DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

Hackety hack hack…

Posted on July 4, 2021 by Dissent

There are so many breach reports that it’s hard to even find all the notices and reports about them these days. These days, there are many breaches that I log in worksheets I compile for Protenus’s Breach Barometer annual report but never even post on this blog.

Just today, for example, I found:

  • a notice from Fairbanks Cancer Physicians disclosing that their patients had been impacted by the Elekta cyberattack;
  • a notice from Dermatology Group of Arkansa disclosing that their patients had been impacted by a phishing attack;
  • a notice from CentraCare Health and Carris Health – Willmar Lakeland Clinic (formerly known as Family Practice Medical Center) disclosing that their patients had been impacted by the Netgain Technology ransomware attack; and
  • a somewhat unusual notice from Good Shepherd Centres in Canada that merited its own post.

None of the U.S. ones above have shown up in HHS’s public breach tool yet as far as I can determine.

And I am still mulling over a press release this week by Coastal Family Health Center. DataBreaches.net had broken the story of their May ransomware incident on June 11. Their press release of this week talks about some patient files being accessed. It does not come out and say that 506 GB of files with clinic, patient, and employee personal and protected health information was dumped on the dark web and the center has no idea how many people have already downloaded it all for possible misuse.  As of today, there is no report yet on HHS as to how many patients they have notified, but in addition to patients, there were many employees whose personal identity information and wage information for W-2 etc was dumped.

I understand that entities may want to downplay how serious a breach was, but there really ought to be a requirement that they disclose when they know that data has been publicly dumped so that people can factor that in when determining what they may  need to do to protect themselves now and in the future.

 


Related:

  • Protected health information of 462,000 members of Blue Cross Blue Shield of Montana involved in Conduent data breach
  • Resource: NY DFS Issues New Cybersecurity Guidance to Address Risks Associated with the Use of Third-Party Service Providers
  • TX: Kaufman County Faces Cybersecurity Attack: Courthouse Computer Operations Disrupted
  • Bombay High Court Orders Department of Telecommunications to Block Medusa Accounts After Generali Insurance Data Breach
  • Cyber-Attack On Bectu’s Parent Union Sparks UK National Security Concerns
  • Attorney General James Announces Settlement with Wojeski & Company Accounting Firm
Category: Commentaries and AnalysesHealth DataMalwarePhishing

Post navigation

← Canadian non-profit hit by malware gets help — from the threat actor
In: Air India flyer seeks damages over SITA data breach →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • Did you hear the one about the ransom victim who made a ransom installment payment after they were told that it wouldn’t be accepted?
  • District of Massachusetts Allows Higher-Ed Student Data Breach Claims to Survive
  • End of the game for cybercrime infrastructure: 1025 servers taken down
  • Doctor Alliance Data Breach: 353GB of Patient Files Allegedly Compromised, Ransom Demanded
  • St. Thomas Brushed Off Red Flags Before Dark-Web Data Dump Rocks Houston
  • A Wiltshire police breach posed possible safety concerns for violent crime victims as well as prison officers
  • Amendment 13 is gamechanger on data security enforcement in Israel
  • Almost two years later, Alpha Omega Winery notifies those affected by a data breach.
  • Court of Appeal reaffirms MFSA liability in data leak case, orders regulator to shoulder costs
  • A jailed hacking kingpin reveals all about the gang that left a trail of destruction

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • Lawmakers Warn Governors About Sharing Drivers’ Data with Federal Government
  • As shoplifting surges, British retailers roll out ‘invasive’ facial recognition tools
  • Data broker Kochava agrees to change business practices to settle lawsuit
  • Amendment 13 is gamechanger on data security enforcement in Israel
  • Changes in the Rules for Disclosure for Substance Use Disorder Treatment Records: 42 CFR Part 2: What Changed, Why It Matters, and How It Aligns with HIPAAs

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net
Security Issue: security[at]databreaches.net
Mastodon: Infosec.Exchange/@PogoWasRight
Signal: +1 516-776-7756
DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.