Avamere Holdings Facing Class Action Lawsuit Over 2022 Cyberattack
The Wilsonville, OR-based home health care service provider and nursing home operator, Avamere Holdings, is facing a class action lawsuit over a major data breach that affected 96 senior living and healthcare facilities and resulted in the exposure of the protected health information of more than 380,000 individuals. The breach occurred Avamere Health Services – a business associate of Avamere Holdings that provides information technology services. An unauthorized individual had access to the network of Avamere Health Services between January 19, 2022, and March 17, 2022, and exfiltrated files containing protected health information. While the nature of the attack was not disclosed, a ransomware group claimed credit for the attack and uploaded some of the stolen data to its data leak site. The breach was reported to the Department of Health and Human Services as affecting 197,730 individuals, although some of the companies affected by the breach, such as Premere Infinity Rehab, issued their own breach notifications. At least 380,984 individuals are understood to have been...
EmergeOrtho & General Health System Victims of Ransomware Attacks
EmergeOrtho, a North Carolina orthopedic practice, has recently notified 68,661 patients that some of their protected health information has been accessed by unauthorized individuals. According to EmergeOrtho’s substitute breach notice, a sophisticated ransomware attack was detected and blocked on May 18, 2022. The forensic investigation confirmed that the threat actors behind the attack had accessed files containing patients’ protected health information. A comprehensive review of all affected files confirmed on August 19, 2022, that they contained information such as first and last names, addresses, Social Security numbers, and, for certain individuals, date of birth. No medical records, treatment information, or financial information was compromised in the attack and no evidence has been identified that suggests any of the affected information has been specifically misused. EmergeOrtho said leading IT specialists were engaged to confirm the security of its network environment, steps will continue to be taken to enhance the security of its systems, and additional monitoring tools...
Source Code Stolen in LastPass Data Breach
A cyberattack and data breach has been reported by LastPass, the provider of the world’s most popular password management solution. According to LastPass, there are around 30 million users of its password manager solution globally, including 85,000 business customers. Notifications have been sent to customers to inform them about the cyberattack and provide reassurances that while some company data was stolen in the attack, users’ password vaults were not affected and the cyberattack did not cause any disruption to its products or services. According to the notice, two weeks ago, LastPass discovered that an unauthorized individual had gained access to the account of one of its developers, which gave the attacker access to the LastPass development environment. LastPass said steps were immediately taken to contain the attack and prevent further unauthorized access, with the forensic investigation confirming the attackers stole portions of its source code and “some proprietary LastPass technical information.” As is the case with many other password management solutions, LastPass...
Study Explores How Medical Apps are Sending Health Data to Facebook and Others
Sensitive information is being shared with data brokers and advertisers for the purpose of serving targeted advertisements, and not just by health apps and fitness trackers. HIPAA-covered entities are also sharing the health data without patient consent, which puts them at risk of regulatory fines and lawsuits. Many consumer health apps collect sensitive health data, including pregnancy and fertility trackers and personal fitness and exercise apps. These apps are fed data or directly collect that information through associated wearable devices, and that information may be shared with third parties or sold, as per the terms and conditions for use of the apps. If users do not wish to share their data, they can simply not use the apps. However, there is growing concern over the sharing of identifiable health data by healthcare organizations covered by the Health Insurance Portability and Accountability Act, which places restrictions on uses and disclosures of identifiable protected health information. Many hospitals have recently been discovered to have used the Meta Pixel JavaScript...
HC3 Sounds Alarm Over Data Theft and Extortion Attacks by Karakurt Threat Actors
The Department of Health and Human Services’ Health Sector Cybersecurity Coordination Center (HC3) has issued a warning to the Healthcare and Public Health Sector (HPH) about a relatively new ransom threat group called Karakurt, which is known to have conducted hacking and extortion attacks on the HPH sector. These attacks are similar to attacks conducted by ransomware gangs, but the group doesn’t bother encrypting data, just steals data and issues a demand to prevent its release. The group is thought to be either a breakaway group from the Conti ransomware gang or has ties to the prolific ransomware group. Karakurt, aka Karakurt Team/Karakurt Lair, conducted its first attacks in late 2021 and is known to have conducted attacks on at least four organizations in the HPH sector: A hospital, healthcare provider, assisted living facility, and dental firm. HC3 did not disclose the names of the healthcare organizations that have been targeted so far, but one is Methodist McKinney Hospital in Texas. That attack was detected by the hospital in June, which confirmed that files containing...



