On November 3, 2024, WALB in Georgia reported that Memorial Hospital and Manor had been the victim of a ransomware attack on November 1 that they discovered on November 2. The hospital announced the incident on its Facebook page in a post that is no longer available. But Memorial Hospital and Manor did not appear…
Category: Breach Incidents
Elon Musk’s DOGE Posts Classified Data On Its New Website
Jennifer Bendery reports: Elon Musk’s team at the so-called Department of Government Efficiency has posted classified information about the size and staff of a U.S. intelligence agency on its new website, raising bigger concerns about where Musk’s programmers got this information and what they are doing with it. DOGE, which President Donald Trump created to…
Humboldt Independent Practice Association’s breach notification leaves questions unanswered
On November 11, 2024, Humboldt Independent Practice Association (Humboldt IPA) submitted a breach report to HHS that used a placeholder of 500 for the number of patients affected. All we knew from HHS’s entry was that it was some kind of hacking or IT incident involving protected health information located in email. The California entity’s…
Attorney General James Releases Statement on DOGE Access to Sensitive Personal Information
When DataBreaches said, “Send in the lawyers” to sue Musk, she was thinking of personal injury lawyers who handle data breach litigation. But 14 state attorneys general may be even better. From NYS Attorney General Letitia James: NEW YORK – New York Attorney General Letitia James today led a coalition of 14 attorneys general in…
Almost one year later, NorthBay Health notifies 569,012 people of breach of sensitive information
While some states are decreasing the amount of time entities have to notify the state or individuals of a breach, the reality is that many entities are nowhere near complying with even more lenient deadlines. HIPAA, for example, allows entities no more than 60 calendar days from discovery of a breach (the first day they…
Backdoor found in two healthcare patient monitors, linked to IP in China
Lawrence Abrams reports: The US Cybersecurity and Infrastructure Security Agency (CISA) is warning that Contec CMS8000 devices, a widely used healthcare patient monitoring device, include a backdoor that quietly sends patient data to a remote IP address and downloads and executes files on the device. Contec is a China-based company that specializes in healthcare technology, offering…

