Sen. Warner Demands Answers from HHS Over Apparent Lack of Response to Major PACS Data Breach
U.S. Senator, Mark. R. Warner (D-VA) has written to the Director of the HHS’ Office for Civil Rights, Roger Severino, expressing concern over the HHS response to the mass exposure of medical images by U.S. healthcare organizations. Sen. Warner is the Vice Chairman of the Senate Intelligence Committee and co-founder of the Senate Cybersecurity Caucus. This is the latest in a series of communications in which he has voiced concerns about cybersecurity failures that have compromised the personal and private information of Americans. In February, Sen. Warner demanded answers from HHS agencies, NIST, and healthcare associations about healthcare cybersecurity following the continued increase in healthcare data breaches. His recent letter to OCR was in response to a September 17, 2019 report about the exposure of millions of Americans’ medical images that were stored in unsecured picture archiving and communications systems (PACS). The report detailed the findings of an investigation by ProPublica, German public broadcaster Bayerischer Rundfunk, and vulnerability and analysis firm,...
Microsoft Issues Fresh Warning to Patch BlueKeep Vulnerability
Prompt patching, or rather the lack of it, has prompted a fresh round of warnings to patch the BlueKeep vulnerability (CVE-2019-0708) that was exploited in a mass attack that started on October 23. The attack was first detected on November 2, with the delay due to the failure of the attacker to take full advantage of the vulnerability. The campaign appears to have been conducted by a low-level threat actor who exploited the vulnerability to deliver cryptocurrency mining malware. Microsoft has issued yet another warning that worse is yet to come. The first mass exploitation attempt certainly made the headlines, but it does not appear to have had much of an impact on the speed of patching. A scan conducted by the SANS Institute shows there has been little change in the rate of patching following the attacks. The number of unpatched devices has been steadily declining since Microsoft issued the patch in May, but hundreds of thousands of devices are still vulnerable to attack. The attack was on a large scale, albeit with limited success. The exploit that was used failed to work...
HHS Increases Civil Monetary Penalties for HIPAA Violations in Line with Inflation
The U.S Department of Health and Human Services has increased the civil monetary penalties for HIPAA compliance violations in accordance with the Inflation Adjustment Act. The final rule took effect on Tuesday November 5, 2019. This rule increases the civil monetary penalties for HIPAA violations that occurred on or after February 18, 2009. Under the new penalty structure, the increases from 2018 to 2019 are detailed in the table below: Penalty Tier Level of Culpability Minimum Penalty per Violation (2018 » 2019) Maximum Penalty per Violation (2018 » 2019) New Maximum Annual Penalty (2018 » 2019)* 1 No Knowledge $114.29 » $117 $57,051 » $58,490 $1,711,533 » $1,754,698 2 Reasonable Cause $1,141 » $1,170 $57,051 » $58,490 $1,711,533 » $1,754,698 3 Willful Neglect – Corrective Action Taken $11,410 » $11,698 $57,051 » $58,490 $1,711,533 » $1,754,698 4 Willful Neglect – No Corrective Action Taken $57,051 » $58,490 $1,711,533 » $1,754,698 $1,711,533 » $1,754,698 Penalties for HIPAA violations that occurred prior to February 18, 2009 have increased to $159 per violation, with an annual...
Salem Health Hospitals & Clinics and Delta Dental of Arizona Notify Patients About Phishing Attacks
Salem Health Hospitals & Clinics in Oregon experienced a phishing attack on July 31, 2019 that resulted in an unauthorized individual gaining access to the email accounts of several employees. The breach was detected within a day of the accounts being accessed and the compromised accounts were secured. Patients were notified about the breach on September 27 and were told that a review of the affected accounts was underway. The compromised email accounts were expected to contain a limited amount of patient information such as names, dates of birth, and information related to the medical services patients had received. At the time of issuing the notice, the investigation into the breach was ongoing. On Thursday, November 7, 2019, Salem Health spokesperson, Elijah Penner, said “The incident was reviewed thoroughly, and Salem Health has no indication that any patient information has been misused.” No evidence was uncovered to suggest patient information in emails and email attachments was accessed. Salem Health has advised affected patients to exercise caution and monitor...
Vulnerabilities Identified in Medtronic Valleylab Energy Platform and Electrosurgery Products
6 vulnerabilities have been identified in the Medtronic Valleylab energy platform and electrosurgery products, including one critical flaw that could allow an attacker to gain access to the Valleylab Energy platform and view/overwrite files and remotely execute arbitrary code. The vulnerabilities were identified by Medtronic which reported the flaws to the Department of Homeland Security Cybersecurity and Infrastructure Security Agency under its responsible vulnerability disclosure policy. Four vulnerabilities have been identified in the following Medtronic Valleylab products Valleylab Exchange Client, Version 3.4 and below Valleylab FT10 Energy Platform (VLFT10GEN) software Version 4.0.0 and below Valleylab FX8 Energy Platform (VLFX8GEN) software Version 1.1.0 and below The critical vulnerability is an improper input validation flaw in the rssh utility, which facilitates file uploads. Exploitation of the vulnerability would allow an attacker to gain administrative access to files, allowing those files to be viewed, altered, or deleted. The flaw could also allow remote execution of...



