PHI of 127,000 NorthCare Patients Potentially Compromised in Ransomware Attack
NorthCare, an Oklahoma City, OK-based mental health clinic, was the victim of a ransomware attack in June 2021, in which patients’ protected health information may have been compromised. NorthCare identified suspicious network activity on June 1, 2021, when ransomware was used to encrypt files. The investigation into the attack confirmed its network was breached on May 29, 2021. The attackers rapidly deployed ransomware to prevent access to files and demanded payment of a ransom for the keys to decrypt files. Steps were immediately taken to contain the attack, and while it was not possible to prevent file encryption, it was possible to restore its systems and data from backups without paying the ransom. The parts of the network accessed by the attackers contained patients’ protected health information. While data exfiltration was not confirmed, NorthCare is assuming the attackers accessed patient data. The types of data potentially compromised in the attack included full names, addresses, dates of birth, medical diagnoses, and Social Security numbers. Following the attack,...
HHS Increases HIPAA Penalties for 2021 per the Inflation Adjustment Act
Under the Federal Civil Penalties Inflation Adjustment Act Improvements Act of 2015*, the Office of the Assistant Secretary for Financial Resources of the Department of Health and Human Services (HHS) has issued a final rule that implements adjustments to the maximum civil monetary penalties for HIPAA violations for 2021. According to the Department of Health and Human Services, the 2021 annual inflation adjustment “is determined using the percent increase in the Consumer Price Index for all Urban Consumers (CPI–U) for the month of October of the year in which the amount of each CMP was most recently established or modified.” The cost-of-living adjustment multiplier for 2021 is 1.01182. Previous cost-of-living multipliers are indicated below: 2017 – 1.01636 2018 – 1.02041 2019 – 1.02522 2020 – 1.01764 The final rule took effect on Monday, November 15, 2021, and applies to penalties assessed on or after November 15, 2021, if the violation occurred on or after November 2, 2015. These penalties will apply until the next inflation increase is applied. The annual...
Data Breaches Reported by Lakeshore Bone & Joint Institute and Putnam County Memorial Hospital
Lakeshore Bone & Joint Institute, an orthopedic practice in Indiana, has experienced a breach of its Microsoft Office 365 environment, which included emails and attachments that contained the protected health information of certain patients. Unusual activity was detected in an employee email account on July 7, 2021. Steps were immediately taken to prevent further unauthorized access and a cybersecurity and digital forensic firm was retained to investigate the breach and assist with remediation efforts. The breach investigation confirmed that an unauthorized individual had gained access to a single employee email account. A review of the account was completed on October 21, 2021, and revealed the following types of patient information may have been viewed or acquired in the attack: Date of birth, treatment information, diagnosis, provider name, MRN/patient ID, health insurance information, treatment cost information, and, for certain individuals, Social Security numbers. Individuals whose Social Security numbers were potentially compromised have been offered a 12-month...
Patients Unaware of the Extent of Healthcare Cyberattacks and Data Theft
A recent survey conducted by the unified asset visibility and security platform provider Armis has explored the state of cybersecurity in healthcare and the security risks that are now faced by healthcare organizations. The survey was conducted by Censuswide on 400 IT professionals at healthcare organizations across the United States, and 2,000 U.S. patients to obtain their views on cybersecurity and data breaches in healthcare. The survey confirmed cyber risk is increasing, with 85% of respondents saying cyber risk has increased over the past 12 months. Ransomware gangs have targeted the healthcare industry over the past 12 months, and many of those attacks have succeeded. 58% of the surveyed IT professionals said their organization had experienced a ransomware attack in the past 12 months. Ransomware attacks were viewed as a cause of concern by 13% of IT security pros, indicating most are confident that they will be able to recover data in the event of an attack. However, data breaches that result in the loss of patient data were a major worry, with 52% of IT pros rating data...
PHI of 1.27 Million Patients Compromised in Two Healthcare Data Breaches
The protected health information of 1,271,642 individuals has been exposed and potentially stolen in two healthcare hacking incidents that were recently been reported to the Department of Health and Human Services’ Office for Civil Rights. PHI of 688,000 Individuals Compromised in Sea Mar Community Health Centers Hack Sea Mar Community Health Centers is a nonprofit community-based provider of health, human, housing, educational, and cultural services to underserved communities in Washington state. On June 24, 2021, Sea Mar learned sensitive data had been exfiltrated from its IT systems by an unauthorized individual. Assisted by a leading third-party cybersecurity firm, Sea Mar determined its systems had been accessed between December 2020 and March 2021. According to the breach notice posted on its website, a review was conducted of the information potentially stolen from its network, which confirmed the following data types had been stolen: Name, address, Social Security number, date of birth, client identification number, diagnostic and treatment information, insurance...



