โŒ

Reading view

There are new articles available, click to refresh the page.

Massachusetts hospitals Heywood, Athol say outage was a cybersecurity incident

Joseph Topping reports: Heywood Hospital and Athol Hospital said a network outage this week was caused by a cybersecurity incident. The hospitals said they took affected systems offline and engaged a third-party cybersecurity firm. The facilitiesโ€”Heywood Hospital in Gardner, Massachusetts, and Athol Hospital in Athol, Massachusettsโ€”remain open and caring for patients; earlier in the week...

Source

Heritage Provider Network $49.99M Class Action Settlement

Nicole Aljet reports an update on a data breach that had been disclosed by Regal Medical Group in February 2023. Current and former patients who received a notice in early 2023 stating aย data breachย involving Heritage Provider Network or its affiliates may have exposed their personal or medical information could qualify to claim a cash payment...

Source

Integris Health Agrees to $30 Million Settlement Over 2023 Data Breach

Lauren Giella reports: Oklahoma health system Integris Health reached a $30 million settlement in a data breach class action lawsuit that impacted over two million people over two years ago. This agreement settles a class action lawsuit filed in the U.S. District Court for the Western District of Oklahoma that accuses Integris of negligence after...

Source

They were victims of a massive data breach in 2009. Interior Health denied it for a decade.

Harvey Cashore, Eva Uguen-Csenge,ย  and Mark Kelley report: Kelowna nurse Ashley Stone sits down at her kitchen table, opens a bulky blue folder containing a paper trail of 10 years of multiple frauds committed in her name by imposters and gets right to the point. โ€œItโ€™s just been a nightmare.โ€ She says sheโ€™s had to...

Source

Watsonville Community Hospital had a data breach โ€” or two. It would be helpful to know which.

On December 8, 2024, DataBreaches reported that Watsonville Community Hospital in California was continuing to respond to what they referred to as a cyberattack on November 29. No gang had claimed responsibility at that point, patients hadnโ€™t been notified yet, and the hospital wasnโ€™t stating whether the attack involved encryption of any files. Weeks later,...

Source

Missing Risk Analysis Cost NY CPA Firm $175Kโ€”But Not the Big Group Whose Data Was Breached in 2019

Theresa Defino reports: Covered entities (CEs) and business associates (BAs) might be forgiven if the most recent HHS Office for Civil Rights (OCR) HIPAA enforcement action evoked little more than a yawn. Yes, the $175,000 payment isnโ€™t a particularly large amount, and the sole alleged violation is a retread. Actually, itโ€™s the 10th in OCRโ€™s...

Source

Vn: Major hospitals hit by cyberattacks, patient data sold on hacker forums

Over the years, DataBreaches has noted hospitals in APAC countries having data leaked or being hit with ransomware attacks, but I have not seen a lot of reviews. An article by Thai Khang in VietnamNet names mentions some of the bigger hospital breaches in Vietnam since 2024, and then continues: According to Thuy, in the...

Source

California hospitals can escape fines if workers expose patient info

Scott Holland reports that a California state appeals court agreed with a hospital that it should not be held liable for employee misbehavior if they had a clear policy in place but the employee knowingly violated it: A state appeals panel has agreed hospitals canโ€™t be sued if one of their employees posts confidential patient...

Source

Harris Health discloses insider-wrongdoing breach that went on for a decade

Here is todayโ€™s reminder of the insider threat and why it may be challenging, but itโ€™s still necessary, to monitor and audit employee access to patient records to spot any inappropriate access. Harris Health is notifying more than 5,000 patients that an employee โ€” who was fired and referred to law enforcement when their wrongdoing...

Source

Leak of patient records feared as Israeli hospital hit by cyberattack demanding ransom

The Times of Israel reports: The Assaf Harofeh Medical Center in the central city of Beer Yaakov was targeted by a cyberattack over Yom Kippur, according to a joint announcement from the hospital, the Health Ministry and the National Cyber Directorate. Authorities were investigating the possibility of a leak as a result of the attack....

Source

Archer Health was leaking protected health information. Criminals appear to have found it. (2)

From our โ€œNo Need to Hack When Itโ€™s Leakingโ€ files, a report involving Archer Health, an in-home healthcare provider. Website Planet recently reported a misconfigured bucket that was found by researcher Jeremiah Fowler.ย  The unencrypted and non-password-protected database reportedly contained approximately 145k files (totaling 23 GB). โ€œIn a limited sampling of the exposed files, I...

Source

Columbia University Irving Medical Center pays $600K in data breach lawsuit settlement

In May 2024, DataBreaches logged an incident on our worksheets that involved the Columbia University Irving Medical Center in New York. The incident had been reported to HHS as affecting 29,629 patients whose name, medical record number, date of birth, provider name, and laboratory test result had been exposed between Sept. 11, 2023, and March...

Source

ApolloMD notifies patients of 11 physician practices affected by a June cyberattack

On June 12, 2025, Qilin added ApolloMD to their darkweb leak site with a date of June 6. They claimed to have 238 GB of files. ApolloMD, headquartered in Georgia, is a business associate to hospitals and health systems, providing them with services to enhance clinical operations and patient care, and to optimize financial performance....

Source

Verily Faces Lawsuit Over Alleged HIPAA Violations

John Blacksmith reports: Verily, owned by Alphabet, is facing a lawsuit filed by an ex-employee who alleges the misuse of the personally identifiable health information of over 25,000 patients, and the failure of the company to submit HIPAA breach reports, as per the Health Insurance Portability and Accountability Act (HIPAA) requirement. Verily, previously known as...

Source

Medical Associates of Brevard notifies 246,711 patients after cyberattack

On January 23, 2025, the Bian Lian ransomware gang added the Medical Associates of Brevard (โ€œMABโ€) to its dark web leak site. At the time, they listed the types of data they claimed to have acquired, but did not provide any screenshots or proof of claims. Months later, BianLian went offline. What happened to any...

Source

Two teenage suspected Scattered Spider members charged in UK over TfL hack; U.S. unseals charges (1)

Alexander Martin reports: Two suspected members of the Scattered Spider cybercrime collective have been arrested and charged in the United Kingdom following an investigation into the hack of Transport for London (TfL) last year. The National Crime Agency (NCA) announced on Thursday that Thalha Jubair, 19, from East London, and Owen Flowers, 18, from Walsall,...

Source

Survival Flight reports second cybersecurity incident in less than a year (1)

Survival Flight is an Arizona-headquartered firm that provides ground and air emergency medical transportation services. On August 12, they issued a substitute notice saying that on July 17, they had discovered a cybersecurity incident affecting its IT systems. In their substitute notice, which has not been updated as of this publication, they wrote: The investigation...

Source

Microsoft seizes 338 websites to disrupt rapidly growing โ€˜RaccoonO365โ€™ phishing service

Giles Bruce reports: Microsoft hasย seizedย 338 phishing websites associated with a cybercrime service that targeted at least 20 U.S. healthcare organizations. Using a court order granted by the U.S. District Court for the Southern District of New York, the tech giantโ€™s Digital Crimes Unit disrupted RaccoonO365, which offers subscription-based phishing kits allowing novices to mimic official...

Source

FBI โ€˜awareโ€™ of Anchorage health clinic data breach as hackers claim 60K patients impacted

Will Courtney reports: Days after anย anonymous hacker group claimed they had leakedย an additional 50,000 Anchorage Neighborhood Health Center patient records, an FBI spokesperson confirmed Monday they are aware of the claim. โ€œThe FBI Anchorage Field Office is aware of the alleged data breach affecting the Anchorage Neighborhood Health Center and takes allegations of this nature...

Source

US national charged in Finnish psychotherapy center extortion

Alexander Martin reports: Finnish prosecutors have charged a second individual โ€” U.S. national Daniel Lee Newhard โ€” with attempted extortion of the Vastaamo psychotherapy center. The Finnish Prosecution Service announced on Monday it had charged Newhard with aiding and abetting attempted aggravated extortion. It said the suspect, a 28-year-old, denies the offense. Officials did not...

Source

โŒ