Health IT Security and HIPAA News

BEC Phishing Campaigns Bypass MFA, Target Office 365 Executive Accounts

by

Entities should be on the alert for an increase in two business email compromise campaigns. One report found an increase in BEC phishing campaigns targeting the Microsoft Office 365 accounts...

Ransomware Hackers Post Data From 2 Providers, Device Manufacturer

by

NetWalker and DoppelPayer ransomware threat actors posted data from three healthcare entities to their dark web blog in the last week, including a rehabilitation center, fertility...

House Votes to Lift HHS Funding Ban on National Patient Identifier

by

In its Fiscal Year 2021 minibus package passed this week, the House of Representatives once again voted to remove a provision that effectively bans providing federal funds to the...

Researchers Find More Devices, Vendors Vulnerable to Ripple20

by

An additional 34 devices have been identified as vulnerable to Ripple20 flaws, which are found in the TCP/IP communication stack software developed by Treck, according to...

Hacker Leaks 900 Enterprise VPN Server Passwords on Dark Web

by

The usernames and passwords, as well as IP addresses, from more than 900 Pulse Secure Virtual Private Network enterprise servers were posted in plain text on the dark web by a Russian-speaking...

FBI: Operating Windows 7 Increases Cyber Risk to Network Infrastructure

by

Organizations continuing to operate with Microsoft Windows 7 platforms on the network infrastructure are at an increased risk of cyberattack, according to a private industry notification from the...

The Risk of Nation-State Hackers, Government-Controlled Health Data

by

The COVID-19 pandemic has driven a rise in targeted, sophisticated cyberattacks designed to take advantage of an increasingly connected environment. In healthcare, it’s led to a rise in...

COVID-19 Impact on Ransomware, Threats, Healthcare Cybersecurity

by

COVID-19 has significantly shifted the threat landscape from attacks on individuals and small businesses to critical infrastructure, governments, and major corporations, according to Interpol....

DHS CISA Alert Warns of Chinese-Backed Malware Cyberattacks

by

The Department of Homeland Security Cybersecurity and Infrastructure Security Agency identified a malware variant tied to the Chinese government, which is targeting US organizations to both...

Moderna COVID-19 Vaccine Data Targeted by Nation-State Hackers

by

Massachusetts-based Moderna, a research firm currently tasked with the development of a COVID-19 vaccine, was targeted by hackers with ties to the government of China, in an effort designed to...

Philips Discloses Vulnerability in DreamMapper Mobile App Software

by

The Department of Homeland Security Cybersecurity and Infrastructure Security Agency released an advisory on a medium-severity vulnerability found...

FBI Alerts to Rise in Targeted Netwalker Ransomware Attacks

by

Netwalker ransomware attacks are again on the rise, targeting US and foreign health agencies, education entities, private companies, and governments, according to a recent FBI flash...

Proposed COVID-19 Relief Bills Include Privacy, Security Funding

by

The Senate Committee on Appropriations unveiled COVID-19 relief legislation this week, which would allocate $53 million in funds to the Department of Homeland Security...

IBM: Health Sector Leads in Annual Data Breach Costs, Topping $7.13M

by

Data breaches are the most expensive in healthcare when compared to all global industries with costs topping $7.13 million annually, compared to $3.86 million across all sectors,...

Lifespan to Pay OCR $1.04M HIPAA Penalty For Unencrypted Laptop Theft

by

The Office for Civil Rights reached a settlement with Lifespan Health System Affiliated Covered Entity over the theft of an unencrypted laptop in 2017. The Rhode...

COVID-19 Cybersecurity: Building Resilience Beyond the Crisis

by

A recent Forescout report showed more than a third of workstations in healthcare operate on unsupported versions of Windows, among a host of other vulnerabilities found in...

National Cardiovascular Partners Email Hack Impacts 78K Patients

by

National Cardiovascular Partners recently notified 78,070 patients that their data was potentially compromised after an attacker gained access to an employee email account.  According to its...

OCR Settles with Small Provider for $25K Over Multiple HIPAA Violations

by

The Department of Health and Human Services Office for Civil Rights has reached a settlement with North Carolina-based Metropolitan Community Health Services, DBA Agape Health Services, over...