Ransom Paid to Recover Healthcare Data Stolen in Cyberattack on Online Storage Vendor
The protected health information of 29,982 patients of a Laguna Hills, CA-based provider of medical and surgical eye care services has potentially been stolen in a cyberattack on its online storage vendor. On January 15, 2021, Harvard Eye Associates was informed by its storage vendor that hackers had gained access to the vendor’s computer system and exfiltrated data. It is not clear whether files were encrypted to prevent access; however, a ransom demand was issued for the return of the stolen data. The storage vendor consulted with cybersecurity experts and the Federal Bureau of Investigation and took the decision to pay the ransom demand. The hackers returned the stolen data and provided assurances that no copies of the data had been made and there had been no further disclosures of the stolen information. The cybersecurity experts engaged by the security vendor have been monitoring the Internet and darknet and have not found any evidence to suggest the stolen data has been sold or leaked online. An investigation into the breach revealed the hackers first gained access to its...
LastPass Restricts Functionality of its Free Password Manager
LastPass, one of the most popular free-to-use password manager solutions, has announced it will be restricting access to its services for free users of the solution. LastPass offers paid and free version of its password manager, with the paid service offering a more comprehensive range of features, but the free version was a solid choice, offering users most of the features of the paid version. That is now about to change. From March 20, 2021, users of the free version of LastPass will be faced with a choice. If they continue using the password manager under the free tier, they will only be able to do so for either desktop computers and laptops or mobile devices. Previously, the free version could be used across all device types, but now they face a desktop or mobile choice. Accompanying this change will be the end of access to customer support via email for free users of the solution. Support will continue until August 23, 2021, after which it will only be provided for Premium and Families accounts. While LastPass remains a great choice in terms of the quality of the password...
January 2021 Healthcare Data Breach Report
January saw a 48% month-over-month reduction in the number of healthcare data breaches of 500 or more records, falling from 62 incidents in December to just 32 in January. While this is well below the average number of data breaches reported each month over the past 12 months (38), it is still more than 1 data breach per day. There would have been a significant decline in the number of breached records were it not for a major data breach discovered by Florida Healthy Kids Corporation that affected 3.5 million individuals. With that breach included, 4,467,098 records were reported as breached in January, which exceeded December’s total by more than 225,000 records. Largest Healthcare Data Breaches Reported in January 2021 The breach reported by Florida Healthy Kids Corporation was one of the largest healthcare data breaches of all time. The breach was reported by the health plan, but actually occurred at one of its business associates. The health plan used an IT company for hosting its website and an application for applications for insurance coverage. The company failed to apply...
HHS Secretary Announces Limited HIPAA Waiver in Texas Due to the Winter Storm
Following President Joseph R. Biden’s declaration of an emergency in the State of Texas, Norris Cochran, Acting Secretary of the Department of Health and Human Services, declared a public health emergency due to the consequences of the winter storm in the state of Texas. Pursuant to Section 1135(b)(7) of the Social Security Act, the HHS Secretary announced a limited waiver of sanctions and penalties arising from noncompliance with certain provisions of the HIPAA Privacy Rule. For the period of the waiver, sanctions and penalties will not be imposed for noncompliance with the following HIPAA Privacy Rule requirements: The requirement to obtain a patient’s agreement to speak with family members of friends – 45 C.F.R. § 164.510(a); The requirement to honor a patient’s request to opt out of the facility directory – 45 C.F.R. § 164.510(b); The requirement to distribute a notice of privacy practices – 45 C.F.R. § 164.520; The patient’s right to request privacy restrictions – 45 C.F.R. § 164.522(a); The patient’s right to request confidential communications –...
Wilmington Surgical Associates Facing Class Action Lawsuit Over Netwalker Ransomware Attack
Wilmington Surgical Associates in North Carolina is facing a class action lawsuit over a Netwalker ransomware attack and data breach that occurred in October 2020. As is now common in ransomware attacks, files were exfiltrated prior to the deployment of ransomware. In this case, the Netwalker ransomware gang stole 13GB of data from two Wilmington Surgical Associates’ servers that were used for administration purposes. Some of the stolen was published on the threat actors’ data leak site where it could be accessed by anyone. The leaked data was spread across thousands of files and included financial information related to the practice, employee information, and patient data such as photographs, scanned documents, lab test results, Social Security numbers, health insurance information, and other sensitive patient information. Wilmington Surgical Associates sent notifications to affected individuals in December 2020 and reported the data breach to the HHS’ Office for Civil Rights on December 17, 2020 as affecting 114,834 patients. The lawsuit – Jewett et al. v. Wilmington...



