Workplace Safety Survey Shows Communication Issues are Placing Employees at Risk
Framingham, MA-based Rave Mobile Safety has published the results of its annual workplace safety and preparedness survey. The report shows that while preparedness for emergencies is better than in 2017, there is still considerable room for improvement, especially in healthcare and education. The survey was conducted on 540 full-time employees in the United States across several industries. The aim of the survey was to identify trends in emergency planning, obtain the views of employees about workplace safety, and find out more about the efforts that have been made to ensure effective communication in the event of an emergency and alert employees at risk. The survey shows companies are increasingly developing plans for modern emergencies, such as active shooters, workplace violence, cyberattacks, and system outages. However, greater effort is required to ensure that emergency plans are communicated to employees. Some 20% of workers were unaware of emergency plans for cyberattacks and system outages and 18% of workers were unaware of the emergency plan for active shooters and...
Three Healthcare Ransomware Attacks Reported: 70,000 Individuals Affected
Three ransomware attacks have been reported by healthcare organizations and vendors in the past few days. The PHI of almost 70,000 patients has potentially been compromised in the attacks. 50,000 Individuals Affected by Ransomware Attack on Delaware Guidance Services for Children and Youth Delaware Guidance Services for Children and Youth (DGS) was forced to pay a ransom to recover files that had been encrypted in a Christmas Day ransomware attack. DGS has not publicly disclosed how much was paid for the decryption keys to unlock the files on its data servers. After recovering files, DGS engaged an IT firm to conduct a forensic analysis to determine whether the attackers had gained access to sensitive information prior to encrypting files. The firm found no evidence to suggest that any protected health information had been compromised or stolen. The attack appeared to have been conducted solely for the purpose of extorting money from DGS. DGS started sending notification letters to the parents and guardians on February 26, 2019 alerting them that sensitive information had been...
More Than 600,000 Michigan Residents Affected by Wolverine Solutions Breach, Warns AG Nessel
Michigan Attorney General Dana Nessel has issued a warning to Michigan residents about the ransomware attack on Detroit-based Wolverine Solutions Group, which she says may have affected more than 600,000 Michigan residents. Nessel has advised all individuals who receive a breach notification letter to sign up for credit monitoring services, to monitor their accounts and EoB statements for signs of fraudulent use of their data, to place a fraud alert on their credit file and to consider freezing their credit file as a protection against fraud and identity theft. The cyberattack on Wolverine Solutions Group occurred on or around September 23, 2018. Critical systems were mostly restored within a month, but it has taken considerably longer to determine which clients had been affected. Some clients were only notified about the extent of the attack in March. While the types of information differ from company to company and individual to individual, the exposed information may include data elements such as names, addresses, dates of birth, social security numbers, insurance contract...
HIPAA Compliant Online Forms
Web forms offer healthcare organizations an easy way to digitally collect information from patients, but care must be taken not to violate HIPAA Rules. To collect any health data, HIPAA compliant online forms must be used. HIPAA Compliant Online Forms Must be Used for Collecting Health Information The HIPAA Privacy and Security Rules requires all HIPAA-covered entities and business associates to implement a range of safeguards to ensure the confidentiality, integrity, and availability of protected health information. Online forms are not specifically mentioned in the HIPAA text, but the Privacy and Security Rules do apply to online forms. Large healthcare organizations are more likely to have in-house staff with the skills to create forms that comply with HIPAA Rules, but many covered entities take advantage of the convenience of third-party webform solutions. There are many companies that offer HIPAA compliant online forms software that allows forms to be quickly spun up and used for a wide range of purposes such as onboarding new patients, obtaining consent, collecting payments,...
Security Risks of Medical Devices Explored by Check Point
Researchers at Check Point have demonstrated just how easy it can be to gain access to IoT medical devices and warn that the security risks of medical devices cannot be ignored. There have been major technological advances in recent years that has resulted in an explosion of new medical devices, but the IT environments that the devices are incorporated into often lack appropriate security controls. One of the main problems is many medical devices run on legacy systems and operating systems such as Windows XP, Windows 2000, and Windows 7. Those operating systems are no longer patched and contain vulnerabilities that could easily be exploited to gain access to patient data or the network to which the devices connect. Even when patches are available, applying them can be difficult and involves considerable downtime. Consequently, devices often remain unpatched and vulnerable to attack. Many healthcare providers also use medical devices from a wide range of manufacturers. Even identifying vulnerabilities and ensuring patches are applied can be a major challenge. Check Point...



