Vendor Management

DHS CISA Shares SolarWinds Post-Threat Compromise Activity Tool

by Jessica Davis

The Department of Homeland Security Cybersecurity and Infrastructure Security Agency shared another tool to support remediation of threats posed by the SolarWinds supply-chain attack. The new dashboard...

586K Trinity Health Patients Added to Accellion Tally, as Lawsuits Pile Up

by Jessica Davis

Michigan-based Trinity Health recently notified 586,869 patients that their data was compromised during the hack on Accellion’s File Transfer Application (FTA). As the breach tally continues to...

Accellion Breach Tally for Centene’s Subsidiaries: 1.3M Patients Impacted

by Jessica Davis

The Department of Health and Human Services’ breach reporting tool shows over 1.3 million patients of Centene subsidiaries were impacted by the massive Accellion File Transfer Appliance...

Patient Data from Multiple Providers Leaked in Third-Party GitHub Incident

by Jessica Davis

The patient data from multiple providers appears to have been captured and subsequently leaked on the data repository GitHub Arctic Code Vault by third-party vendor MedData, according to a new...

Trillium, SIU Medicine Added to Tally of Accellion FTA Breach Victims

by Jessica Davis

Trillium Community Health Plan and the Southern Illinois University School of Medicine recently reported some of their patient data was involved in the exploit of Accellion’s File Transfer...

Verkada Security Camera Hack Allows Access, Leak of Hospital Live Feeds

by Jessica Davis

A report from Bloomberg shows hackers were able to gain access to the live feeds from at least 150,000 security cameras, including those belonging to several hospitals, health clinics, Tesla, and...

CISA Warns of Accellion FTA Exploit; Centene Among Breach Victims

by Jessica Davis

The Department of Homeland Security Cybersecurity and Infrastructure Security Agency is urging all organizations to be on alert, as threat actors exploited several unpatched vulnerabilities in...

White House: SolarWinds Hack Impacted 9 Fed Agencies, 100 Entities

by Jessica Davis

At a White House press briefing on Wednesday, Deputy National Security Advisor for Cyber and Emerging Technology Anne Neuberger confirmed that the SolarWinds Orion compromise claimed nine federal...

Sutter Buttes Imaging PACS Vulnerability Causes 18 Month Data Breach

by Jessica Davis

Sutter Buttes Imaging (SBI) is notifying an undisclosed number of patients that their data was compromised for 18 months, due to a leak caused by a vulnerability in its third-party IT...

Can Healthcare Mitigate Risks to the COVID-19 Vaccine Supply Chain?

by Jessica Davis

As the world races to vaccinate its citizens, providers, hospitals, and research teams have rapidly deployed technologies to support the COVID-19 response. In turn, cybercriminals are preying on the thinly stretched supply chain with...

Patient Sues Rady Children’s Hospital Over Blackbaud Data Breach

by Jessica Davis

A guardian of a patient whose information was included in last year's Blackbaud data breach has sued Rady Children’s Hospital over the incident. Blackbaud is a third-party vendor of the...

Fed Task Force Says Russian APT Hackers Behind SolarWinds Attack

by Jessica Davis

The extent of the serious compromise of SolarWinds technology is continuing to unfold. The latest alert from the National Security Council officially claims that advanced persistent (APT) threat...

CISA Insights on Ongoing APT Cyber Activity Behind SolarWinds Attack

by Jessica Davis

The Department of Homeland Security Cybersecurity and Infrastructure Security Agency released insights that address the ongoing advanced persistent threat (APT) cyber activity, stemming from an earlier...

OCR Warns of Global Supply-Chain Cyberattacks Via SolarWinds Orion

by Jessica Davis

The Office for Civil Rights urges all healthcare organizations to review a Department of Homeland Security alert, warning of ongoing global supply-chain cyberattacks. Nation-state actors trojanized...

AMA Warns of Telehealth Cyber Risks, Insider Threats Tied to COVID-19

by Jessica Davis

Hospitals, health systems, and other providers should reassess their security posture in light of the COVID-19 pandemic, which has increased the number of cyber risks within the sector, such as...

Medical Device Vendor Zoll Sues IT Firm Over Breach Affecting 277K

by Jessica Davis

Medical device vendor Zoll filed a lawsuit with the US District Court of Massachusetts against IT service vendor Barracuda Networks, after an error during a server...

Mount Locker Ransomware Actors Claim Sonoma Valley Hospital Attack

by Jessica Davis

Mount Locker ransomware threat actors claim to be behind the cyberattack on Sonoma Valley Hospital, leaking data they allegedly stole from the California provider prior to deploying the malware...

FDA Scoring Tool Update Adds Vulnerability Risk to Patient Safety

by Jessica Davis

The FDA recently unveiled a new scoring system for assessing medical device vulnerabilities, an update from its previous system that was initially designed for commercial devices...

350M Voicemails, Health Details Exposed by Misconfigured Database

by Jessica Davis

Comparitech researchers discovered a trove of Broadvoice databases containing more than 350 million customer records, including names, contact details, and in some...

1M Inova Health Individuals Added to Blackbaud Breach Victim Tally

by Jessica Davis

The Blackbaud breach victim tally has climbed to nearly 3 million healthcare-connected entities and other nonprofits. In the last week, Inova Health System reported more than 1 million...