calHIPAA

Promoting HIPAA Compliance For Over 20 Years

  • HIPAA News
  • HIPAA Advice
  • HIPAA Compliance
    • HIPAA Law
  • HIPAA Violations
    • HIPAA Penalties
    • Social Media HIPAA Violation Examples
  • HIPAA Training
  • About calHIPAA
HomeHIPAA News

HIPAA News

The HIPAA News category delivers timely and authoritative updates on the latest developments in HIPAA regulations and enforcement. This section is dedicated to providing healthcare professionals, compliance officers, and business associates with critical information on recent regulatory changes, legal rulings, and enforcement actions related to the protection of protected health information (PHI).

Our news coverage focuses on significant events and trends within the healthcare industry that impact HIPAA compliance. By staying informed on these developments, you can better anticipate regulatory shifts and ensure that your organization remains compliant with evolving privacy and security requirements under HIPAA.

4 Vulnerabilities Found in Baxter & Sigma Spectrum Infusion Pumps

September 13, 2022 Christine Garcia

Rapid 7 researchers found four vulnerabilities in Baxter and Sigma Spectrum infusion pumps. These devices are employed to supply patients with medications and nutrition. These TCP/IP enabled-devices are typically linked to healthcare networks. Vulnerabilities can […]

Lamoille Health Partners Faces Class Action Lawsuit Due to 58K-Record Data Breach

September 9, 2022 Christine Garcia

The healthcare provider based in Morristown, VT, Lamoille Health Partners, is dealing with a class action lawsuit because of a ransomware attack in June 2022 that impacted approximately 60,000 patients. Lamoille Health Partners discovered the […]

OIG Requires Better Oversight of the Organ Procurement and Transplantation Network Cybersecurity

September 8, 2022 Christine Garcia

The HHS’ Office of Inspector General (OIG) has required the Health Resources and Services Administration (HRSA) to enhance supervision of the cybersecurity of the Organ Procurement and Transplantation Network (OPTN). The OPTN is a nationwide […]

Several Vulnerabilities Found in Vital Signs Patient Monitors of Contec Health

September 7, 2022 Christine Garcia

Five vulnerabilities were found in CMS8000 CONTEC ICU CCU Vital Signs Patient Monitor of Contec Health. A threat actor could exploit the vulnerabilities to carry out a denial-of-service attack, gain access to a root shell, […]

PHI Compromised in Breaches at CorrectHealth, Peter Brasseler, and UF Health Shands

September 6, 2022 Christine Garcia

CorrectHealth Notifies 54,000 Patients About the Email System Breach in November 2021 CorrectHealth based in Alpharetta, GA is sending notifications to patients regarding a breach of its email accounts. The security breach was identified on […]

HC3 Alert About Evil Corp. Cybercrime Syndicate Attack on Healthcare Sector

September 2, 2022 Christine Garcia

The Health Sector Cybersecurity Coordination Center (HC3) is alerting the healthcare and public health sector (HPH) regarding one of the ablest and hostile cybercrime syndicates presently active – Evil Corp. The group works from Russia […]

Class Action Lawsuit Filed Against Avamere Holdings Due to 2022 Cyberattack

September 1, 2022 Christine Garcia

Avamere Holdings based in Wilsonville, OR, a provider of home health care services and operator of a nursing home, is dealing with a class action lawsuit due to a serious data breach that impacted 96 […]

EmergeOrtho & General Health System Suffer Ransomware Attacks

August 31, 2022 Christine Garcia

EmergeOrtho, an orthopedic practice in North Carolina, has just informed 75,200 patients that unauthorized individuals accessed some of their protected health information (PHI). As per the substitute breach notice posted by EmergeOrtho, the practice detected […]

HC3 Gives Warning on Karakurt Threat Actors’ Data Theft and Extortion Attacks

August 30, 2022 Christine Garcia

The Department of Health and Human Services’ Health Sector Cybersecurity Coordination Center (HC3) has released an alert to the Healthcare and Public Health Sector (HPH) regarding a fairly new ransom threat group named Karakurt, which […]

Humana & Cotiviti Resolves Class Action Data Breach Lawsuit

August 26, 2022 Christine Garcia

Humana & Cotiviti have decided to resolve a class action lawsuit and the claims from people impacted by a data breach in 2020 that compromised the protected health information (PHI) of 64,654 people. Humana had […]

Data Breaches Reported by the Onyx Technologies, New Jersey Department of Health, & San Diego American Indian Health Center

August 25, 2022 Christine Garcia

Onyx Technologies based in Largo, MD, a company offering Information Technology and Consulting Services and a vendor of Independent Care Health Plan (iCare), recently informed 96,814 health plan members about the potential compromise of some […]

Healthcare Data Breach Report in July 2022

August 24, 2022 Christine Garcia

July 2022 had 66 healthcare data breaches affecting 500 and up records reported to the Department of Health and Human Services Office for Civil Rights. This figure is 5.71% less than the 70 data breach […]

Digital Marketing and Analytics Firm Files Lawsuit Against FTC Due to Alleged Privacy Violations

August 19, 2022 Christine Garcia

A digital marketing and analytics company based in Idaho filed a lawsuit against the Federal Trade Commission for allegedly violating the Federal Trade Commission (FTC) Act with its data practices. Kochava’s principal business unit offers […]

PHI Exposed Due to Breaches at Practice Resources and Valley Baptist Medical Center

August 18, 2022 Christine Garcia

Practice Resources based in Syracuse, NY provides billing and other professional services. It encountered a data breach that affected the data of 942,138 persons. The breach notification provided to the California Attorney General indicated that […]

Data Breaches at Priority Health, Living Innovations, and Florida Springs Surgery Center

August 17, 2022 Christine Garcia

The health plan provider Priority Health based in Michigan has reported that it was affected by a data breach that occurred at a business associate, the law agency Warner Norcross & Judd (WNJ). Steps were […]

CISA Issues Warning on Zeppelin Ransomware Attacks on Healthcare Organizations

August 16, 2022 Christine Garcia

The Federal Bureau of Investigation (FBI) and the U.S. Cybersecurity and Infrastructure Security Agency (CISA) have released a joint security advisory concerning the extensive attack on organizations in the healthcare and medical sectors by the […]

Information on the New Draft of the ADPPA Law

August 13, 2022 Christine Garcia

The American Data Privacy and Protection Act (ADPPA) presented in June was considerably revised in just a few days. Then, last month there was a new draft of ADPPA law presented having more changes. The […]

Security Breaches at Zenith American Solutions, Centerstone, and Southwest Behavioral & Health Services

August 12, 2022 Christine Garcia

Zenith American Solutions, the Sound Health and Wellness Trust’s third-party manager, recently advised people regarding a mailing error that compromised their Social Security numbers of the people. Based on the breach notification, the company sent […]

Salinas Valley Memorial Healthcare Paid $340K to Resolve Email Data Breach Lawsuit

August 11, 2022 Christine Garcia

Salinas Valley Memorial Healthcare System based in California has decided to negotiate a class action lawsuit by paying $340,000 to settle claims from patients impacted by the email security breach in 2020. From April 30, […]

Updates About the Cyberattacks on Behavioral Health Group and Goodman Campbell Brain and Spine

August 10, 2022 Christine Garcia

Additional information was recently published regarding two cyberattacks on healthcare companies: Behavioral Health Group and Goodman Campbell Brain and Spine. Behavioral Health Group Reports Potential Compromise of Patient Data in December 2021 Cyberattack Behavioral Health […]

Dental Care Alliance Pays $3 Million to Settle Class Action Data Breach Lawsuit

August 9, 2022 Christine Garcia

Dental Care Alliance decided to resolve a class action lawsuit filed due to a data breach that affected approximately 1.7 million people. A $3 million fund was reserved to cover claims from persons impacted by […]

Fast Track Urgent Care Reports 258,411 Persons Impacted by 2021 PracticeMax Ransomware Attack

August 5, 2022 Christine Garcia

Fast Track Urgent Care, an urgent healthcare clinic network in Florida, has announced that the protected health information (PHI) of 258,411 persons was exposed and possibly stolen due to a ransomware attack on PracticeMax, a […]

More Class Action Lawsuit Versus Meta for Using Meta Pixel Code on Hospital Sites

August 4, 2022 Christine Garcia

Meta is dealing with one more class action lawsuit because of the illegal collection and disclosure of health information with no content. The Northern District of California received the filed lawsuit on behalf of the […]

Avamere Data Breach Affects 96 Senior Living and Healthcare Facilities

August 3, 2022 Christine Garcia

A big data breach was reported that has impacted many healthcare, senior living and rehabilitation centers in Arizona, Oregon, Nevada, Colorado, Utah, and Washington, which are managed by organizations that belong to the group Avamere […]

Survey Indicates Bad Cyber Security and Weak Password Practices

August 2, 2022 Christine Garcia

Almost all Americans are confident regarding their understanding of cybersecurity as per the latest AT&T study of 2,000 People in America. Nevertheless, bad cyber hygiene and poor password strategies remain a usual thing. OnePoll performed […]

Cloud Security Alliance Publishes Third Party Vendor Risk Management Guidance to Help Healthcare Providers

July 29, 2022 Christine Garcia

Cybercriminals are increasingly attacking business associates of HIPAA-covered entities because of the ease of accessing the systems of a number of healthcare providers. To help healthcare delivery organizations (HDOs) manage the situation, the Cloud Security […]

HC3 Gives Alert about Risk of Web Application Attacks on Healthcare Companies

July 28, 2022 Christine Garcia

The Department of Health and Human Services’ Health Sector Cybersecurity Coordination Center (HC3) has released information to assist healthcare companies to be protected against web application attacks. In recent years, web applications have increased in […]

Data Breaches Reported by Blue Cross and Blue Shield of Massachusetts and Blue Shield of California

July 27, 2022 Christine Garcia

Blue Cross and Blue Shield of Massachusetts (BCBSofMA) has just confirmed that a data breach at a business associate resulted in the exposure of the protected health information (PHI) of a number of its health […]

Healthcare Data Breach Report in June 2022

July 26, 2022 Christine Garcia

In June 2022, 70 healthcare data breaches involving 500 or higher records were reported to the Department of Health and Human Services’ Office for Civil Rights (OCR). This number is two less than May and […]

NIST Revised Guidance on Compliance with the HIPAA Security Rule

July 22, 2022 Christine Garcia

The National Institute of Standards and Technology (NIST) has made updates to its guidance for HIPAA-covered entities on enforcing the HIPAA Security Rule to better secure patients’ personal data and protected health information (PHI). The […]

The Methodist Hospitals Pays $425,000 to Settle Class Action Data Breach Lawsuit

July 21, 2022 Christine Garcia

The Methodist Hospitals Inc decided to resolve a class action lawsuit and allocated a $425,000 fund for claims filed by victims in relation to a data breach in 2019 that impacted about 70,000 patients. The […]

Study Reveals Security Awareness Training Considerably Minimizes Risks to Phishing Attacks

July 20, 2022 Christine Garcia

A new Phishing by Industry Benchmarking Report showed that giving security awareness training to the employees considerably lowers risks to phishing attacks. KnowBe4 conducted the study to find out how helpful security awareness training is […]

Oklahoma State University Pays $875,000 to Resolve HIPAA Case with OCR

July 19, 2022 Christine Garcia

The Department of Health and Human Services’ (HHS) Office for Civil Rights (OCR) has reported that Oklahoma State University – Center for Health Sciences (OSU-CHS) has decided to negotiate a HIPAA investigation arising from the […]

Health Aid of Ohio Resolves Class Action Lawsuit Due to Data Breach

July 14, 2022 Christine Garcia

Health Aid of Ohio has decided to resolve a class action lawsuit to handle claims concerning its inability to secure the sensitive personal data of its clients. Health Aid of Ohio based in Parma, OH […]

Senators Require Change in HIPAA Privacy Rule to Forbid Disclosures of Reproductive Health Care Data to Law Enforcement

July 12, 2022 Christine Garcia

The HHS’ Office for Civil Rights has lately released guidance to healthcare companies after the overturning of Roe v. Wade subsequent to the SCOTUS Dobbs v. Jackson Women’s Health Organization judgment, which took away the […]

Feds Tell about Threat of Maui Ransomware Attacks Conducted By North Korean State-Sponsored Hackers

July 8, 2022 Christine Garcia

The Federal Bureau of Investigation (FBI), the Department of the Treasury, and Cybersecurity and Infrastructure Security Agency (CISA) issued a joint security advisory to the healthcare and public health industry about the risk of Maui […]

Google Announces New Measures to Safeguard User Privacy on Healthcare Matters

July 7, 2022 Christine Garcia

Google has stated that it is going to take steps to improve privacy protections for end users of its services. Google has always recommended an extensive, national privacy law covering consumer data to make sure […]

FBI, FinCEN, and CISA Release an Alert Regarding the MedusaLocker Ransomware

July 6, 2022 Christine Garcia

The Department of the Treasury, Federal Bureau of Investigation (FBI), Cybersecurity and Infrastructure Security Agency (CISA), and the Financial Crimes Enforcement Network (FinCEN) have released a joint cybersecurity warning regarding the MedusaLocker ransomware. The MedusaLocker […]

Senators Question Mental Health App Companies Regarding Privacy and Data Sharing Practices

July 5, 2022 Christine Garcia

Senators Cory Booker (D-NJ), Ron Wyden (D-OR), and Elizabeth Warren (D-MA) have written to two prominent mental health app companies and sought responses regarding their practices on data collection and sharing. There were several reports […]

GAO: HHS Must Create System for Getting Comments on HIPAA Data Breach Reporting Process

July 1, 2022 Christine Garcia

The Government Accountability Office (GAO) has advised the Department of Health and Human Services (HHS) to create a feedback system to enhance the efficiency of its data breach reporting procedure. The Health Information Technology for […]

MCG Health Faces Multiple Class Action Lawsuits Over Data Breach

June 30, 2022 Christine Garcia

Hearst Health subsidiary, MCG Health based in Seattle, is facing multiple class-action lawsuits due to a data breach that impacted approximately 10 healthcare companies such as Lenoir Health Care, Indiana University Health, Jefferson County Health […]

Data Breach Reported by Acorda Therapeutics, TridentCare, and Avamere Health Services

June 28, 2022 Christine Garcia

Acorda Therapeutics Reports Email Account Breach The biotechnology firm Acorda Therapeutics based in Ardsley, NY reported that an unauthorized third party acquired access to its email system and possibly viewed email messages and file attachments […]

University of Pittsburgh Medical Center Paid $450,000 to Settle Data Breach Lawsuit

June 24, 2022 Christine Garcia

University of Pittsburgh Medical Center has made the decision to negotiate a class action data breach lawsuit. It will set aside $450,000 to pay for claims from persons who have had losses because of the […]

PHI Exposed Due to Hacking Incidents in 3 HIPAA-Regulated Entities

June 23, 2022 Christine Garcia

PHI of Approximately 69,000 Persons Compromised in Comstar Hacking Incident Comstar based in Rowley, MA provides ambulance invoicing, collection, ePCR Hosting, and client/patient services. It found out that an unauthorized third-party acquired access to selected […]

Data Breaches at Central Florida Inpatient Medicine and Yale New Haven Hospital

June 22, 2022 Christine Garcia

Recently, Central Florida Inpatient Medicine (CFIM) based in Lake Mary, FL has found that an unauthorized person has accessed the email account of a staff member. The compromised emails and file attachments may contain the […]

Bill Wishes to Prohibit Data Brokers from Selling Health and Location Data

June 21, 2022 Christine Garcia

A new bill has been launched by Sen. Elizabeth Warren (D-MA) that wishes to prohibit data brokers from selling the health and location information of Americans. The bill called The following senators co-sponsored the Health […]

Texas Tech University Health Sciences Center and Baptist Health Report Data Breach

June 17, 2022 Christine Garcia

Texas Tech University Health Sciences Center has announced the compromise of the protected health information (PHI) of 1,290,104 patients due to a data breach that occurred at Eye Care Leaders, its electronic medical record provider. […]

Shields Health Care Group Faces Class Action Lawsuit Over 2 Million-Record Data Breach

June 16, 2022 Christine Garcia

Shields Health Care Group is facing a class-action lawsuit over the 2 million-record data breach it recently announced. This is the largest healthcare data breach ever reported for this year. Shields Health Care Group is […]

Yuma Regional Medical Center Ransomware Attack Impacts 700,000 Patients

June 15, 2022 Christine Garcia

Yuma Regional Medical Center (YRMC) based in Arizona has stated that it suffered a ransomware attack in April. The threat actors obtained the protected health information (PHI) of around 700,000 current and past patients. Based […]

Healthcare Ransomware Attacks Rose by 94% in 2021

June 10, 2022 Christine Garcia

The 2022 State of Ransomware Report published by cybersecurity firm Sophos revealed that ransomware attacks on healthcare providers increased by 94% year over year. The report based its information on a worldwide survey participated by […]

Atlassian Releases Patch for Maximum Severity Extensively Exploited Vulnerability in Confluence Server and Data Center

June 9, 2022 Christine Garcia

Atlassian has announced a patch to correct a critical zero-day vulnerability that impacts all supported versions of Confluence Server and Data Center. The vulnerability, which is tracked as CVE-2022-26134 has a maximum CVSS severity score […]

Unofficial Patch Released for DogWalk Zero-day Windows MSDT Vulnerability

June 8, 2022 Christine Garcia

There is a new zero-day vulnerability discovered that impacts a Windows tool like Follina. Although there’s no information if the vulnerability was exploited in the wild, it is possible to exploit it. The recent attention […]

Healthcare Companies Cautioned About Critical Vulnerabilities Identified in Illumina Devices

June 7, 2022 Christine Garcia

Five vulnerabilities were discovered in the Illumina Local Run Manager (LRM), which is utilized by Illumina Researcher Use Only (ROU) instruments and Illumina In Vitro Diagnostic (IVD) devices. The impacted instruments are employed for clinical […]

Class Action Lawsuit Filed Against Injured Workers Pharmacy Because of Email Account Breach

June 3, 2022 Christine Garcia

The law firm Morgan & Morgan filed a class-action lawsuit in the U.S. District Court for the District of Massachusetts against Injured Workers Pharmacy (IWP) in association with a breach of the personal records of […]

New York Judge Drops Class Action PACS Data Breach Case for Insufficient Standing

June 2, 2022 Christine Garcia

A New York Federal Judge dismissed a class-action lawsuit filed against Alliance HealthCare Services and NorthEast Radiology PC because of a data breach that compromised the protected health information (PHI) of above 1.2 million people […]

BJC HealthCare and Cooper University Health Care Report Email Account Breach

June 1, 2022 Christine Garcia

BJC HealthCare, a not-for-profit healthcare company located in St. Louis, MO, has begun informing a number of patients that an unauthorized individual accessed some of their protected health information (PHI) that was kept in email […]

Study Recognizes Risks Related to 3rd and 4th Party Scripts on Websites

May 31, 2022 Christine Garcia

A recent study conducted by Source Defense analyzed the risks related to using third- and fourth-party codes on online sites. They found that all modern, active websites had code that can be targeted by attackers […]

Washington University School of Medicine & Oswego County Opportunities Report Email Incidents

May 27, 2022 Christine Garcia

Oswego County Opportunities (OCO) in New York has reported that an unknown actor has recently accessed a small number of staff email accounts. OCO discovered the security breach because of notable suspicious email activity and […]

Sensitive Data of Breast Cancer Patients Compromised Because of Misconfiguration in AWS S3 Bucket

May 26, 2022 Christine Garcia

Researchers found out that a misconfigured AWS S3 bucket is exposing information. This cloud storage is owned by Breastcancer.org, a breast cancer support charity located in Ardmore, PA. SafetyDetectives learned that the unsecured AWS bucket […]

Healthcare Data Breach Report in April 2022

May 25, 2022 Christine Garcia

After four consecutive months of decreasing figures of data breaches, reported data breaches increased by 30.2%. In April 2022, the Department of Health and Human Services’ Office for Civil Rights (OCR) received 56 data breaches […]

Data Breaches at Parker-Hannifin, Vail Health, Behavioral Health Partners of Metrowest

May 24, 2022 Christine Garcia

Parker-Hannifin Cyberattack Affects About 120,000 Health Plan Members Parker-Hannifin Corporation based in Cleveland, OH, a company offering motion and control technologies, lately announced that unauthorized people have obtained access to a section of its IT […]

Top 10 Security Vulnerabilities Exploited by Attackers

May 20, 2022 Christine Garcia

Based on the latest security advisory released by the Five Eyes Cybersecurity agencies in the U.K., U.S., Australia, Canada, and New Zealand, the most frequent attack vectors cyber threat actors use for preliminary access to […]

Cyberattacks Reported by NuLife Med LLC and FPS Medical Center

May 19, 2022 Christine Garcia

The medical equipment organization NuLife Med LLC based in Manchester, NH, has just announced that it encountered a cyberattack in March 2022. It discovered suspicious network activity on or approximately March 11, 2022, and took […]

AvosLocker Professed to Have Conducted the Christus Health Ransomware Attack

May 18, 2022 Christine Garcia

The nonprofit health system Christus Health based in Irving, TX operates over 600 healthcare establishments in Arkansas, Texas, New Mexico, and Louisiana. It has been reported recently that it discovered suspicious activity with its computer […]

Thousands of Patients Affected by Eye Care Leaders Hacking Incident

May 17, 2022 Christine Garcia

Unauthorized persons have acquired access to the computer systems of Eye Care Leaders, which is an electronic health records and patient management software solutions provider for eye care clinics. On or around December 4, 2021, […]

HC3 Shows Developments in Ransomware Attacks on the HPH Sector

May 13, 2022 Christine Garcia

The tactics, techniques, and procedures (TTPs) employed by ransomware and other cyber attackers are always changing to elude identification and enable the groups to carry out more successful attacks. The Department of Health and Human […]

Bill Presented to Help Strengthen Medical Device Cybersecurity

May 12, 2022 Christine Garcia

A new bill was presented to address the issue of cybersecurity of medical devices that will necessitate makers of medical devices to satisfy particular minimum criteria for cybersecurity with regard to the complete lifecycle of […]

Partnership Health Plan & Oregon Anesthesiology Group Face Class Action Lawsuits Over Ransomware Attacks

May 11, 2022 Christine Garcia

Class action lawsuits were lately filed against Oregon Anesthesiology Group and Partnership Health Plan in Northern California because of ransomware attacks that resulted in the theft of sensitive patient/plan member information. Partnership Health Plan of […]

Email Security Report Submitted by HealthPlex and Optima Dermatology

May 10, 2022 Christine Garcia

Healthplex Inc., one of the largest dental insurance providers located in New York state, has announced the compromise of an employee’s email account during a phishing attack on November 24, 2021. Upon discovery of the […]

NIST Issues Updated Cybersecurity Supply Chain Risk Management Guidance

May 9, 2022 Christine Garcia

The National Institute of Standards and Technology (NIST) released an updated version of the cybersecurity supply chain risk management (C-SCRM) guidance to aid businesses in developing an effective plan for identifying, evaluating, and responding to […]

Password Security and Management Guidelines

May 6, 2022 Christine Garcia

Making and remembering long, complicated passwords is hard for many individuals, and it is made even more difficult because of the need to make passwords to protect several accounts – A study by NordPass advises […]

World Password Day and the Importance of Passwords

May 5, 2022 Christine Garcia

May 5, 2022 is World Password Day. This event was established in 2013 and is observed every first Thursday of May with the objective of bettering understanding of the value of using complex and unique […]

Which Vulnerabilities are the Most Exploited in 2021

May 4, 2022 Christine Garcia

The Five Eyes security agencies, a group of intelligence agencies from Canada, Australia, New Zealand, the United States, and the United Kingdom have released a joint advisory regarding the 15 vulnerabilities in software programs and […]

Cyber Attacks Reported by Smile Brands Ransomware Attack and ArCare

April 28, 2022 Christine Garcia

Smile Brands located in Irvine, CA offers support services for dental clinics. It just gave a new report on the number of persons affected by a ransomware attack, which was uncovered on April 24, 2021. […]

Five Eyes Agencies Alert Critical Infrastructure Orgs Regarding Danger of Russian State-Sponsored and Criminal Cyberattacks

April 27, 2022 Christine Garcia

The five eyes cybersecurity agencies have lately published a joint security advisory regarding the danger of cyberattacks on critical infrastructure carried out by pro-Russia cybercriminal groups and Russian nation-state threat actors. Intelligence collected by the […]

PHI Compromised in Security Breaches at Georgia Pines CSB and Ballad Health

April 26, 2022 Christine Garcia

Georgia Pines CSB and Ballard Health recently reported security breaches that affected the protected health information (PHI) of 28,295 people. Ballad Health Finds Breach Involving Employee Email Account Ballard Health, an integrated community health improvement […]

FBI Gives an Alert Regarding the BlackCat Ransomware Operation

April 25, 2022 Christine Garcia

The Federal Bureau of Investigation (FBI) has given a TLP: WHITE flash notification regarding the BlackCat ransomware-as-a-service (RaaS) operation. BlackCat, also called ALPHAV, which began in November 2021. It was released immediately after the shutdown […]

HHS Releases Alert to HPH Sector regarding Hive Ransomware

April 22, 2022 Christine Garcia

The HHS’ Office of Information Security Health Sector Cybersecurity Coordination Center (HC3) has released a TLP: White alert concerning the Hive ransomware gang – A specifically hostile cybercriminal operation that has substantially attacked the healthcare […]

Healthcare Data Breach Report for March 2022

April 21, 2022 Christine Garcia

For the fourth month now, there has been a drop in the number of reported healthcare data breaches. March 2022 had 43 healthcare data breaches involving 500 and up records reported to the U.S. Department […]

Newman Regional Health and Contra Costa County Report Email Account Breaches

April 20, 2022 Christine Garcia

Newman Regional Health (NRH), which manages a 25-bed critical access hospital located in Emporia, KS, has lately begun informing 52,224 individuals that unauthorized persons have acquired access to selected employee email accounts containing protected health […]

SuperCare Health Faces Legal Action Regarding 318,000-Record Data Breach

April 19, 2022 Christine Garcia

Legal action was taken versus the in-home respiratory care company, SuperCare Health, because of a cyberattack and information breach report sent to the Department of Health and Human Services as of March 28, 2022. The […]

Resources for Human Development, Tague Family Practice and Central Vermont Eye Care Report Data Breaches

April 15, 2022 Christine Garcia

Resources for Human Development Breach Impacts 46,673 Persons Resources for Human Development (RHD), a national human services non-profit group based in Philadelphia, PA, has recently reported the theft of a hard drive that contains the […]

JekyllBot:5 Vulnerabilities Permit Hackers to Control Aethon TUG Hospital Robots

April 14, 2022 Christine Garcia

There were five zero-day vulnerabilities found in Aethon TUG autonomous mobile robots, which hospitals around the world use for transporting products, medicines, and other medical items. Hospital robots are alluring targets for hackers. When access […]

Alert Issued Concerning Phishing Campaigns Affecting Legit Email Marketing Service

April 13, 2022 Christine Garcia

Due to the latest data breach at Mailchimp, the Department of Health and Human Services’ Health Sector Cybersecurity Coordination Center (HC3) gave an alert regarding the risk of phishing attacks utilizing this email marketing service. […]

FDA Launches Up-to-Date Guidance on Healthcare Device Cybersecurity

April 12, 2022 Christine Garcia

The U.S. Food and Drug Administration (FDA) has released new draft guidance to help medical device companies integrate cybersecurity features into their merchandise at the premarket phase, and to make sure safety risks are taken […]

Charleston Area Medical Center and Advanced Medical Practice Management Report Data Breaches

April 11, 2022 Christine Garcia

Charleston Area Medical Center Breach Had 54,000 Victims Charleston Area Medical Center (CAMC) located in Charleston, WV, has just announced a phishing attack that allowed unauthorized individuals to get access to the email accounts of […]

Cyberattack on SuperCare Health and Englewood Health

April 8, 2022 Christine Garcia

SuperCare Health based in Downey, CA, a provider of post-acute, in-home respiratory care in the Western United States, recently began informing 318,379 individuals about the exposure of some of their protected health information (PHI) and […]

Warnings Released Regarding Vulnerabilities in the Spring Application Building Platform and UPS Devices

April 7, 2022 Christine Garcia

Two remote code execution vulnerabilities were discovered in the Spring platform – a well-known application framework utilized by software creators for quickly creating Java apps. Proof-of-concept exploits for the two vulnerabilities can be found in […]

Audit of the Connecticut Health Insurance Exchange Reveals 44 Unreported Data Breaches

April 6, 2022 Christine Garcia

An audit of Health Insurance Exchange of Connecticut, Access Health CT, by the state auditor indicated that Access Health CT experienced 44 data breaches in the period of 3.5 years and did not completely report […]

Ransomware Gangs Claim to Have Attacked Health Plan and Healthcare Provider

April 5, 2022 Christine Garcia

Partnership Health Plan of California Getting back from Alleged Ransomware Attack The nonprofit managed care health plan based in Fairfield, CA, Partnership Health Plan of California (PHC), experienced a cyberattack that resulted in the shut […]

Abuse and Fraud in the Health Care Sector

April 1, 2022 Christine Garcia

$7 Billion Lost Every Year Because of Fraud Rep. Ted Archer explained a Congressional Report to the House Ways and Means Committee in March 1996. The report exposed the degree of abuse and fraud in […]

CSI Laboratories and Christie Clinic Report Data Breaches

March 31, 2022 Christine Garcia

Conti Ransomware Gang Owns Responsibility for CSI Laboratories Cyberattack Cytometry Specialists, Inc. also known as CSI Laboratories in Alpharetta, GA, has lately announced that it encountered a cyberattack that was noticed on February 12, 2022. […]

Dental Practices Fined for Violation of HIPAA Rules

March 30, 2022 Christine Garcia

$50,000 Civil Monetary Penalty Paid by Dental Practice for Social Media HIPAA Violation OCR investigated Dr. U. Phillip Igbinadolor, D.M.D. & Associates, P.A., (UPI), dental practice managing offices in Monroe and Charlotte, NC after a […]

Horizon Actuarial Services and Clinic of North Texas Reports Data Breaches

March 29, 2022 Christine Garcia

Horizon Actuarial Services and the Clinic of North Texas have just announced breaches of the protected health information (PHI) of patients and plan members. Data Theft and Extortion Incident at Horizon Actuarial Services Horizon Actuarial […]

Bipartisan Bill Presented to Reinforce Cybersecurity in Healthcare and Public Health Sector

March 28, 2022 Christine Garcia

Two bipartisan senators introduced a new bill that aspires to enhance the cybersecurity of the healthcare and public health (HPH) industry, in consideration of the current White House alert about the growing danger of Russian […]

FBI Reports 148 Healthcare Companies Encountered Ransomware Attacks in 2021

March 24, 2022 Christine Garcia

The Federal Bureau of Investigation (FBI) Internet Crime Complaint Center (IC3) has published its 2021 Internet Crime Report, which shows that critical infrastructure organizations had about 649 ransomware attacks between June 2021 and December 2021. […]

President Biden Prompts Private Sector to Take Quick Action to Toughen Cybersecurity Defense

March 24, 2022 Christine Garcia

Present Biden has released an alert regarding the growing threat of cyberattacks conducted by Russian state-sponsored hackers due to the economic sanctions enforced on the country as a reply to the attack on Ukraine. President […]

Healthcare Data Breach Report in February 2022

March 23, 2022 Christine Garcia

For the 3rd consecutive month, there is a decrease in the number of data breaches submitted to the HHS’ Office for Civil Rights (OCR). February had 46 healthcare data breaches involving 500 and up records […]

Woman Sentenced to 15-Month Jail Term for Stealing Over $200,000 Using Victims’ Patient Data

March 22, 2022 Christine Garcia

A woman was sentenced to 15 months imprisonment for being involved in a plan to defraud patients of a medical clinic based in Metairie, LA. In 2015, three persons were captured in association with the […]

DOJ Resolves Civil Cyber Fraud Initiative Case with CHS and Issues a $930,000 Penalty

March 17, 2022 Christine Garcia

The U.S. Department of Justice (DOJ) has reported the settlement agreed with the healthcare services company, Comprehensive Health Services (CHS) located in Cape Canaveral, FL to resolve alleged False Claims Act violations. This is the […]

Posts pagination

« 1 2 3 4 … 12 »
  • Site Map
  • About calHIPAA
  • Privacy Policy
  • Editorial Policy
  • Terms & Conditions
  • Cookie Policy
  • Diversity & Inclusion Policy
  • Jobs at calHIPAA

CalHIPAA is a registered trademark. © Copyright 2003 to 2024 calHIPAA. All rights reserved.