Ransomware and Data Destruction Attacks Dominate Healthcare Threat Landscape
A recent report from Carbon Black has revealed that 66% of healthcare organizations have experienced a ransomware attack in the past year and 45% experienced an attack in which data destruction was the main motivation behind the attack. The figures come from Carbon Black’s latest report: Healthcare Cyber Heists in 2019. Carbon Black sought input from 20 industry-leading CISOs and questioned them about the cyberattacks they had experienced in the past year, the tactics used in the attacks, and how the threat landscape is evolving. Last year was a record-breaking year for healthcare data breaches and attacks are continuing at an unprecedented level. April 2019 was the worst ever month for healthcare data breaches with 46 major breaches (500+ records) reported to the HHS’ Office for Civil Rights. “The potential, real-world effect cyberattacks can have on healthcare organizations and patients is substantial,” explained Rick McElroy, Carbon Black’s Head of Security Strategy and co-author of the report. “Cyber attackers have the ability to access, steal, and sell patient information on...
PHI Potentially Compromised at Rosenbaum Dental Group and Kingman Regional Medical Center
Kingman Regional Medical Center (KRMC) has discovered a flaw on its website resulted in the exposure of the protected health information (PHI) of certain patients. KRMC became aware of the security issue on April 8, 2019 and the website was shut down while the security problem was investigated. Assisted by a third-party computer forensics company, KRMC determined that the configuration of the website was such that unauthorized individuals may have been able to gain access to patient information. The website was housed on an isolated server, so any access to data was limited to the information stored on the server. For a small subset of patients who used the website to enter information related to their care, such as making an appointment, could have had the following information exposed: Name, date of birth, and information supplied related to a medical condition for which medical services were being requested. Affected patients were notified of the breach by mail on June 7, 2019. The KRMC website has been offline now for more than 2 months. KRMC is in the process of rebuilding the...
Mercy Health Discovers PHI of 978 Patients Was Exposed
Mercy Health, MI, has discovered a limited amount of patient data had been saved on a private server which was used for other activities such as online scheduling and electronic physician office check-ins. As a result, patient information could potentially have been accessed by unauthorized individuals. The issue has been corrected and all patient information has now been secured. The investigation did not uncover any evidence of unauthorized access or data theft, but it was not possible to rule out either with a very high degree of certainty. Patient information was accessible on the server from an unspecified date in 2014 to March 25, 2019, when the problem was detected and rectified. The security issue only affected certain individuals who had received medical services at Mercy Health facilities in Grand Rapids or Muskegon in Michigan. The types of information potentially accessed were limited to names, addresses, email addresses, and health insurance information for the vast majority of affected individuals. A limited number of patients may also have had their Social Security...
Delta Health Systems Alerts Plan Members to Exposure of SSNs Over Internet
Employees of Turlock Irrigation District in California who are members of their employer-sponsored health plan are being notified that some of their protected health information has been exposed online as a result of an error at a business associate. Delta Health Systems (DHS) provides administrative services related to the health plan and requires access to certain protected health information. Some of that information was made accessible over the internet through a link to a DHS webpage. The error was made by third-party website developer. While the website had been configured to restrict access, there was a conflicting setting which provided general access to the document which took precedence. Affected plan members have been told that their billing statement for their employee-sponsored health plan could have been accessed by unauthorized individuals during the time it was accessible over the internet. The billing statement contained the plan member’s first and last name, employer’s name and address, DHS ID number, and Social Security number. All affected members have been...
Oregon Updates Data Breach Notification Law to Include Vendors of Covered Entities
Oregon has updated its breach notification laws and has broadened the definition of consumer information, updated the definition of covered entity, and expanded the law to cover vendors. The update (Senate Bill 684) renames The Oregon Consumer Identity Theft Protection Act as The Oregon Consumer Information Protection Act, which will come into effect on January 1, 2020. The update expands the definition of personal information to include usernames and other means of identifying a consumer which would allow access to be gained to a consumer’s account, along with any method used to authenticate a user. The definition of covered entity has been updated to “a person that owns, licenses, maintains, stores, manages, collects, processes, acquires or otherwise possesses personal information in the course of the person’s business, vocation, occupation or volunteer activities.” A vendor is defined as an individual or entity “with which a covered entity contracts to maintain, store, manage, process or otherwise access personal information for the purpose of, or in connection with, providing...



