Healthcare Organizations Warned About Maximum Severity Vulnerabilities in Illumina Devices
Five vulnerabilities have been identified in the Illumina Local Run Manager (LRM), which is used by Illumina In Vitro Diagnostic (IVD) devices and Illumina Researcher Use Only (ROU) instruments. The affected devices are used for clinical diagnostic DNA sequencing and testing for various genetic conditions, and for research use. Four of the vulnerabilities are critical, with three having a maximum CVSS severity score of 10 out of 10. The vulnerabilities affect the following devices and instruments: Illumina IVD Devices NextSeq 550Dx: LRM Versions 1.3 to 3.1 MiSeq Dx: LRM Versions 1.3 to 3.1 Illumina ROU Devices NextSeq 500 Instrument: LRM Versions 1.3 to 3.1 NextSeq 550 Instrument: LRM Versions 1.3 to 3.1 MiSeq Instrument: LRM Versions 1.3 to 3.1 iSeq 100 Instrument: LRM Versions 1.3 to 3.1 MiniSeq Instrument: LRM Versions 1.3 to 3.1 A threat actor could exploit the vulnerabilities remotely, take control of the instruments, and perform any action at the operating system level such as modifying the settings, configurations, software, or data on the instrument. It would also be...
Data Breaches Reported by Alameda Health System, Aon, and Capsule Pharmacy
Alameda Health System in California, Capsule pharmacy in New York, and Aon PLC in Illinois have recently reported data breaches affecting a total of 56,290 individuals. Alameda Health System Notifying 90,000 Patients About PHI Breach Oakland, CA-based Alameda Health System has recently reported a data breach to the Department of Health and Human Services’ Office for Civil Rights that has affected up to 90,000 patients. Limited information has been released so far on the nature of the breach. Alameda Health System said suspicious activity was detected in the email accounts of certain employees with the investigation confirming several employee email accounts had been accessed by an unauthorized third party. The review of those accounts confirmed they contained the protected health information of patients, although it is currently unclear to what extent patient information has been compromised. Alameda Health System said no evidence has been found that suggests any information in the accounts has been viewed or removed. Notification letters will be sent to affected individuals...
PHI Potentially Compromised in Security Incidents at Allwell Behavioral Health Services and WellDyneRx
Allwell Behavioral Health Services in Zanesville, OH, has announced that a computer system used to store quality assurance information related to the treatment of patients has been accessed by an unauthorized individual. The unauthorized access was detected on March 5, 2022, with the subsequent forensic investigation determining the system was breached on March 2, 2022. The breach investigation concluded in late April and determined that it was likely that files containing sensitive information had been copied in the attack, although at the time of issuing notifications to affected individuals there had been no reports of any actual or attempted misuse of patient data. The types of information in the files varied from patient to patient and may have included information such as names, dates of birth, Social Security numbers, phone numbers, treatment activity, treatment provider, treatment date, treatment location, and payer information. According to the breach summary on the HHS’ Office for Civil Rights website, 29,972 patients have been affected. Complimentary identity theft...
Injured Workers Pharmacy Faces Class Action Lawsuit over Email Account Breach
A class action lawsuit has been filed in the U.S. District Court for the District of Massachusetts by the law firm Morgan & Morgan against Injured Workers Pharmacy (IWP) over a breach of the personal information of 75,771 customers. IWP is an Andover, MA-based pharmacy that serves employees who were injured at work and receive workers’ compensation benefits. On May 11, 2021, IWP discovered several employee email accounts had been accessed by an unauthorized individual, and those email accounts contained sensitive information such as names, addresses, and Social Security numbers. The first email accounts were compromised in January 2021, which allowed unauthorized access to the information in the accounts for 4 months before the breach was detected and the accounts were secured. Affected individuals were offered complimentary credit monitoring and identity theft protection services for 24 months. Plaintiffs Alexsis Webb and Marsclette Charley allege IWP failed to implement appropriate data security safeguards to ensure the privacy of their personal information and that of the...
BD Issues Security Advisories About Pyxis and Synapsys Vulnerabilities
BD has issued security advisories about two vulnerabilities that affect certain BD Pyxis automated medication dispensing system products and the BD Synapsys microbiology informatics software platform. BD Pyxis – CVE-2022-22767 According to BD, certain BD Pyxis products have been installed with default credentials and may still operate with those credentials. In some scenarios, the affected products may have been installed with the same default local operating system credentials or domain-joined server(s) credentials that may be shared across product types. If a threat actor were to exploit the vulnerability, it would be possible to gain privileged access to the underlying file system, which would allow access to ePHI or other sensitive information. The vulnerability is tracked as CVE-2022-22767 and has a CVSS v3 base score of 8.8 out of 10 (high severity). The following products are affected by the vulnerability BD Pyxis ES Anesthesia Station BD Pyxis CIISafe BD Pyxis Logistics BD Pyxis MedBank BD Pyxis MedStation 4000 BD Pyxis MedStation ES BD Pyxis MedStation ES Server BD...



