Over 10,000 Organizations Targeted in Ongoing MFA-Bypassing Phishing and BEC Campaign
Microsoft has warned of a large-scale phishing campaign targeting Office 365 credentials that bypasses multi-factor authentication (MFA). The campaign is ongoing and more than 10,000 organizations have been targeted by scammers in the past 10 months. Microsoft reports that one of the phishing runs used emails with HTML file attachments, with the email telling the user about a Microsoft voicemail message that had been received. The HTML file had to be opened to download the message. The HTML file serves as a gatekeeper, ensuring the targeted user was arriving at the URL from a redirect from the original attachment. The user is redirected to a website that hosts a popular open source phishing kit, which is used to harvest credentials. The user is told that they need to sign in to their Microsoft account to receive the voicemail message and after sign in an email will be sent to the user’s mailbox within an hour with the MP3 voicemail message attached. The user’s email address is auto-filled into the login window and the user only needs to enter their password. This campaign is...
Data Brokers and Health Apps Probed Over Privacy Practices
On Friday, the House Committee on Oversight and Reform announced that a probe has been initiated to determine how data brokers and health app companies are collecting and selling individuals’ personal reproductive health data. The probe was initiated as a result of the SCOTUS decision that overturned Roe v. Wade, as members of the committee were concerned that the personal data of individuals seeking reproductive healthcare services may be misused. Rep. Carolyn B. Maloney, Chairwoman of the Committee on Oversight and Reform, Rep. Raja Krishnamoorthi, Chairman of the Subcommittee on Economic and Consumer Policy, and Rep. Sara Jacobs, wrote to five data brokers (SafeGraph, Digital Envoy, Placer.ai, Gravy Analytics, Babel Street) and five health app companies (Flo Health, Glow, BioWink, GP International, and Digitalchemy Ventures) requesting documentation on how personal reproductive care information is collected and sold. Huge amounts of personal data are now being collected and sold, often without the knowledge of individuals. The information is used to serve individuals’...
Associated Eye Care Partners Issues Notifications About December 2020 Data Breach
Montana-based Associated Eye Care Partners (AECP) has recently started notifying patients that their private health information was compromised in a data breach at a business associate that was detected in early December 2020. The data breach in question occurred at Netgain Technology, which provided managed IT services to many organizations in the healthcare sector. Netgain Technology experienced a ransomware attack in which files containing sensitive data were stolen. Netgain paid the ransom to prevent any further disclosure of the stolen data and received assurances from the ransomware gang that the stolen data had been deleted. Netgain Technology notified affected healthcare clients in January 2021, and those entities started to issue notification letters to affected patients over the next couple of months. While some affected healthcare clients took longer to issue notifications, it has now been 18 months since Netgain started notifying affected clients. According to the AEC notification letter – dated July 8, 2022 – “Upon notification by Netgain to AEC, we worked with...
President Biden Signs Executive Order to Protect Access to Reproductive Healthcare Services
President Biden has signed an executive order that aims to protect access to reproductive healthcare services following the SCOTUS ruling that overturned Roe v. Wade, which gave women the constitutional right to make their own reproductive healthcare decisions almost 50 years ago. “These deeply private decisions should not be subject to government interference. Yet today, fundamental rights — to privacy, autonomy, freedom, and equality — have been denied to millions of women across the country,” said President Biden. The SCOTUS ruling did not ban abortions in the United States, instead, it has been left to individual states to determine the legality of abortions. Several states have already banned or severely restricted abortion care for state residents, which has threatened access to reproductive care for millions of Americans. 16 states have either banned or mostly banned abortions, with those laws taking effect within a month, and further 6 states are expected to introduce bans imminently or in the near future. Clinics that provide abortions in the states that have already...
Patient Information Compromised at Phoenixville Hospital, Family Practice Center, and Southwest Health Center
Phoenixville Hospital Fires Employee for HIPAA Violation Phoenixville Hospital in Pennsylvania has recently fired an employee for accessing the medical records of patients without authorization. According to the hospital operator, Tower Health, the unauthorized access was discovered during a routine audit of medical record access logs. An employee was discovered to have accessed the medical records of 934 patients without authorization between October 2021 and May 2022, when there was no legitimate work reason for viewing those records. When the privacy violation was discovered, the employee was immediately suspended pending an internal investigation and was later fired for the HIPAA breach. The employee viewed names, addresses, dates of birth, appointment dates, diagnoses, vital sign information, medications, test results, and physicians’ notes. Some of the accessed records included partial Social Security numbers and health insurance information. Tower Health said additional training has been provided to the workforce regarding patient privacy and the accessing of medical...



