Data Breaches Reported by CareFirst Administrators, Legacy Health & Blakehurst
CareFirst Administrators (CFA) has notified 14,538 individuals about a phishing attack on its revenue cycle management vendor, Conifer. CFA was one of several healthcare organizations to be affected by the incident. A security breach was identified by Conifer in late March, with the investigation determining several Microsoft 365 had been accessed by unauthorized individuals between March 17 and March 22, 2022. CFA was informed about the breach on June 23, 2022. One of the compromised email accounts was determined to contain the protected health information of CFA members, including names, addresses, birth dates, Social Security numbers, health insurance information, medical information, and billing and claims information. Conifer said it has implemented additional security measures to better protect its Microsoft 365 email environment to reduce the risk of further breaches. Legacy Health Identifies Insider Breach Legacy Health in Oregon has recently reported a breach of the protected health information of 7,983 patients. According to the substitute breach notice, the Privacy...
Telehealth Websites are Transmitting Sensitive Health Information to Big Tech Firms
The private information of visitors to telehealth websites is being shared with big tech companies without user consent due to the use of tracking code snippets on the websites, according to a recent analysis by The Markup. The websites of 50 direct-to-consumer telehealth companies were analyzed for the presence of third-party tracking code, 49 of which were found to have tracking code that transmitted the information of visitors to third parties, including Meta/Facebook and Google. The study follows on from an analysis of the websites of the top 100 hospitals in the United States in the summer, which revealed one-third were using tracking code on their websites that was sending data to third parties without consent, valid HIPAA authorizations, or business associate agreements. In a handful of cases, the tracking code was added behind password-protected patient portals. The latest study of telehealth websites included sites that collect highly sensitive information from visitors, such as the personal and health information of people suffering from Substance Use Disorder (SUD) who...
Sturdy Memorial Hospital & North Shore Pain Management Settle Data Breach Lawsuits
Two healthcare organizations in Massachusetts have chosen to settle class action lawsuits that were filed by patients whose protected health information was stolen in cyberattacks. Sturdy Memorial Hospital Sturdy Memorial Hospital in Attleboro, MA, has agreed to settle a lawsuit filed in response to a September 2021 ransomware attack, where the attackers gained access to the data of approximately 60,000 patients, such as names, addresses, dates of birth, Social Security numbers, financial information, and health information. The attackers exfiltrated patient data and threatened to release the information publicly. The hospital chose to pay the ransom. The lawsuit – Shedd, et al. v. Sturdy Memorial Hospital Inc. – alleged the hospital had maintained patient information in a reckless manner, as the information was stored on a system vulnerable to cyberattacks and the data was not encrypted. The lawsuit alleged the hospital did not follow Federal Trade Commission guidelines and violated Massachusetts laws by delaying sending notification letters to patients for almost 4...
Ransomware Gangs Adopt New Tactics to Attack Victims and Increase Likelihood of Payment
Ransomware remains one of the most serious threats to the healthcare industry. Attacks can be incredibly costly to resolve, they can cause considerable disruption to business operations, and can put patient safety at risk. Ransomware gangs are constantly changing their tactics, techniques, and procedures to gain initial access to networks, evade security solutions, and make recovery without paying the ransom more difficult, and with more victims refusing to pay the ransom demand, ransomware gangs have started to adopt increasingly aggressive tactics to pressure victims into paying up. Telemedicine Providers Targeted A variety of methods are used to gain access to healthcare networks, including remote access technologies such as VPNs and Remote Desktop Protocol (RDP) and exploiting unpatched vulnerabilities, with phishing a leading attack vector. One of the latest phishing tactics to be adopted is to target healthcare providers that offer telemedicine services, especially those offering consultations with patients over the Internet. One new tactic that has proven to be successful is...
HC3 Shares Analyses of LockBit 3.0 and BlackCat Ransomware
The Health Sector Cybersecurity Coordination Center (HC3) has released analyses of two ransomware variants that are being used in attacks on the healthcare sector: LockBit 3.0 and BlackCat. LockBit 3.0 LockBit ransomware was first detected in September 2019 when it was known as ABCD ransomware. Over the past three years, the ransomware has been continuously improved and updated, and it is now one of the most prolific ransomware families. In 2022, more attacks have been conducted using LockBit ransomware than any other ransomware variant. The cybercriminal group behind LockBit runs a highly professional ransomware-as-a-service (RaaS) operation with a strong affiliate program, which has helped the group stay ahead of its competitors. In a first for a ransomware operation, the release of LockBit 3.0 in June 2022 also saw the launch of a bug bounty program, where security researchers are encouraged to identify vulnerabilities to help the gang improve its operation, for which the group claims it will pay anywhere from $1,000 to $1 million. The ransomware has many anti-analysis features,...



