Email Breach at CSI Laboratories Impacts Almost 245,000 Patients
Cytometry Specialists, Inc., doing business as CSI Laboratories in Alpharetta, GA, has recently announced that the email account of an employee has been accessed by an unauthorized individual, who may have viewed or obtained the protected health information of 244,850 patients. CSI Laboratories is a leading cancer testing and diagnostics laboratory that serves pathologists, oncologists, and community hospitals throughout the U.S. The email account breach was detected on July 8, 2022, and the account was immediately secured. The investigation into the incident indicates the purpose of the attack was to use the email account in a business email compromise (BEC) attack to redirect CSI customer health care provider payments to an account under the control of the attacker by posing as CSI using a fictitious email address, rather than to obtain patient information; however, the breach investigation confirmed on July 15, 2022, that certain files had been copied from the employee’s mailbox that contained patient information. The files related to invoices sent to CSI Health Care provider...
PHI Exposed in Data Incidents at Anthem, WellMed Medical Management and CareOregon
Anthem has confirmed that the protected health information of certain plan members has been compromised in a data breach at its vendor, Choice Health. Choice Health was provided with the data of plan members to perform its contracted duties. On August 5, 2022, Anthem discovered that an unauthorized individual had gained access to a database and downloaded files containing plan members’ protected health information, including names, addresses, dates of birth, phone numbers, email addresses, Medicare ID numbers, and Medicaid ID numbers. The database was accessible over the Internet due to a misconfiguration by a third-party service provider and was accessed and downloaded on May 7, 2022. Choice Health confirmed that the database has now been secured and that steps have been taken to improve its data security measures to prevent similar incidents in the future, including implementing multi-factor authentication for access to database files. Affected individuals have been offered complimentary credit monitoring services. The breach affected several Choice Health clients,...
Netwalker Ransomware Affiliate Sentenced to 20 Years in Jail
An affiliate of the infamous Netwalker ransomware gang has been sentenced to serve 20 years in jail for his role in ransomware attacks on entities in the United States. Netwalker is a ransomware-as-a-service (RaaS) operation where affiliates are recruited to conduct attacks and deploy ransomware in exchange for a cut of the ransom payments they generate, typically receiving up to 75% of any ransoms paid. After gaining access to a victim’s network, sensitive data would be identified and exfiltrated and used as leverage to pressure victims into paying. Threats were then issued to publish or sell the data if the ransom is not paid. Ransom demands ranged from hundreds of thousands to millions of dollars. While some RaaS operations ban their affiliates from conducting attacks on healthcare organizations, that was not the case with Netwalker, which actively targeted healthcare organizations around the world. The gang also stepped up attacks on the sector during the COVID-19 pandemic. Victims included the Champaign-Urbana Public Health District and the University of California San...
Mon Health Faces Class Action Lawsuit Over 493K Record Data Breach
Mon Health is facing a class action lawsuit over a hacking incident that allowed unauthorized individuals to gain access to its network for an 11-day period in December 2021. Mon Health said it detected the breach on December 30, 2021, with the forensic investigation determining hackers accessed its network between December 9 and December 19. Mon Health announced the security breach on February 28, 2022, and confirmed that the hackers had access to the personal and protected health information of 492,861 individuals, including information about patients, employees, providers, and contractors. The information potentially accessed and stolen included names, addresses, birth dates, Social Security numbers, Medicare claim numbers, patient account numbers, health insurance information, medical record numbers, dates of service, provider names, claims information, and medical and clinical treatment information. The lawsuit, which names Monongalia Health Systems Inc. and affiliated hospitals, Monongalia County General Hospital Co., Stonewall Jackson Memorial Hospital Co., and Preston...
LifeBridge Health Agrees to $9.5 Million Settlement to Resolve 2016 Data Breach Claims
LifeBridge Health Inc. has agreed to settle a class action lawsuit to resolve claims from patients affected by a data breach that was discovered in 2018. The total value of the settlement is $9.475 million, which includes an $800,000 fund to cover claims from class members. In March 2018, LifeBridge Health discovered a malware infection that provided unauthorized individuals with access to a server that hosted its electronic medical records, patient registration, and billing systems. The breach investigation determined the initial intrusion occurred 18 months previously in September 2016. The breach was disclosed by LifeBridge Health in May 2018, with the healthcare provider confirming the information of 582,174 patients had potentially been compromised, with the exposed information including names, dates of birth, addresses, diagnoses, medications prescribed, clinical and treatment information, insurance details, and a limited number of Social Security numbers. A lawsuit – Johnson, et al. v. LifeBridge Health, Inc. – was filed in the Circuit Court for Baltimore City,...



