PHI of 47,000 Individuals Potentially Compromised in Electromed Inc. Data Breach
Electromed Inc., a New Prague, MN-based developer and manufacturer of airway clearance devices, has announced it suffered a security breach in June 2021 in which unauthorized individuals gained access to certain IT systems. Electromed said unauthorized activity was detected in its IT systems on June 16, 2021 and steps were immediately taken to prevent further unauthorized access. An investigation was launched to determine the source and scope of the breach and third-party cybersecurity experts were engaged to assist with the investigation. Electromed determined the unauthorized third party accessed certain files that contained the personal and protected health information of its customers, as well as information of its employees and certain third-party contractors. A comprehensive review was conducted of all files on the affected systems, which revealed they contained customers’ first and last names, mailing addresses, medical information, health insurance information and, for associates, Social Security numbers, driver’s license numbers, and financial account information. While...
UNM Health Data Breach Affects More than 637,000 Patients
UNM Health has discovered an unauthorized third party gained access to its network and potentially viewed and exfiltrated files from its systems that contained patients’ protected health information. The security breach was discovered on June 4, 2021 and an investigation was immediately launched to determine the extent and scope of the breach. UNM Health determined its systems were accessed by the unauthorized third-party on May 2, 2021 and files containing the protected health information of its patients, including those of UNM Hospital, UNM Medical Group, Inc., and UNM Sandoval Regional Medical Center Inc. were potentially compromised. A comprehensive review of all files on the compromised parts of its network was conducted and it was confirmed they contained information such as names, addresses, dates of birth, medical record numbers, patient identification numbers, health insurance information, and some clinical information related to the healthcare services provided by UNM Health. The Social Security numbers of a limited number of patients were also potentially compromised in...
Password Reuse is Rife and Security Awareness Training Has Little Effect
An overwhelming majority of employees are aware what constitutes a strong password, but 53% of employees do not always set a strong password to protect their accounts. When it comes to setting unique passwords for all accounts, even fewer employees adhere to the best practice, according to a survey recently conducted by My1login on 1,000 employees and 1,000 business leaders. 62% of employees said they reuse personal passwords for their business accounts or vice versa. Healthcare employees were the worst when it comes to password reuse, with 94% of surveyed healthcare employees admitting to reusing passwords across multiple accounts, with similarly high numbers of employees in education (91%) and the public sector (83%) reusing passwords. These three verticals also rated the highest for the use of personal passwords for business applications, with education coming top (75%) followed by healthcare (68%) and the public sector (61%). Across all industry sectors, 87% of employees said they reused passwords across business applications. Password reuse is a security risk. If a password is...
Study Reveals Extent of Cybersecurity Vulnerabilities at Major Pharmaceutical Firms
Reposify, a provider of an external attack surface management platform, has published the findings of a study of security vulnerabilities at pharmaceutical firms which shows the vast majority of pharma firms have unresolved vulnerabilities that are putting sensitive data and internal systems at risk of compromise. The study was conducted to assess the prevalence of exposures of services, sensitive platforms, unpatched CVEs and other security issues. Data analyzed for the Pharmaceutical Industry: 2021: The State of the External Attack Surface Report were collected over a two-week period in March 2021 and covered 18 of the leading pharmaceutical companies worldwide and more than 900 of their subsidiaries. Pharmaceutical companies hold vast amounts of sensitive personal data and extremely valuable drug and vaccine research data. That has made them an attractive target for cybercriminals. During the COVID-19 pandemic, nation state hackers targeted pharma and biotech firms to gain access to sensitive COVID-19 research and vaccine development data. According to the 2020 Cost of a Data...
PHI of Employees Compromised in Cyberattack on Waste Management Firm
USA Waste-Management Resources, LLC has started notifying certain employees, former employees, and dependents covered by its self-administered health plan that some of their personal and protected health information (PHI) was compromised in a January 2021 cyberattack. Waste-Management Resources said suspicious activity was detected in its IT systems on January 21, 2021. An investigation was launched and, assisted by third party computer forensics specialists, Waste-Management Resources confirmed that an unauthorized individual had accessed its systems between January 21 and January 23, 2021 and that certain files were accessed and stolen in the attack. An extensive review was conducted to determine if any files stored on the compromised parts of its network contained any sensitive information. That process was completed on June 21, 2021. The review confirmed the following types of information had been exposed and have potentially been compromised: Names, Social Security numbers, taxpayer identification numbers, government ID numbers, state ID numbers, driver’s license...



