Children’s medical alerts and health conditions may be breached in so many ways outside of the healthcare sector. Schools, sports clubs, camps, and yes, boy scouts and girl scouts, are just some of the organizations that may hold sensitive information that gets breached, with no report needed to HHS. Alejandra Reyes-Velarde reports: Members of the…
Category: U.S.
Security company sued after alleged information leak
Oops. I missed this one when WTOC first reported it on October 17th: Dozens of social security numbers connected to work hours and rates of pay are at risk of being used by criminals because of the actions of a security firm supervisor. Those are the allegations in a lawsuit filed by a Savannah law…
Cyber attack exposed information for 40,000 patients of Sioux City vision clinic
Mason Doktor reports that Jones Eye Clinic and CJ Elmwood Partners, L.P., an affiliated surgery center, experienced a ransomware attack on the evening of August 22. The attack affected 40,000 patients seen between Jan. 1, 2003 and Aug. 23. The providers were able to restore from backup and did not pay any ransom. Their full notice…
Data leak at consulting firm handling fundraisers for the Democratic party
Catalin Cimpanu reports: A Maryland consulting firm that handles political fundraisers for the Democratic Party has left fundraiser data and passwords to databases storing voter records exposed online via an unsecured network attached storage (NAS) device. The exposed data was found last week by Bob Diachenko, Director of Cyber Risk Research at Hacken, a cyber-security…
Byram Healthcare notifies patients about rogue insider incident
Byram Healthcare is a firm that provides disposable medical supplies. They were acquired in 2017 by Owens & Minor. On October 22, Byram sent notification letters to patients whose data may have been stolen and/or misused by a former employee. Byram learned of the former employee’s wrongdoing when they were contacted by law enforcement. In…
Update: TIO Networks notifies consumers of breach going back to 2014 or earlier
TIO Networks USA was acquired by PayPal in July, 2017. Months later, they reported, services were suspended after discovery of vulnerabilities. Investigation into those vulnerabilities resulted in TIO having to report that it had been hacked by 2014 and possibly earlier. According to information provided in December, 2017, 1.6 million consumers were affected. From their…