Last week, this site reported that a U.K. fertility clinic had been impacted by an attack on Stor-a-File, their document scanning vendor. This week, there was more bad news for Stor-A-File clients. Michael Powell, Molly Clayton, and Kevin O’Sullivan report that Clop threat actors have dumped sensitive files on their dark web leak site when…
Category: Health Data
A mailing error with troubling potential
We have all read about mailing errors by now. In fact, such errors are one of the biggest types of HIPAA breaches — providing one patient’s information to another, or a mail merge error, or something similar. But here’s a case in the U.K. that serves as a painful reminder that such breaches can have…
Episcopal Retirement Services suffered two ransomware attacks in a one-month period
It’s bad enough experiencing one ransomware attack. Imagine experiencing two, because that’s what Episcopal Retirement Services (ERS) in Ohio has been dealing with. On or about September 24, ERS discovered that i had been the victim of what it describes as a cyberattack that impacted its systems and servers. Then on October 22, they experienced…
Brussels health authorities deny data violation on vaccination platform
Lauren Walker reports: A legal analysis has shown Brussels’ vaccination platform Bru-Vax respects personal data, Brussels health authorities’ have announced, following criticism of a data leak regarding people’s vaccination status. Earlier this week, it was reported that people, for example, employers, insurers or banks, could find out if a Brussels resident had been vaccinated by simply entering…
Update: Eskenazi patients receive letter in the mail alerting them of cyber security breach 6 months ago
Bianca Reyes has an update on the Eskenazi ransomware incident that this site has been reporting on since August: Roughly three months after Eskenazi Health released a statement announcing a cyber security breach that compromised personal data, some patients are just now receiving that news in the mail. According to this release posted last month, Eskenazi…
Data Breach Rule for Health Apps Leaves Developers in the Dark
Christopher Brown reports: Makers of health apps are scrambling to understand the extent of their legal liability after a divided Federal Trade Commission announced they’re now required to inform users about data and privacy breaches—and if they have used their customers’ health data without authorization. The commission approved 3-2 a policy statement that the makers of health…