Study Confirms Increase in Mortality Rate and Poorer Patient Outcomes After Cyberattacks
A recent study has revealed that more than 20% of healthcare organizations experienced an increase in mortality rate after a significant cyberattack and more than half of surveyed healthcare organizations (57%) said they experienced poorer patient outcomes, with almost half reporting an increase in medical complications. The most common consequences of the attacks that contributed to poorer patient outcomes were delays to procedures and tests. The study was conducted by the Ponemon Institute on behalf of cybersecurity firm Proofpoint on 641 healthcare IT and security practitioners in the United States, with the findings detailed in the report, Cyber Insecurity in Healthcare; The Cost and Impact on Patient Safety and Care. The findings mirror those of a previous study conducted by the Ponemon Institute in 2021 on behalf of Censinet. That study was conducted on 597 healthcare respondents and one-fifth (22%) said they experienced an increase in their mortality rates following a ransomware attack. The latest study used a broader definition of cyberattack, which includes the four most...
Bitwarden’s $100 Million Investment will Accelerate Addition of Passwordless Authentication and Developers Secrets
The open source password manager provider, Bitwarden, has raised $100 million in funding which will be used to provide greater support for its user community and accelerate product development to help the firm achieve its long-term goals more rapidly. This is the first funding round to be publicly disclosed by the company. The funding round was led by the private equity firm PSG, with previous Bitwarden investor, Battery Ventures, also participating. Bitwarden has developed a popular password manager that is used by tens of thousands of businesses worldwide and millions of users, with the platform offering a wide range of functions to meet the needs of businesses and consumers. The platform is available in more than 50 languages, with around half of the company’s business coming from outside North America. The company is planning to use some of the funding to accelerate growth in the Asian and European markets, as well as South America and Australia, which are currently served through channel partners in those regions. Bitwarden’s goal is to empower individuals by providing...
Lamoille Health Partners Facing Class Action Lawsuit Over 58K-Record Data Breach
The Morristown, VT-based healthcare provider, Lamoille Health Partners, is facing a class action lawsuit over a June 2022 ransomware attack that affected almost 60,000 of its patients. The attack was detected on June 13, 2022, with the investigation confirming the attackers gained access to its network the previous day. Before file encryption, the attackers potentially accessed or acquired documents from its systems that contained names, addresses, dates of birth, Social Security numbers, health insurance information, and medical treatment information. On or around August 11, 2022, notification letters were sent to affected individuals, and complimentary identity protection and credit monitoring services were offered to patients whose Social Security numbers were potentially stolen. Lamoille Health Partners said the delay in issuing notification letters was due to the length of the investigation to establish which individuals had been affected and the types of information involved. The HIPAA breach was reported to the HHS’ Office for Civil Rights as affecting 59,381 patients. As is...
ADPPA’s Preemption of State Laws is A Major Sticking Point
The ADPPA is now awaiting a House vote but there are doubts about whether the federal data privacy and protection bill will pass that vote. While there is strong support for the ADPPA, that support is far from universal and several House members have stated that they would not vote in favor of the ADPPA in its current form and would require tweaks to be made before they would give their support. One of the biggest sticking points is the preemption of state laws. The ADPPA would override state laws, including the California Consumer Privacy Act (CCPA) and the California Privacy Rights and Enforcement Act (CPRA), which provide greater protection for state residents in some key areas. The Health Insurance Portability and Accountability Act (HIPAA) preempts state laws; however, it sets minimum standards for healthcare data privacy and security, but states are permitted to implement their own laws that go further than HIPAA. The ADPPA in its current form does not permit that and sets a floor and a ceiling for data privacy. House Speaker Nancy Pelosi has recently criticized some...
OIG Calls for Greater Oversight of the Cybersecurity of the Organ Procurement and Transplantation Network
The HHS’ Office of Inspector General (OIG) has called for the Health Resources and Services Administration (HRSA) to improve oversight of the cybersecurity of the Organ Procurement and Transplantation Network (OPTN). The OPTN is a national system for allocating and distributing donor organs to individuals in need of organ transplants. The OPTN is a public-private partnership that links all professionals that are involved in the donation and transplantation system which is administered by the United Network for Organ Sharing (UNOS). UNOS is a nonprofit that is responsible for managing systems that contain the personal and medical information of organ donors, candidates for transplants, and transplant recipients. The IT systems supporting the OPTN ensure the rapid matching of donated organs with patients awaiting organ donation. There is a very short window of opportunity for providing donated organizations to recipients, which can be just a matter of hours or days. The IT systems that support the OPTN are essential for ensuring that process is efficient, and require the...



