s license numbers, Social Security numbers, health insurance information, and medical information, such as diagnosis/treatment information, lab results, and medications. Affected individuals have been notified by mail and advised to monitor their accounts, credit reports, and explanation of benefits statements for unusual...
HHS Urged to Extend Deadline for Compliance with Cures Act Information Blocking Requirements
The deadline for compliance with the information blocking requirements of the 21st Century Cures Act is October 6, 2022, after which the HHS can impose financial penalties and healthcare providers will be subject to appropriate disincentives if they are determined to have failed to facilitate the easy digital sharing of patient data. Information blocking is defined as any practice by an entity that is likely to interfere with the access, exchange, or use of electronic health information that is not covered by eight exceptions. These new requirements were introduced pursuant to the 21st Century Cures Act to improve patient access to their medical records. From October 6, 2022, healthcare providers are required to start sharing the data of patients contained in a designated record set, as defined under HIPAA. Previously the data sharing mandates only required information to be shared that is contained in the USCDI. Last week, 10 healthcare groups wrote to HHS Secretary, Xavier Becerra, to express their concern about the fast-approaching deadline. They explain that despite the best...
Cybersecurity Awareness Month Focuses on 4 Key Behaviors
October is Cybersecurity Awareness Month – a 19-year collaborative effort between the government and industry to improve awareness of cybersecurity in the United States, led by the Cybersecurity and Infrastructure Security Agency (CISA) and the National Cybersecurity Alliance (NCA). 2022 Cybersecurity Awareness Month – See Yourself in Cyber The theme of this year’s Cybersecurity Awareness Month is See Yourself in Cyber, where the focus is on the actions that everyone should take to improve cybersecurity. In previous years, the month of October has been divided into four weeks, each of which has a different theme. This year, rather than have a different weekly theme, the focus each week will be on one of four key behaviors that everyone should adopt. Simply practicing these basics of cybersecurity will greatly improve an individual’s and an organization’s security posture. Enabling multifactor authentication – Improve access controls by adding additional authentication requirements in addition to a password. MFA can prevent access from being granted to accounts using stolen...
Zero Day Microsoft Exchange Server Vulnerabilities Being Actively Exploited
Microsoft was warned that two zero-day vulnerabilities in Microsoft Exchange Server are being actively exploited in the wild and has shared mitigations ahead of the vulnerabilities being patched. The two flaws are being chained together and are being exploited by a Chinese threat actor. The attacks have been limited so far, but the healthcare and public health sector in the United States could potentially be a target. The flaws affect Microsoft Exchange Server 2013, 2016, and 2019. CVE-2022-41040 is a Server-Side Request Forgery (SSRF) vulnerability that can be exploited for initial access, after which the second vulnerability can be exploited – A Remote Code Execution vulnerability thacked as CVE-2022-41082. The second vulnerability can only be exploited if PowerShell is available to the attacker. Microsoft has confirmed that the flaws cannot be exploited by an unauthenticated attacker. Both vulnerabilities require authenticated access to a vulnerable Microsoft Exchange Server to be exploited, such as if an attacker had valid stolen credentials. The first vulnerability has been...
More Than 233,000 Patients Affected by Cyberattack on FMC Services
FMC (Family Medicine Centers) Services, an Amarillo, TX-based network of primary care clinics in Amarillo and Canyon, has recently announced it was the victim of a hacking incident that was detected and blocked on July 26, 2022. A forensic investigation was conducted by a third-party cybersecurity firm to determine the nature and scope of the attack. That investigation did not uncover any evidence to suggest the cyberattack was conducted with a view to misusing patient information; however, files containing patients’ protected health information were exposed and may have been viewed. FMC Services said that at the time of issuing notifications to affected individuals, it had not been made aware of any cases of identity theft or other misuses as a result of the incident. A comprehensive review of the exposed files confirmed they contained information such as names, mailing addresses, birth dates, and Social Security numbers, and potentially other types of protected health information. Affected individuals have been offered a complimentary membership to an identity theft monitoring...



