From the SEC: The Securities and Exchange Commission today announced that the entity formerly known as Yahoo! Inc. has agreed to pay a $35 million penalty to settle charges that it misled investors by failing to disclose one of the world’s largest data breaches in which hackers stole personal data relating to hundreds of millions…
Category: U.S.
Data breach could impact some patients of medical lab chain with Alabama locations
Connor Sheets reports: A data breach may have resulted in the exposure of the personal and protected health information of patients of a medical lab chain with multiple Alabama locations. American Esoteric Laboratories announced Friday that it had become aware of a “data security incident” that could impact patients’ data security. An AEL employees’ company-issued laptop was…
Atlanta spent at least $2.6 million on ransomware recovery
Zack Whittaker reports: Atlanta spent more than $2.6 million on recovery efforts stemming from a ransomware attack, which crippled a sizable part of the city’s online services. The city was hit by the notorious SamSam ransomware, which exploits a deserialization vulnerability in Java-based servers. The ransom was set at around $55,000 worth of bitcoin, a…
Former gynecologist set to stand trial for patient privacy violations, lying to federal agents
Stephanie Barry reports on a case that I don’t recall ever hearing about before: Jury selection will begin this morning in the trial of Rita Luthra, a former gynecologist accused of violating patient confidentiality laws, witness tampering and lying to federal investigators. The case against Luthra, of Longmeadow, is a significantly watered-down version of the…
Transcription Service Leaked Medical Records
Brian Krebs reports: MEDantex, a Kansas-based company that provides medical transcription services for hospitals, clinics and private physicians, took down its customer Web portal last week after being notified by KrebsOnSecurity that it was leaking sensitive patient medical records — apparently for thousands of physicians. On Friday, KrebsOnSecurity learned that the portion of MEDantex’s site…
New Orangeworm attack group targets the healthcare sector in the U.S., Europe, and Asia – Symantec
There’s a new report out from Symantec that is somewhat worrying. Symantec has identified a previously unknown group called Orangeworm that has been observed installing a custom backdoor called Trojan.Kwampirs within large international corporations that operate within the healthcare sector in the United States, Europe, and Asia. First identified in January 2015, Orangeworm has also…