The following announcement by HHS OCR stems from an accidental exposure of protected health information online that continued for several years. Inmediata’s incident resulted in a class action lawsuit that was settled for $1.1 million in 2022, and a settlement with 33 states for $1.14 million in 2023. HHS seems to be the first to…
Category: Breach Incidents
Watsonville Community Hospital still dealing with November cyberattack
Watsonville Community Hospital in California is continuing to work through what they refer to as a cyberattack on November 29. The hospital’s network has been offline since then with staff reverting to “downtime” procedures using paper. The hospital has been able to continue to provide emergency, inpatient, and outpatient care but alerts patients that there…
Anna Jaques Hospital notifies 316,300 people about 2023 ransomware attack
On Christmas, December 2023, Anna Jaques Hospital (AJH) in Massachusetts was grappling with a cyberattack that knocked out their EHR system and resulted in them having to divert ambulances to other area hospitals. On January 23, they posted a preliminary website notice (archived) about the attack. That notice was posted four days after threat actors…
Trump FBI Pick Kash Patel’s Emails Accessed By Iranian Hackers: Report
David Gilmour reports: President-elect Donald Trump’s FBI director pick, Kash Patel, was informed by the agency he’ll soon lead that he’d been targeted by Iranian hackers, sources familiar with the situation revealed to CNN. Hackers reportedly accessed some of Patel’s communications, according to one source. Patel, a former chief of staff to the defense secretary during Trump’s first term, has…
Failure to terminate access can be costly. Very costly.
Earlier today, DataBreaches posted an HHS OCR announcement of a settlement with a HIPAA covered entity. A former contractor had accessed its electronic medical record system on three occasions without authorization to retrieve PHI for use in potential fraudulent Medicare claims. OCR imposed a monetary penalty of $1.19 million for the entity’s failure to: conduct…
Bolton Walk-In Clinic in Ontario: lock down your backup already!
DataBreaches hates reporting on an incident when the entity has not yet secured misconfigured storage, but after four months of futile efforts to get a Canadian clinic to respond to responsible disclosures, maybe publication will help get them off the dime. Bolton Walk-In Clinic in Ontario has a data protection policy that says: We are…