Ransomware Attack on New York Billing Company Affects 942K Individuals
Practice Resources, a Syracuse, NY, provider of billing and other professional services, has suffered a data breach involving the records of 942,138 individuals. According to the breach notification sent to the California Attorney General, Practice Resources was the victim of a ransomware attack on April 12, 2022. Assisted by third-party digital forensics experts, Practice Resources determined that there had been unauthorized access to parts of the network where the protected health information of its clients was stored and the attackers may have infiltrated that information prior to file encryption. A review of the documents potentially affected by the attack confirmed they contained information such as names, addresses, dates of treatment, health plan numbers, and medical record numbers. Practice Resources has offered affected individuals a complimentary membership to an identity theft protection and credit monitoring service. Practice Resources said it has issued notification letters to affected individuals on behalf of 28 clients that were affected by the data breach. Achieve...
United Health Centers of San Joaquin Valley Notifies Patients About August 2021 Ransomware Attack
In August 2021, the Vice Society ransomware operation published data on its data leak site that had allegedly been obtained in a ransomware attack on United Health Centers of San Joaquin Valley. On August 31, 2021, Bleeping Computer was made aware of the data leak and made multiple attempts to notify United Health Centers. The website DataBreaches was also made aware of the data breach and similarly attempted to notify United Health Centers on multiple occasions. HIPAA Journal reported on the incident in September 2021. Almost a year on and individuals whose protected health information was exposed or stolen in the attack have been notified by United Health Centers. The breach notification provided to the California Attorney General on August 12, 2022, explains that technical difficulties were experienced by United Health Centers on August 28, 2021, which caused disruption to its computer systems. Steps were immediately taken to secure its network and systems, and an investigation was launched to determine the nature of the incident. United Health Centers said it discovered on...
Novant Health Notifies 1.36 Million Patients About Unauthorized Disclosure of PHI via Meta Pixel Code on Patient Portal
Novant Health has recently notified 1,362,296 patients about a breach of their protected health information due to the incorrect configuration of Meta Pixel code on its patient portal. Code Snippet Sending Sensitive Patient Data to Meta Earlier this year, an investigation conducted by The Markup into the use of Meta Pixel code on healthcare providers’ websites revealed 33 of the top 100 hospitals in the United States had included Meta Pixel code on their websites, and 7 of those hospitals had added the code to their password-protected patient portals. The 7 hospitals discovered by The Markup to have installed Meta Pixel on their patient portals were Community Health Network, FastMed, Edward-Elmhurst Health, Piedmont, Renown Health, WakeMed, and Novant Health. Meta Pixel is a snippet of JavaScript code that is used to track website visitors, and the information gathered is sent to Meta (Facebook), which may be used to serve targeted ads. Meta claims that organizations that use Meta Pixel are not supposed to send sensitive data. If Meta discovers it has been sent sensitive data by...
How the FIDO Alliance Aims to Make Logging In More Secure
The Fido Alliance is an association of businesses from many different industries with a shared vision – to make logging in to online services more secure. The Alliance aims to achieve its vision by developing standards for user authentication and device attestation that will – it is hoped – replace the world´s “over-reliance on passwords”. The failure to use strong, unique passwords for each account – and the failure to keep the passwords secure – is the leading cause of data breaches; and while technologies exist that can prevent password-related data breaches, they are not as widely adopted as they should be because end users would rather sacrifice security for convenience. Acknowledging that poor online security is an issue that´s not going to go away, the FIDO Alliance evolved from an idea initiated by PayPal and Validity Sensors to replace passwords with biometric logins. The idea gained traction, and the Alliance was launched in 2013 with the support of companies such as Google, Lenovo, Samsung, and Yubico. Since its launch, the FIDO Alliance has published three sets of...
Is Cloud Computing HIPAA Compliant?
Cloud computing has revolutionized the way healthcare organizations operate, but ensuring cloud computing is HIPAA compliant can be a challenge. Many healthcare organizations have already embraced cloud technologies, but as with any technology, care must be taken as there is considerable potential for HIPAA violations in the cloud. Here we consider how healthcare organizations can use cloud computing in a HIPAA-compliant manner. There is an extensive range of Cloud Service Providers (CSPs) and their products differ in terms of storage limits, accessibility, and security configurations, Covered Entities are advised to research CSPs and ensure that a product supports HIPAA compliance. They should establish how they will use the cloud computing technologies, conduct a risk assessment, and ensure all staff members are trained on how to use a CSP’s products and services. All CEs are required to obtain a signed business associate agreement (BAA) from their chosen CSP prior to using that service in connection with any protected health information (PHI). BAAs outline the responsibilities...



