HIPAA Breach News

Accellion Proposes $8.1 Settlement to Resolve Class Action FTA Data Breach Lawsuit

The Palo Alto, CA-based technology firm Accellion has proposed an $8.1 million settlement to resolve a class action data breach lawsuit filed on behalf of victims of the December 2020 cyberattack on the Accellion File Transfer Appliance (FTA).

The Accellion FTA is a legacy solution that is used for securely transferring files that are too large to be sent via email. The Accellion FTA had been in use for more than 20 years and was at end-of-life, with support due to end on April 30, 2021. Accellion had developed a new platform, Kiteworks, and customers were encouraged to upgrade from the legacy solution; however, a significant number of entities were still using the FTA solution at the time of the cyberattack.

In December 2020, two previously unknown Advanced Persistent Threat (APT) groups linked to FIN11 and the CLOP ransomware gang exploited unaddressed vulnerabilities in the Accellion FTA, gained access to the files of its clients, and exfiltrated a significant amount of data. Following the breach, four vulnerabilities associated with the breach were disclosed and issued CVEs.

Accellion clients affected by the breach included banks, law firms, universities, and healthcare organizations. Many of the files belonging to healthcare organizations contained sensitive patient and health plan member data. Healthcare organizations affected by the breach include Health Net Community Solutions, Health Net of California, California Health & Wellness, Trinity Health, The University of California, Stanford University School of Medicine, University of Miami Health, Kroger, Trillium, Community Health Plan, Arizona Complete Health, CalViva Health, and Health Employees’ Pension Plan.

Following the attack, several lawsuits were filed against Accellion and its clients over the data breach. The class action lawsuit against Accellion alleged the company had failed to implement and maintain appropriate data security practices to protect the sensitive data of its clients, failed to detect security vulnerabilities in the Accellion FTA, failed to disclose its security practices were inadequate and failed to prevent the data breach. As a result of the attack, highly sensitive information was stolen, including names, contact information, dates of birth, Social Security numbers, driver’s license numbers, and healthcare data.

Accellion denied all of the allegations in the lawsuit and accepts no liability for the data breach. The company said in the settlement agreement that it is not responsible for managing, updating, and maintaining customers’ instances of the FTA software. Accellion also said the company does not collect any customer data, does not access the content of files shared or stored via the FTA solution, and provided no guarantees to customers that the FTA software was secure.

It is unclear how many individuals will be covered by the settlement, but the number is certainly in excess of 9.2 million individuals. Accellion will attempt to obtain up-to-date contact information for those individuals in order to send notices of the proposed settlement. The proposed settlement includes a cash fund of $8.1 million to cover claims, notices, administration costs, and service awards to affected users of the Accellion FTA. $4.6 million of the fund will be made available within 10 days, with the remainder made available within 10 days of the settlement being approved.

Affected individuals will be entitled to sign up for 24 months of three-bureau credit monitoring and insurance services, or receive reimbursement for documented losses up to a maximum value of $10,000, or receive a cash payment, which is expected to be in the region of $15 to $50. Accellion will also fully retire the Accellion FTA and take steps to ensure the security of its replacement Kiteworks solution. Those measures include increasing its bug bounty program, maintaining FedRAMP certification, employing individuals with responsibility for cybersecurity, providing cybersecurity training to its workforce, and undergoing regular assessments to confirm continued compliance with the cybersecurity measures outlined in the settlement.

The proposed settlement will resolve all claims against Accellion only. There are still lawsuits and settlements outstanding against clients affected by the breach. The supermarket chain Kroger has proposed a $5 million settlement to resolve lawsuits filed on behalf of the 3.8 million employees and customers affected by the breach.

The post Accellion Proposes $8.1 Settlement to Resolve Class Action FTA Data Breach Lawsuit appeared first on HIPAA Journal.

Online Pharmacy Notifies 105,000 Patients About Cyberattack and Potential Theft of PHI

The Auburndale, FL-based digital pharmacy and health app developer Ravkoo has started notifying certain patients that some of their sensitive personal information has been exposed and potentially obtained by an unauthorized individual.

Ravkoo hosts its online prescription portal on Amazon Web Services (AWS). The portal was targeted in a cyberattack that was detected on September 27, 2021. Upon discovery of the security breach, steps were immediately taken to secure the portal and third-party cybersecurity experts were engaged to assist with the forensic investigation, mitigation, restoration, and remediation efforts.

The investigation confirmed sensitive patient data had been exposed and may have been compromised, including names, addresses, phone numbers, certain prescription information, and limited medical data. Ravkoo said the impacted portal did not contain any Social Security numbers, which are not maintained in the affected portal. The forensic investigation did not uncover any evidence that indicated information contained within the portal has been or will be misused.

Ravkoo has reported the cyberattack to the Federal Bureau of Investigation (FBI) and is assisting with the investigation. Ravkoo has also been working with forensics experts to review the security of its AWS environment. Steps are now being taken to improve security to prevent further data breaches in the future.

The data breach has been reported to the Department of Health and Human Services’ Office for Civil Rights as affecting up to 105,000 individuals. Affected individuals are being offered complimentary access to Kroll’s online credit monitoring service as a precaution, which includes access to resolution services in the event of identity theft.

Micah Lee at The Intercept said in a September 28, 2021 tweet that a hacker had claimed responsibility for the attack on Ravkoo and said the patient portal was “hilariously easy” to hack and involved the use of a hidden admin portal that any user could log in to and request patient data.

The post Online Pharmacy Notifies 105,000 Patients About Cyberattack and Potential Theft of PHI appeared first on HIPAA Journal.

EHR Vendor Facing Class Action Lawsuit Over 320,000-Record Data Breach

QRS, a Tennessee-based healthcare technology services company and EHR vendor, is facing a class action lawsuit over an August 2021 cyberattack in which the protected health information (PHI) of almost 320,000 patients was exposed and potentially stolen.

The investigation into the data breach confirmed a hacker had gained access to one of its dedicated patient portal servers between August 23 and August 26, 2021, and viewed and possibly obtained files containing patients’ PHI. Sensitive data stored on the server included patients’ names, addresses, birth dates, usernames, medical information, and Social Security numbers. QRS started sending notification letters to affected individuals in late October and offered identity theft protection services to individuals who had their Social Security number exposed.

On January 3, 2022, Matthew Tincher, a Frankfurt, KY resident, filed a class action complaint in the U.S. District Court for the Eastern District of Tennessee against QRS. The lawsuit alleges QRS was negligent for failing to reasonably secure, monitor, and maintain the PHI and personally identifiable information (PII) stored on its patient portal.

As a result of those failures, the lawsuit alleges Tincher and class members have suffered actual, concrete, and imminent injury, including present injury and damages from identity theft, loss or diminished value of their PHI and PII, and have incurred out-of-pocket expenses from attempting to remedy the exposure of their sensitive information and have had to spend time mitigating the effects of the unauthorized data access. They also face a continued and increased risk to their PHI and PII, which were unencrypted and remain available to unauthorized parties to access and abuse.

The lawsuit also takes issue with the speed at which QRS issued breach notification letters, which were issued almost 2 months after the discovery of the breach. During those two months, the plaintiffs and class embers were unaware they had been placed at significant risk of identity theft, fraud, and personal, social, and financial harm.

The lawsuit alleges QRS had a responsibility to ensure the PHI and PII within its patient portal were appropriately protected, and the breach of its duties to protect that information amounts to negligence and/or recklessness, which violates federal and state statutes. The lawsuit claims QRS signed business associate agreements (BAAs) with its healthcare provider clients, so was aware or should have been aware of its responsibilities to ensure PHI was protected against cyberattacks. The lawsuit also lists cybersecurity measures recommended by the Cybersecurity and Infrastructure Security Agency (CISA) which should have been implemented in that regard and maintains QRS should have been aware of the high risk of being attacked due to the large number of healthcare data breaches that have been reported in recent years.

Lawsuits are often filed against healthcare organizations over data breaches that exposed sensitive information. Whether the lawsuits succeed often depends on whether the plaintiffs are able to demonstrate they have suffered actual harm as a direct consequence of the data breach. Tincher claims to have been notified about the breach on October 22, 2021, and within 3 days was the victim of actual identity theft, and that it is more likely than not that his sensitive information was exfiltrated from the QRS patient portal during the data breach.

The lawsuit alleges the total damages incurred by the plaintiff and class members exceed the minimum $5 million jurisdictional amount required by the Court, and that the Court has jurisdiction over the defendant because QRS operates and is incorporated in the district. The plaintiff and class members seek a jury trial, unspecified damages, and injunctive and equitable relief.

The post EHR Vendor Facing Class Action Lawsuit Over 320,000-Record Data Breach appeared first on HIPAA Journal.

Disruption to Services at Maryland Department of Health Continues One Month After Ransomware Attack

Maryland Chief Information Security Officer (CISO) Chip Stewart has issued a statement confirming the disruption to services at the Maryland Department of Health (MDH) was the result of a ransomware attack.

A security breach was detected in the early hours of December 4, 2021, and prompt action was taken to isolate the affected server and contain the attack. Stewart said the Department of Information Technology successfully isolated and contained the affected systems within a matter of hours, limiting the severity of the attack. “It is in part because of this swift response that we have not identified, to this point in our ongoing investigation, evidence of the unauthorized access to or acquisition of State data,” said Stewart in a statement issued on January 12, 2022.

According to Stewart, there was an attempted distributed-denial-of-service (DDoS) attack shortly after the ransomware attack; however, that attack was not successful. Evidence gathered during the investigation of the ransomware and DDoS attacks indicates they were conducted by different threat actors.

Stewart said he reported the incident to the Cybersecurity and Infrastructure Security Agency (CISA) and the Federal Bureau of Investigation (FBI), activated the state’s cybersecurity insurance policy through the State Treasurer’s Office, and engaged third-party forensic investigators to assist with the investigation and response and recovery efforts. “The companies and personnel provided by the insurance policy are widely regarded as the best in the industry,” said Stewart.

The response to the ransomware attack required systems to be taken offline, sites on the network were isolated from each other, and external access to resources over the Internet and by third parties was blocked. The containment approach limited the ability of state employees to use computers and access shared resources and more than a month after the ransomware attack some services continue to face disruption. While the response and recovery approach has resulted in ongoing disruption, Stewart said this approach was necessary to protect the state’s network and the citizens of the state of Maryland and was important to prevent reinfection.

Atif Chaudhry, MDH Deputy Secretary for Operations, said a major focus in the aftermath of the attack was to ensure business and service continuity, which involved implementing the FEMA Incident Command System (ICS). “Under this ICS system, we formed a Unified Command Structure to address the incident. This permits MDH and DoIT to jointly collaborate to manage and address all incident-related matters. DoIT provides the technical expertise and is taking the lead on network security and IT system recovery efforts,” said Chaudhry.

MDH faced a shortage of equipment in the aftermath of the attack, which meant employees have had to share computers at work. To address the problem, Chaudhry said MDH ordered an additional 2,400 laptop computers and a further 3,000 will be ordered this week.  Additional IT equipment such as wireless access points and printers have also been ordered to ensure employees have the equipment they need to do their jobs. Further, alternative processes have been implemented to ensure staff can serve the most urgent needs of the public, which include migration to Google Workspaces. Google Workspaces has provided employees a suite of online tools that are unaffected by the ransomware attack ensuring employees can collaborate and save and share critical files.

The attack has caused disruption to the state’s pandemic response. On Thursday, January 12, 2022, MDH said it had restored around 95% of state-level surveillance data and it is working to restore the complete COVID-19 dataset. Reports will be updated at the earliest opportunity.

The post Disruption to Services at Maryland Department of Health Continues One Month After Ransomware Attack appeared first on HIPAA Journal.

PHI of Anthem Members and Advocate Aurora Health Patients Potentially Compromised

Anthem Inc. has alerted 2,003 members that some of their protected health information has potentially been viewed or obtained by an unauthorized individual who gained access to the network of one of its business associates.

Anthem works with the Atlanta, GA-based insurance broker OneDigital, which provides support for individuals enrolled in group health plans to help them procure and manage their health insurance. OneDigital had been provided with the protected health information of certain members to assist them or their current or former employer to obtain and manage their health insurance plan.

On November 24, 2021, Anthem was notified by OneDigital about a network server hacking incident that occurred in January 2021. Anthem said the investigation into the breach did not uncover any direct evidence of unauthorized viewing or theft of protected health information, but those activities could not be ruled out.

The types of data stored on the compromised systems included names, addresses, dates of birth, healthcare provider names, health insurance numbers, group numbers, dates and types of health care services, medical record numbers, lab test results, prescription information, payment information, claims information, Social Security numbers, and driver’s license numbers.

Affected individuals have been offered complimentary credit monitoring and identity theft protection services for 12 months. Anthem said it is working with OneDigital to reduce the risk of similar breaches occurring in the future.

Billing Error Results in Exposure of the PHI of More Than 1,700 Advocate Aurora Health Patients

The Illinois-based 26-hospital health system, Advocate Aurora Health, has notified more than 1,700 patients that some of their protected health information has potentially been compromised.

On or around July 29, 2021, billing statements were prepared and mailed to patients, but they failed to reach their destination. The statements contained a limited amount of protected health information, such as patients’ names, dates of service, the types of services provided, the name of the healthcare provider they visited, and visit account numbers.

Advocate Aurora Health discovered the billing error on October 29, 2021. The subsequent investigation revealed there had been an accidental change to its billing software that went unnoticed, which resulted in statements being mailed to the wrong address. Advocate Aurora Health said it has not received any reports of attempted or actual misuse of any patient data as a result of the incident, but patients have been notified by mail as a precaution and have been offered complimentary credit monitoring services.

Advocate Aurora Health said it is making changes to its internal processes and technology to prevent similar breaches in the future. The breach was reported to the HHS’ Office for Civil Rights as affecting 1,729 individuals.

The post PHI of Anthem Members and Advocate Aurora Health Patients Potentially Compromised appeared first on HIPAA Journal.

Over 30 Healthcare Providers Affected by CIOX Health Data Breach

The health information management services provider CIOX Health has suffered a data breach that has affected at least 32 healthcare providers. In July 2021, CIOX Health discovered an unauthorized individual had gained access to the email of an employee in the customer service department. The email account was immediately secured, with the subsequent investigation confirming the email account had first been accessed by an unauthorized individual on June 24, 2021, and access remained possible until the security breach was detected on July 2, 2021.

The CIOX Health breach investigation confirmed that the incident was confined to a single employee email account, with the review of the contents of the email account determining on September 24, 2021, that it contained emails and attachments that included the protected health information of some of its healthcare provider clients such as names, dates of birth, provider names, dates of service, and the Social Security numbers, driver’s license numbers,  health insurance information, and/or treatment information of a very limited number of individuals.

The employee in question worked in customer service and, as such, serviced healthcare provider clients across the country with billing issues and helped with other customer service requests, hence a large number of affected clients. The employee did not, however, have access to the medical record systems of any of its healthcare provider clients.

CIOX Health said that during the time that the account was accessible it is possible that emails containing protected health information were accessed or copied, but no direct evidence of attempted or actual misuse of patient data has been uncovered. CIOX Health believes that the email account was compromised to send phishing emails from the company domain to individuals unrelated to CIOX Health.

COX Health is encouraging all individuals affected by the breach to check their statements and explanation of benefits statements from their healthcare providers and insurers for any sign of unauthorized use of their information.

In response to the breach, CIOX Health will be implementing stronger email security measures and will provide the workforce with further security awareness training.

CIOX health started notifying affected healthcare provider clients about the breach on December 30, 2021. Healthcare providers known to have been affected by the email account breach at CIOX Health are listed below.

  • AdventHealth – Orlando
  • Alabama Orthopaedic Specialists
  • Baptist Memorial Health Care
  • Butler Health Systems
  • Cameron Memorial Community Hospital
  • Centra Health
  • Children’s Healthcare of Atlanta
  • Coastal Family Health Center
  • Copley Hospital
  • DeSoto Memorial Hospital Health System
  • EvergreenHealth
  • Hoag Health System
  • Hospital Sisters Health System
  • Huntsville Hospital Health System
  • Indiana University Health
  • McLeod Health System
  • MD Partners
  • Niagara Falls Memorial Medical Center Health System
  • Northern Light Mercy Hospital
  • Northwestern Medicine
  • Ohio State University Health System
  • OrthoConnecticut
  • Prisma Health – Greenville Health System
  • Prisma Health – Palmetto Health
  • Sarasota County Public Hospital District d/b/a Sarasota Memorial Health Care System
  • Trinity Health – Holy Cross Hospital
  • Trinity Health – Mount Carmel Health System
  • Trinity Health – Saint Alphonsus Health System
  • Trinity Health – St. Francis Medical Center
  • Trinity Health – St. Joseph Mercy Health System
  • Union Hospital Healthcare System
  • Women’s Health Specialist

The security breach has been reported to the HHS’ Office for Civil Rights by CIOX Health as affecting 12,493 individuals.

The post Over 30 Healthcare Providers Affected by CIOX Health Data Breach appeared first on HIPAA Journal.

Millennium Eye Care Says Ransomware Gang Stole a Large Amount of Patient Data

Millennium Eye Care, a Freehold, NJ-based provider of ophthalmology services, announced on December 22, 2021, that hackers recently gained access to its computer network and used ransomware to encrypt files in an attempt to extort money from the practice.

It is unclear when the attack occurred from its breach notification letters, but Millennium Eye Care said it discovered on November 14, 2021, that the attackers had exfiltrated “a large amount of data” prior to encrypting files. The files obtained in the attack included a range of protected health information including names and Social Security numbers.

Millennium Eye Care said it has increased network security measures to reduce the risk of further attacks and has provided additional cybersecurity training to the workforce to help them recognize external attacks.

Affected individuals have been notified by mail and have been provided with information on the steps they can take to protect against identity theft and fraud. Identity theft protection services are being provided free of charge and affected patients will also be covered by a $1,000,000 identity theft reimbursement policy.

The breach has been reported to regulators but has not yet appeared on the HHS’ Office for Civil Rights breach portal so it is currently unclear how many patients have been affected.

Cyberattack Reported by Duneland School Corporation

Duneland School Corporation in Indiana has notified the HHS’ Office for Civil Rights about a recent cyberattack in which the protected health information of 7,000 individuals was potentially compromised.

The cyberattack was detected on October 27, 2021, and resulted in certain systems within its computer network being made unavailable. A third-party cybersecurity firm was engaged to investigate and determine the nature and scope of the attack. The investigation confirmed that unauthorized individuals had access to parts of its network between October 21 and October 27, and those systems contained the personal information of employees and information related to its self-insured health plan, such as names, dates of birth, Social Security numbers, driver’s license numbers, and benefits information.

Duneland School Corporation says it has implemented additional safeguards and technical security measures to prevent any further cyberattacks. Identity monitoring services are being provided to current and former employees, beneficiaries, and dependents, whose data were compromised.

The post Millennium Eye Care Says Ransomware Gang Stole a Large Amount of Patient Data appeared first on HIPAA Journal.

BioPlus Specialty Pharmacy Services Faces Class Action Lawsuit Over Data Breach

A Florida specialty pharmacy is facing a class action lawsuit over an October 2021 cyberattack in which the personally identifiable information (PII) and protected health information (PHI) of up to 350,000 patients were stolen.

Altamonte Springs, FL-based BioPlus Specialty Pharmacy Services said a hacker had access to its network from October 25, 2021, until November 11, 2021, and during that time viewed files containing sensitive patient data. A computer forensics firm investigated the breach and confirmed patient data had been accessed. Since it was not possible to determine how many patients had been affected, the decision was taken to send notification letters to all 350,000 patients on or around December 10, 2021, one month after the breach was discovered.

Data potentially compromised in the attack included names, contact information, dates of birth, medical record numbers, health insurance and claims information diagnoses, prescription information, and Social Security numbers. Affected individuals were offered a 12-month subscription to credit monitoring services at no cost.

In late December, BioPlus patient Bonnie Gilbert and her attorneys filed a lawsuit in the U.S. District Court of the Middle District of Florida alleging BioPlus had violated the Health Insurance Portability and Accountability Act (HIPAA) by failing to ensure the confidentiality, integrity, and availability of the PHI of its patients.

The lawsuit alleges negligence for failing to maintain reasonable data security safeguards, failing to implement industry-standard data security practices, and failing to exercise reasonable care in the hiring and supervision of its employees and agents. The lawsuit also claims BioPlus failed to detect the attack and the exfiltration of sensitive data from its network, and delayed breach notifications. The lawsuit claims that if a reasonable amount of care had been taken and appropriate data security measures had been in place, the attack could have been detected sooner and/or prevented.

The lawsuit alleges the plaintiff and class members have suffered “numerous actual and imminent injuries” as a direct result of the data breach, including the theft of their PII and PHI, invasion of privacy, a reduction in the economic value of their PII and PHI, emotional distress and stress, and a significant present and future risk of identity theft and financial fraud, as well as incurring costs attempting to mitigate and deal with the consequences of the data breach.

The lawsuit seeks class action certification, a jury trial, injunctive relief, declaratory relief, and monetary damages. The plaintiff is represented by Morgan & Morgan and Markovits, Stock, & DeMarco LLC.

The post BioPlus Specialty Pharmacy Services Faces Class Action Lawsuit Over Data Breach appeared first on HIPAA Journal.

Almost 80,000 Patients Affected by Cyberattack on Fertility Centers of Illinois

Fertility Centers of Illinois (FCI) has recently notified 79,943 current and former patients that some of their protected health information may have been viewed or obtained by unauthorized individuals.

FCI identified suspicious network activity on February 1, 2021, and took prompt action to secure its systems. Independent forensic investigators were then engaged to determine the nature and scope of the security breach.

FCI had implemented security measures to keep patient data secure, and those measures ensured its electronic medical record system could not be accessed; however, the attackers were found to have accessed administrative files and folders. A review of those files confirmed on August 27, 2021, that they contained a range of patient data including names in combination with one or more of the following types of information:

Social Security numbers, passport numbers, financial account information, payment card information, diagnoses, treatment information, medical record numbers, billing/claims information, prescription information, Medicare/Medicaid identification information, health insurance group numbers, health insurance subscriber numbers, patient account numbers, encounter numbers, referring physicians, usernames and passwords with PINs or account login information.

Employee information was also potentially compromised including names, employer-assigned identification numbers, ill-health/retirement information, occupational health-related information, medical benefits and entitlements information, patkeys/reason for absence, and sickness certificates.

FCI said it had strict security measures in place to prevent unauthorized data access, but the attackers were able to bypass those controls. Steps have since been taken to further secure its systems, data, and equipment, including implementing enterprise-class identity verification software and providing additional training to the workforce on security practices.

All affected individuals have been notified by mail and have been offered complimentary credit monitoring and identity theft protection services for 12 months through Equifax.

The post Almost 80,000 Patients Affected by Cyberattack on Fertility Centers of Illinois appeared first on HIPAA Journal.