Webinar: June 18, 2019: Addressing Mental Health for Improved Community Safety
On Tuesday, June 18, 2019, Rave Mobile Safety will be hosting a webinar that aims to improve understanding of mental health issues, the challenges community members face dealing with individuals with mental health disorders, and how to account for mental health in day to day operations. Many healthcare professionals, business owners, schools, and other community members are aware of the importance of being proactive and improving mental health awareness in the community but are unsure about the best approach to take. The webinar will provide the information you need to make more of a difference and will show how improved communication and greater collaboration with first responders, 9-1-1 call takers, school administrator and other teams in the community are essential for improving understanding of people in the community suffering from mental health issues. The event will be hosted by Rave Mobile Security MPA, ENP, Vice President of Customer Success, Noah Reiter, who will be joined by former Dallas Police Chief, David Brown. Police figures show around 10% of all police calls...
Estes Park Health Ransomware Attack Highlights Risks of Paying Ransoms
Estes Park Health (EPH) in Colorado has suffered a ransomware attack that resulted in widespread file encryption across the network. The attack was noticed by employees on Sunday June 2, 2019 who reported that their computers were behaving strangely. EPH contacted its on-call IT technician who logged in and experienced the same issues, as the ransomware systematically encrypted files on the network. EPH, Chief Information Office, Gary Hall, witnessed the ransomware locking files and taking control of programs on his computer, according to a recent report in the Estes Park Trail Gazette. IT staff responded quickly and started locking systems down, but it was not possible to prevent widespread file encryption. Software in the clinic was the first to go offline, followed by its digital imaging software, which stores all X-rays and other medical images. The attack wiped out the network and its phone service. EPH activated its incident response center and switched to emergency mode procedures while its computer system was down. EPH uses software that constantly monitors the network and...
High and Critical Severity Vulnerabilities Identified in Certain BD Alaris Gateway Workstations
Two vulnerabilities have been identified in certain Becton Dickinson (BD) infusion pumps. One of the vulnerabilities is rated critical and has been given the maximum CVSS v3 score of 10 out of 10. BD has a history of proactively searching for vulnerabilities, addressing cybersecurity issues, and communicating details of the vulnerabilities in a timely fashion. BD voluntarily disclosed the two vulnerabilities in recent security bulletins and shared details of the flaws with information Sharing and Analysis Organizations (ISAOs). In this instance, the vulnerabilities were discovered by Elad Luz of CyberMDX and reported to BD. The Department of Homeland Security’s Industrial Control System Computer Emergency Response Team (ICS-CERT) has also issued a security advisory about the flaws. Both flaws affect BD Alaris™ Gateway Workstations, but not any gateway workstations that are sold or used in the United States. The affected devices are used in around 50 countries, mostly in Europe in Germany, Spain, the Netherlands, and the United Kingdom. The vulnerability affects fewer than 3,000...
Urology Practice Pays $75,000 Ransom to Regain Access to Computer Systems
Boardman, OH-based N.E.O Urology has experienced a severe ransomware attack that has impacted its entire IT system. The ransomware caused widespread file encryption and locked the healthcare provider out of its computers and patient records. While the attack was sophisticated, the notification was not. The healthcare provider was sent a fax from the attackers demanding a $75,000 ransom payment for the keys to unlock the encryption. N.E.O Urology contacted its IT service provider and after assessing options and the risks, the decision was taken to pay the ransom. The IT service provider made contact with the attackers through a third party and the ransom was paid to obtain the keys to unlock the encryption. Even with the decryption keys it took the medical practice three days to restore its computer systems due to the extent of file encryption. The breach investigation uncovered evidence to suggest the attackers were based in Russia. Payment of a ransom is not without risk. The attackers may not be able to unlock files or may choose not to do so even after the ransom is paid. The...
House Overturns Ban on HHS Funding HIPAA National Patient Identifier Development
One of the requirements of the HIPAA Administrative Simplification Rules was the development of a national identifier for all patients. Such an identifier would be used by all healthcare organizations to match patients with health records from multiple sources and would improve the reliability of health information and ensure it could be shared quickly and efficiently. That national patient identifier has failed to materialize. For the past two decades, the Department of Health and Human Services has been prohibited from using funds to develop or promote a unique patient identifier system out of concerns over privacy and security of patient data. Just as was the case in 1996, the benefits of using national patient identifiers remain and the need for such a system is greater than ever. Many hospitals, healthcare and health IT groups have been urging Congress to lift the HHS ban due to the benefits that would come from using a national identifier. They argue it would make it much easier to match medical information from multiple sources with the correct patient and the potential for...



