HHS has announced another Security Rule enforcement action. This one involves iHealth Solutions (dba Advantum Health), a business associate. The incident involved an unsecured server where protected health information of patients was exfiltrated. The iHealth incident had been discovered by Kromtech Security and was first reported by DataBreaches on May 9, 2017. On May 10,…
LetMeSpy, a phone tracking app spying on thousands, says it was hacked
Zack Whittaker reports: A hacker has stolen the messages, call logs and locations intercepted by a widely used phone monitoring app called LetMeSpy, according to the company that makes the spyware. The phone monitoring app, which is used to spy on thousands of people using Android phones around the world, said in a notice on its…
Sweetwater Union High School District now admits February outage was a hack, but still hasn’t answered questions
There’s an update to a report in February about an outage that wasn’t described at the time as a hack or ransomware attack. Laura Acevedo reports: The Sweetwater Union High School District has confirmed a hack was the cause of a days-long system outage at their facilities, saying the personal information of employees, students, and families…
MOVEit breach also impacted major pension systems and insurers
Cathie Anderson of The Sacramento Bee reported that the nation’s two biggest pension systems were impacted by the MOVEit breach: The California Public Employees’ Retirement System reported Wednesday that hackers stole the names, social security numbers, birth dates and other confidential information of roughly 769,000 retirees and beneficiaries….. CalSTRS, the nation’s second-largest, said Thursday it, too,…
NYC schools disclose student and staff information affected by MOVEit breach; National Student Clearinghouse silent on question of extortion payment
Jessica Gould reports: The New York City Department of Education estimates that the personal data of some 45,000 students was compromised as part of a breach involving the file transfer software MOVEit. Officials said the compromised data includes social security numbers, birth dates and certain student evaluations, though the specific types of data breached varies…
Four senior residences in Pennsylvania disclose a data security breach in April
Four senior residences have disclosed that they were the victims of a network intrusion in April that may have compromised residents’ personal and protected health information. Senior Choice, Inc., dba The Atrium in Johnstown, Beacon Ridge in Indiana, and The Patriot in Somerset reported an incident that occurred between April 18 and April 23. The…