Vulnerability Identified in Philips IntelliSpace Perinatal Information Management System
A vulnerability has been identified in the Philips IntelliSpace Perinatal obstetrics information management system. The vulnerability – CVE-2019-13546 – could be exploited remotely by an authorized remote desktop session host application user or by an individual with physical access to a locked application screen. The vulnerability affects IntelliSpace Perinatal Versions K and earlier and requires a low level of skill to exploit. The flaw has been assigned a CVSS v3 base score of 6.1 out of 10 (medium severity). Exploitation of the vulnerability would allow an attacker to break out of the containment of the application and access resources from the Windows operating system as the limited-access Windows user. If an attacker used exploits for vulnerabilities in Windows once access to the operating system had been achieved, the attacker could potentially elevate operating system privileges to administrator level. Once access to the operating system has been achieved, an attacker could execute software and view, update or delete files, directories, and alter the system...
39% of Cybersecurity Professionals Say Their Company is Under Prepared for a Data Breach
A survey of cybersecurity and IT executives in the United States has revealed 39% of companies are under prepared to handle a data breach. The survey was commissioned by the cybersecurity consulting firm Avertium for the firm’s 2019 Cybersecurity and Threat Preparedness report. The survey was conducted on 223 respondents in the United States at companies with 50 or more employees. When asked about the main problems they experienced in relation to cybersecurity, the two biggest issues were the increasing complexity of cybersecurity tech stacks, which was rated as a major pain point by 76% of respondents. Added to that is the increasing sophistication of cyberattacks, which was a pain point for 75% of cybersecurity professionals. 66% of respondents said third-party or partner vulnerabilities were a major problem area, and 65% said their jobs have been made much more difficult due to vulnerabilities introduced by their company’s digital transformation. The cost and complexity of regulatory compliance was also rated as a pain point by 65% of respondents. The types of cyberattack that...
Geisinger Health Plan Notifies Members About Business Associate Phishing Attack
Danville, PA-based Geisinger Health Plan has discovered the protected health information (PHI) of some of its members has been exposed as a result of a suspected phishing attack on one of its business associates, Magellan NIA. Magellan NIA provides radiology benefits management services to the health plan, which requires access to plan members’ PHI. Magellan NIA discovered the breach on July 5, 2019 when suspicious activity was detected in the email account of one of its employees. The account was immediately secured to prevent further unauthorized access and misuse and an investigation was launched to determine the extent of the breach. The investigation revealed the account was breached on May 28, and there had been several connections to the account between up until July 5. Those connections were made from a location outside the United States. Geisinger Health Plan believes the sole purpose of the attack was to gain access to email accounts for the purpose of spamming, rather than to steal sensitive plan member data. However, it was not possible to rule out unauthorized data...
Slew of HIPAA Violations Leads to $2.15 Million Civil Monetary Penalty for Jackson Health System
The Department of Health and Human Services’ Office for Civil Rights has imposed a $2.15 million civil monetary penalty against the Miami, FL-based nonprofit academic medical system, Jackson Health System (JHS), for a slew of violations of the HIPAA Privacy, Security, and Breach Notification Rules. In July 2015, OCR became aware of several media reports in which the PHI of a patient was impermissibly disclosed. The individual was a well-known NFL football player. Photographs of an operating room display board and schedule had also been shared on social media by a reporter. OCR launched an investigation in October 2015 and opened a compliance review in relation to the impermissible disclosure. JHS investigated and submitted a report confirming that a photograph was taken in which two patients’ PHI was visible, including the PHI of a well-known person in the community. The internal investigation revealed that an employee had been accessing patient information without authorization since 2011. During that time, the employee had accessed the records of 24,188 patients without any...
76% of SMBs Have Experienced a Data Breach in the Past Year
A recent survey conducted by the Ponemon Institute on behalf of Keeper Security has revealed 76% of small and medium sized businesses in the United States have experienced a data breach in the past 12 months. The survey was conducted on 2,391 IT and IT security professionals in the United States, United Kingdom, and Western Europe for Keeper Security’s 2109 Global State of Cybersecurity report. The survey revealed SMBs in the United States are more extensively targeted than in other countries. Globally, 66% of SMBs have experienced a data breach in the past year. The frequency of attacks has also increased. Since 2016, the number of cyberattacks on SMBs has risen by 20%. 69% of respondents said cyberattacks have become much more targeted. The main methods used by cybercriminals to attack SMBs are phishing and social engineering, which were behind 57% of SMB cyberattacks in the past 12 months. 30% of attacks involved other forms of credential theft, and 33% of breaches were due to compromised or stolen devices. 70% of surveyed SMBs said they had experienced incidents in past 12...



