Back in July, DataBreaches reported on an Avamere Health Services breach. Avamere has now updated their breach notification. Their newer notice is being provided on behalf of the following entities to whom Avamere is a Business Associate as defined under the Health Insurance Portability and Accountability Act (“HIPAA”): A-One Home Health Services, LLC Avamere at…
Category: Health Data
20 million Americans in 21 states ‘are still at risk of dangerous healthcare after cyberattack’: IT breach at one of biggest hospital chains in the US has already caused overdoses, cancer delays and ambulance diversions
Caitlin Tilley reports: Twenty million Americans are at risk of ‘dangerous’ healthcare after a cyberattack at one of the country’s biggest hospital chains last month, security experts have told DailyMail.com. CommonSpirit Health — a system that runs 140 hospitals, and more than 1,000 care sites including cancer clinics, surgery hubs and stroke centers— suffered a major IT breach…
Yale Medicine discloses breach of doctor’s prior patient records system
From an incident report appearing on Yale Medicine’s website: Yale Medicine has discovered a cybersecurity incident, involving the records of patients seen by Dr. Tito Vasquez at his former practice, Connecticut Plastic Surgery Group LLC, between 2009 and May 2021. This notice concerns a data security event that may have resulted in unauthorized access to…
When was the last time you checked on the paper records you put in storage somewhere?
A cardiology practice recently discovered that early patient records stored in a basement locker had been stolen at some unknown time. Given that these were paper account ledgers, is there even a backup so that the practice will have the names and then-contact information of everyone who should be notified? Their media notice does not…
PA: Medical assistant charged with stealing and misusing patient identity information
Altoona Mirror reports on a case of insider wrongdoing: A medical assistant has been arrested on charges related to stealing patient information for personal use. Ashley Latimer, 34, of Philadelphia, used information she collected from patient records and licenses to open credit cards, purchase items and lease apartments, Attorney General Josh Shapiro said in a…
HC3: Analyst Note: Venus Ransomware Targets Publicly Exposed Remote Desktop Services
November 9, 2022 TLP: Clear Report: 202211091400 Executive Summary HC3 is aware of at least one healthcare entity in the United States falling victim to Venus ransomware recently. The threat actors behind Venus ransomware operations are known to target publicly exposed Remote Desktop Services to encrypt Windows devices. This report provides additional information, indicators of…