On August 17, 2023, SysInformation Healthcare Services, LLC, d/b/a EqualizeRCM (“SysInformation”) notified HHS of a breach. The firm, a business associate that provides revenue and billing cycle management services, reported that 501 patients had been affected. That number is generally interpreted as a placeholder marker when the entity has not yet figured out the real…
Search Results for: HCA
Blackcat may be gone, but recovery from its attacks is not over
The AlphV (aka Blackcat) ransomware group may have disappeared after a law enforcement seizure in December, and then an exit scam by its admin in March, but the impact of some of its breaches continues. While the Change Healthcare breach continues to make headlines, earlier breaches by Blackcat also continue to impact victims. In July…
Impact of Tennessee’s Cybersecurity Class Action Safe Harbor
Here are some perspectives by law firms. From SheppardMullin: Tennessee has joined a handful of other states to provide certain safe harbors in the cybersecurity realm. Unlike others, the law sites beside -but does not modify- the states’ data breach notification law. Also unlike others, the safe harbor is very narrowly tailored, and is not triggered by…
Red Tape Is Making Hospital Ransomware Attacks Worse
Matt Burgess reports: Crippling ransomware attacks against hospitals and health care providers are on the rise. These ruthless cyberattacks can take medical systems offline for weeks—canceling appointments and surgeries and causing harm to patients. Doctors and nurses are plunged into crisis situations where they resort to using pen and paper, while IT staff work to make…
Breach Notification Laws
There is no one overarching federal data breach notification law in the U.S. Attempts to pass one are opposed by those who do not want a federal law to pre-empt stronger state laws. While industry giants may support a federal law if it pre-empts state laws, they do not support any proposal that provides individuals…
PruittHealth was hacked back in November. Here’s what we STILL don’t know.
What happens when threat actors leak data on the dark web but the victim entity doesn’t access it in time to figure out what was leaked? That’s what happened to PruittHealth in Georgia last year. How many people are they notifying because they can’t figure out what was accessed, acquired, or leaked? In November 2023,…