Hive RaaS Gang Leaks Stolen Consulate Health Care Data
The Hive ransomware-as-a-service (RaasS) operation has claimed responsibility for an attack on Consulate Health Care, a Florida-based chain of 140 U.S. nursing homes. The group claims to have stolen 550 GB of data in the attack and said files were encrypted on December 3, 2022. The group posted on its leak site about the breach on January 6, 2023, and has already leaked some of the data allegedly stolen in the attack. The information stolen in the attack allegedly includes contracts, company information, employee information, and patient information such as medical records, Social Security numbers, contact information, and insurance information. Consulate Health Care published a substitute breach notice on its website around the same time as Hive went public about the attack. In the website breach notice, Consulate Health Care claims the attack occurred at one of its (unnamed) vendors, which is still investigating the incident to determine the extent of the breach. Consulate Health Care said it is working closely with its vendor and has confirmed that the investigation is...
Captify Health Suffers 3-Year Breach of its Your Patient Advisor Website
Captify Health has recently started notifying users of its Your Patient Advisor online service that their sensitive information has been exposed and obtained by unauthorized individuals. In some cases, credit card information was stolen and misused. Captify Health prepares patients for their colonoscopy procedures by providing the colonoscopy preparation products recommended by doctors through its Your Patient Advisor service. As an online retailer, Captify Health collects customer information and processes debit/credit card payments through the website. An external investigation into credit card fraud pointed to Captify Health as the source of a data breach. Captify Health was informed in March 2021 about the potential breach and conducted an internal investigation, with assistance provided by a third-party digital forensics firm. Malicious code was identified on the website which was transmitting the data of its customers to a third-party server. That information included full names, addresses, birth dates, payment card numbers, expiration dates, and security codes. The forensic...
Email Account Breaches Reported by Legacy Hospice, Live Oak Surgery Center, University of Miami Health
Email accounts have been compromised at Legacy Hospice and Live Oak Surgery Center, and a University of Miami Health employee’s personal data breach also saw their work email account compromised, highlighting the risks of employees storing their work login credentials on personal devices. Legacy Hospice Email Account Breach Affects 21,000 Patients Legacy Operating Company, an Alabama-based operator of Legacy Hospice facilities in Alabama, Arkansas, Louisiana, Mississippi, Missouri, Oklahoma, and Tennessee, has confirmed that an unauthorized third party gained access to a limited number of employee email accounts on February 11, 2022, and between April 7, 2022, and April 21, 2022. Third-party cybersecurity professionals were engaged to investigate the breach, with the investigation concluding on November 7, 2022, that protected health information was present in the compromised email accounts and may have been accessed or obtained. The breached information included names in combination with one or more of the following types of data: Social Security numbers, taxpayer identification...
Ransomware Attacks Announced by Maternal & Family Health Services and Retreat Behavioral Health
Maternal & Family Health Services in Eastern Pennsylvania has recently notified certain patients about an April 4, 2022, ransomware attack in which sensitive patient data was exposed. When the attack was detected, systems were secured, and a third-party computer forensics firm was engaged to investigate and determine the nature and scope of the breach. The investigation confirmed that its systems were first accessed by the attackers on August 12, 2021, almost 8 months before ransomware was used to encrypt files. Its systems were secured on April 4, 2022, with the investigation, review of affected files, and the verification of contact information lasting until the end of the year. Notifications were sent to affected individuals on January 3, 2023. Maternal & Family Health Services said the compromised files included information such as names, addresses, dates of birth, Social Security numbers, driver’s license numbers, financial account/payment card information, usernames, passwords, medical information, and health insurance information. Complimentary credit monitoring and...
Interview: Natalie Birindelli, Healthcare Engagement Advisor, Amazon Web Services
Natalie Birindelli, Healthcare Engagement Advisor at Amazon Web Services has shared her thoughts on HIPAA and how the legislation relates to her role and her career. Tell the readers about your career in the healthcare industry Experienced Healthcare Cybersecurity/Information Technology Leader with over 20 years in the hospital & healthcare industry. Skilled in Telehealth, Cybersecurity, Cloud Infrastructure, Communications, Education and Awareness, Program and Healthcare Management, Privacy with an innovative approach to implementing complex technical solutions. What was your first position? Medical Assistant/Billing Specialist at Elite OB-Gyn/Genetics Consultants of VA and MDElite OB-Gyn/Genetics Consultants of VA and MD for 6 years. Then worked at McLean, VAMcLean, VA, where I assisted a team of physicians with all aspects of patient care for multi-facilities including processing and submitting referrals, insurance claims and consultation letters, reconciling medical billing and follow through with insurance carriers, and I implemented the 1st EHR, Medisoft software, and...



