Source Code Stolen in LastPass Data Breach
A cyberattack and data breach has been reported by LastPass, the provider of the world’s most popular password management solution. According to LastPass, there are around 30 million users of its password manager solution globally, including 85,000 business customers. Notifications have been sent to customers to inform them about the cyberattack and provide reassurances that while some company data was stolen in the attack, users’ password vaults were not affected and the cyberattack did not cause any disruption to its products or services. According to the notice, two weeks ago, LastPass discovered that an unauthorized individual had gained access to the account of one of its developers, which gave the attacker access to the LastPass development environment. LastPass said steps were immediately taken to contain the attack and prevent further unauthorized access, with the forensic investigation confirming the attackers stole portions of its source code and “some proprietary LastPass technical information.” As is the case with many other password management solutions, LastPass...
Study Explores How Medical Apps are Sending Health Data to Facebook and Others
Sensitive information is being shared with data brokers and advertisers for the purpose of serving targeted advertisements, and not just by health apps and fitness trackers. HIPAA-covered entities are also sharing the health data without patient consent, which puts them at risk of regulatory fines and lawsuits. Many consumer health apps collect sensitive health data, including pregnancy and fertility trackers and personal fitness and exercise apps. These apps are fed data or directly collect that information through associated wearable devices, and that information may be shared with third parties or sold, as per the terms and conditions for use of the apps. If users do not wish to share their data, they can simply not use the apps. However, there is growing concern over the sharing of identifiable health data by healthcare organizations covered by the Health Insurance Portability and Accountability Act, which places restrictions on uses and disclosures of identifiable protected health information. Many hospitals have recently been discovered to have used the Meta Pixel JavaScript...
HC3 Sounds Alarm Over Data Theft and Extortion Attacks by Karakurt Threat Actors
The Department of Health and Human Services’ Health Sector Cybersecurity Coordination Center (HC3) has issued a warning to the Healthcare and Public Health Sector (HPH) about a relatively new ransom threat group called Karakurt, which is known to have conducted hacking and extortion attacks on the HPH sector. These attacks are similar to attacks conducted by ransomware gangs, but the group doesn’t bother encrypting data, just steals data and issues a demand to prevent its release. The group is thought to be either a breakaway group from the Conti ransomware gang or has ties to the prolific ransomware group. Karakurt, aka Karakurt Team/Karakurt Lair, conducted its first attacks in late 2021 and is known to have conducted attacks on at least four organizations in the HPH sector: A hospital, healthcare provider, assisted living facility, and dental firm. HC3 did not disclose the names of the healthcare organizations that have been targeted so far, but one is Methodist McKinney Hospital in Texas. That attack was detected by the hospital in June, which confirmed that files containing...
PHI Exposed in Cyberattacks on Methodist McKinney Hospital and Columbia River Mental Health Services
Methodist McKinney Hospital in Texas has recently announced that its systems have been accessed by unauthorized individuals who removed files containing sensitive data from its systems. The security incident was detected on July 5, 2022, and a third-party cybersecurity firm was engaged to investigate the nature and scope of the incident. The investigation confirmed that the attackers had access to its systems between May 20, 2022, and July 7, 2022, and during that time, files were exfiltrated that contained patient data. The preliminary investigation has confirmed that the files contained names, addresses, Social Security numbers, birth dates, medical history information, medical diagnosis information, treatment information, medical record numbers, and health insurance information. The investigation into the security breach is ongoing and a detailed review of all affected files has been initiated to determine the patients affected. The breach is known to have affected patients of Methodist McKinney Hospital, Methodist Allen Surgical Center, and Methodist Craig Ranch Surgical...
Humana & Cotiviti Settle Class Action Data Breach Lawsuit
Humana & Cotiviti have agreed to settle a class action lawsuit to resolve claims from individuals affected by a 2020 data breach that exposed the PHI of 64,654 individuals. Humana had contracted with Cotiviti to assist with medical record requests to verify the data it reports to the HHS’ Centers for Medicare and Medicaid Services. In order to provide those services, Cotiviti was provided with the protected health information of certain plan members. Cotiviti used a subcontractor, Visionary, to review the medical records that were collected. Between October 12, 2020, and December 16, 2020, a former employee of Visionary accessed its systems and obtained plan members’ data, which was provided to others in connection with a personal coding business. The data disclosed included plan members’ names, partial or full social security numbers, dates of birth, addresses, phone numbers, email addresses, member identification numbers, subscriber information numbers, dates of service, dates of death, provider names, medical record numbers, treatment information, and medical images. A...



