Vulnerabilities Identified in Insulet Omnipod and Systech NDS-5000 Terminal Server
Advisories have been issued about recently discovered vulnerabilities in the Insulet Omnipod Insulin Management System and the Systech NDS-5000 Terminal Server. Improper Access Control Identified in Insulet Omnipod Insulin Management System ThirdwayV Inc. has discovered a high severity flaw in the Omnipod Insulin Management System which could allow an attacker with access to a vulnerable insulin pump to access the Pod and intercept and modify data, change insulin pump settings, and control insulin delivery. The vulnerable insulin pumps communicate with an Insulet manufactured Personal Diabetes Manager device using wireless RF. The researchers discovered the RF communication protocol does not implement authentication or authorization properly. The following versions are affected: Omnipod Insulin Management System Product ID/Reorder number: 19191 and 40160 UDI/Model/NDC number: ZXP425 (10-Pack) and ZXR425 (10-Pack Canada) The vulnerability is tracked as CVE-2020-10597 and has been assigned a CVSS v3 base score of 7.3 out of 10. There have been no reported cases of exploitation of the...
Roundup of Recent Healthcare Data Breaches
A roundup of healthcare data breaches and security incidents recently reported to the HHS’ Office for Civil Rights and by media. Texas Network of Walk-in Clinics Attacked with Maze Ransomware AffordaCare Urgent Care Clinic, a network of walk-in clinics in Texas, has been attacked by the Maze ransomware gang. According to a recent report on DataBreaches.net, the hackers stole 40GB of data prior to encrypting files. Some of the stolen data was published online when AffordaCare refused to pay the ransom. The published data included patient contact details, medical histories, diagnoses, billing information, health insurance information, and employee payroll data. It is currently unclear how many patients have been affected as the breach has not yet appeared on the HHS’ Office for Civil Rights breach portal. Tandem Diabetes Care Patients Notified About Phishing Attack Tandem Diabetes Care, Inc. in San Diego, CA has been targeted by cybercriminals who gained access to the email accounts of a limited number of its employees between January 17, 2020 and January 20, 2020. The attack was...
CISA Warns of Exploitation of Vulnerabilities in VPNs and Campaigns Targeting Remote Workers
In an effort to prevent the spread of the coronavirus, many employers are telling their employees to work from home. While this measure is important for reducing the risk of contracting Coronavirus Disease 2019 (COVID-19), working from home introduces other risks. In order to protect against cyberattacks, enterprise-class virtual private networks (VPN) solutions should be used to connect remotely to the network. VPNs secure the connection between a user’s device and the network, allowing them to access and share healthcare information securely. While VPNs will improve security, many VPN solutions have vulnerabilities that can be exploited by cybercriminals. If those vulnerabilities are exploited, sensitive data can be intercepted, and an attacker could even take control of affected systems. Cybercriminals are actively searching for vulnerabilities in VPNs to exploit, and the increase in remote workers as a result of the coronavirus gives them many more targets to attack. The risks associates with VPNs and the increase in the number of remote workers due to the coronavirus has...
Law Firm Files Class Action Lawsuit After Being Charged Excessive Fees for Copy of Patient’s Medical Records
A law firm is taking legal action against the healthcare release-of-information solution provider, Medical Records Online (MRO), for alleged overcharging for providing electronic copies of patients’ medical records. The lawsuit was filed by Cipriani & Werner of Pittsburgh in federal court in Camden, NJ. The lawsuit relates to MRO charges for providing a copy of a patient’s medical records for a personal injury case against the retailer Kohl’s, which the law firm represents. Cipriani & Werner obtained the medical records of the plaintiff in the suit from John F. Kennedy Medical Center, in Edison, NJ, and was charged $528 by MRO for 518 pages of the plaintiff’s medical records. The law firm was charged a $10 search fee and $1 per page, even though the records were provided electronically as a PDF file. Cipriani & Werner alleges MRO violated the New Jersey Declaratory Judgement Act by charging unlawful fees well in excess of the maximum limit. A claim was also made under the New Jersey Consumer Fraud Act for unconscionable commercial practices, and for a breach of New...
Department of Health and Human Services Targeted in Cyberattack
The U.S. Department of Health and Human Services (HHS) has been targeted by cybercriminals in what appears to be an attempt to overwhelm its website with millions of hits. According to a statement issued by HHS spokesperson, Caitlin B. Oakley, the HHS detected “a significant increase in activity on HHS cyber infrastructure” in what appears to have been an attempted Distributed Denial of Service (DDoS) attack. The individuals responsible for the attack were unsuccessful thanks to additional protections put in place to mitigate DDoS attacks as part of HHS preparation and response to the COVID-19 pandemic. “HHS has an IT infrastructure with risk-based security controls continuously monitored in order to detect and address cybersecurity threats and vulnerabilities,” explained Oakley. No data breach was experienced and the HHS and federal networks are continuing to function normally. Federal cybersecurity professionals are continuing to monitor HHS computer networks and will take appropriate actions to protect those networks and mitigate any further attacks should they occur. The...



