Remedy Medical Group is a pain management specialty practice in California. Their web site indicates that they are consultants to some professional sports teams in their area. Did a breach involving some of their patients’ data also impact any prominent athletes who might receive extortion demands? At this point, there is no indication of any…
Category: Subcontractor
Class action lawsuit filed against Roper St. Francis Healthcare over multiple data breaches
Regular readers may recall that September, 2020 was not a good month for St. Roper Francis, and DataBreaches.net had to explain that the healthcare system was dealing with notifications from two unrelated breaches. One involved 6,000 patients impacted by a hack of an employee’s email account. The other involved more than 90,000 patients impacted by…
Good Luck Explaining to HHS Why Your PHI is in GitHub’s Vault for the Next 1,000 Years
You may see a number of hospitals and covered entities issuing statements this week about a data security incident involving Med-Data (Med-Data, Incorporated). So far, Memorial Hermann, U. of Chicago, Aspirus, and OSF Healthcare have posted notices. Others should be or may be posting soon. Here’s DataBreaches.net’s exclusive report on the incident. Another Day, Another…
University of Maryland, Baltimore responds to Accellion breach
This week, a number of universities were added to CLOP threat actors’ dark web leak site. They appear to be linked to the Accellion breach in December and January. As a reminder, many of Accellion’s clients used a standalone server with Accellion’s software to transfer large files. The attack did not hit Accellion’s clients’ own…
Update on education sector clients impacted by Blackbaud ransomware incident
I don’t know how he finds the energy to do it, but Marco A. DeFelice (@amvinfe on Twitter) continues to track disclosures involving Blackbaud’s ransomware incident of 2020. He has organized his tabulations by whether the entities are hospitals or educational facitlities, etc. Today he has provided another update to the education sector, in which…
GA: Cyberattack on Cobb schools enabled by contractor’s weak password, police say
Kristal Dixon reports: An attack on the Cobb County School District’s crisis management system that forced all schools into lockdown last month happened because of a weak password, according the police. The password was not created by a school district employee, but a worker with the AlertPoint security system used by the district, police said….