HIPAA Breach News

Blackbaud Ransomware Attack Impacts 657,392 Northern Light Health Foundation Donors

The Brewer, ME-based 10-hospital integrated healthcare system, Northern Light Health Foundation, has announced it has been affected by the recent ransomware attack on Blackbaud Inc.

The databases affected contained information about donors, potential donors, and individuals who may have attended a fundraising event in the past. Patient medical records were stored separately and were unaffected. The databases contained the records of 657,392 individuals.

South Carolina-based Blackbaud is one of the world’s largest providers of education, administration, fundraising, and financial management software. A company as large as Blackbaud is naturally a target for cybercriminals. Blackbaud explained it encounters millions of attacks each month and its cybersecurity team successfully defends the company against those attacks, although in May 2020 one of those attacks succeeded.

The ransomware attack could have been far worse. Blackbaud detected the ransomware attack quickly and took action to block the attack. Blackbaud was able to prevent the ransomware from fully encrypting its files, and only a subset of the company’s 25,000+ clients were affected. The attack did not affect its cloud environment and the majority of its self-hosted environment was unaffected.

As is now common in manual ransomware attacks, prior to file encryption data was exfiltrated by the attackers. Blackbaud said in its breach notice that only a subset of data was copied by the attackers and highly sensitive information such as Social Security numbers, credit card information, and bank account information were not stolen in the attack.

“Because protecting our customers’ data is our top priority, we paid the cybercriminal’s demand with confirmation that the copy they removed had been destroyed. Based on the nature of the incident, our research, and third party (including law enforcement) investigation, we have no reason to believe that any data went beyond the cybercriminal, was or will be misused; or will be disseminated or otherwise made available publicly,” explained Blackbaud in its substitute breach notice.

It is currently unclear how many Blackbaud clients have been affected by the attack. Northern Light Health Foundation said it was one of thousands affected in its breach notice, including several other healthcare organizations in Maine. Other healthcare organizations known to have been affected include the New York City-based Cancer Research Institute and the Santa Monica, CA-based Prostate Cancer Foundation.

The BBC reports that at least 10 universities in the US, UK, and Canada have been affected, including Harvard University, Emerson College in Boston, and the Rhode Island School of Design, along with charities, media firms, and a host of private sector companies. While the attack occurred in May 2020, notifications were not sent to affected clients until July 16, 2020. It is unclear why there was such a long delay in alerting affected clients, especially considering many of those clients are located in the EU. The EU General Data Protection Regulation (GDPR) requires notifications to be sent to data protection authorities within 72 hours of a breach and data controllers to also be notified promptly.

The post Blackbaud Ransomware Attack Impacts 657,392 Northern Light Health Foundation Donors appeared first on HIPAA Journal.

Healthcare Data Leaks on GitHub: Credentials, Corporate Data and the PHI of 150,000+ Patients Exposed

A new report has revealed the personal and protected health information of patients and other sensitive data are being exposed online without the knowledge of covered entities and business associates through public GitHub repositories.

Jelle Ursem, a security researcher from the Netherlands, discovered at least 9 entities in the United States – including HIPAA-covered entities and business associates – have been leaking sensitive data via GitHub. The 9 leaks – which involve between 150,000 and 200,000 patient records – may just be the tip of the iceberg. The search for exposed data was halted to ensure the entities concerned could be contacted and to produce the report to highlight the risks to the healthcare community.

Even if your organization does not use GitHub, that does not necessarily mean that you will not be affected. The actions of a single employee or third-party contracted developer may have opened the door and allowed unauthorized individuals to gain access to sensitive data.

Exposed PII and PHI in Public GitHub Repositories

Jelle Ursem is an ethical security researcher who has previously identified many data leaks on GitHub, including by Fortune 500 firms, publicly traded companies, and government organizations. Ursem decided to conduct a search to find out if any medical data had been leaked on GitHub. It took just 10 minutes to confirm that it had, but it soon became clear that this was far from an isolated case.

Ursem conducted searches such as “companyname password” and “medicaid password FTP” and discovered several hard-coded usernames and passwords could be found in code uploaded to GitHub. Those usernames and passwords allowed him to login to Microsoft Office 365 and Google G Suite accounts and gain access to a wide range of sensitive information such as user data, contracts, agendas, internal documents, team chats, and the protected health information of patients.

“GitHub search is the most dangerous hacking tool out there,” said Ursem. Why go to the trouble of hacking a company when it is leaking data that can be found with a simple search on GitHub?

Ursem attempted to make contact with the companies concerned to alert them to the exposure of their data and ensure the information was secured, but making contact with those organizations and getting the data secured proved problematic, so Ursem contacted databreaches.net for assistance.

Together, Dissent Doe of DataBreaches.net and Ursem worked together to contact the organizations concerned and get the data secured. In some cases, they succeeded – with considerable effort – but even after several months of attempts at contacting the companies concerned, explaining the severity of the situation, and offering help to address the problems that led to the exposure of data, some of that data is still accessible.

9 Leaks Identified but There are Likely to be Others

The report details 9 leaks that affected U.S. entities – namely Xybion, MedPro Billing, Texas Physician House Calls, VirMedica, MaineCare, Waystar, Shields Health Care Group, AccQData – and one unnamed entity: Unnamed because the data is still accessible.

The most common causes of GitHub data leaks were developers who had embedded hard-coded credentials into code that had been uploaded into public GitHub repositories, the use of public repositories instead of private repositories, and developers who had abandoned repositories when they were no longer required, rather than securely deleting them.

For example, Ursem found that a developer at Xybion – a software, services and consulting company with a presence in workplace health issues – had left code in a public GitHub repository in February 2020. The code included hard-coded credentials for a system user that, in connection with other code, allowed Ursem to access billing back-office systems that contained the PHI of 7,000 patients, together with more than 11,000 insurance claims dating back to October 31, 2018.

It was a similar story with MaineCare – a state- and federally-funded program that provides healthcare coverage to Maine residents. In that case, hard-coded credentials gave Ursem administrative access to the entire website, access to the internal server infrastructure of MaineCare / Molina Health, MaineCare SQL data sources, and the PHI of 75,000 individuals.

The Typhoid Mary of Data Leaks

The report highlights one developer, who has worked with a large number of healthcare organizations, whose GitHub practices have led to the exposure of many credentials and the PHI of an estimated 200,000 clients. That individual has been called the “Typhoid Mary of Data Leaks”.

The developer made many mistakes that allowed client data to be exposed, including leaking the credentials of 5 employers on GitHub and leaving repositories fully accessible after work had been completed. In one case, the actions of that developer had allowed access to the central telephone system of a large entity in debt collection, and in another credentials allowed access to highly sensitive records for people with a history of substance abuse.

While it was not possible to contact that individual directly, it appears that the work of DataBreaches.net and Ursem has gotten the message through to the developer. The repositories have now been removed or made private, but not before the data was cloned by at least one third party.

This was just one example of several outsourced or contracted developers who were being used by HIPAA-covered entities and business associates, whose practices exposed data unbeknownst to the CEs and BAs.

“No matter how big or small you are, there’s a real chance that one of your employees has thrown the front door key under the doormat and has forgotten that the doormat is transparent,” explained Dissent Doe of DataBreaches.net. Regardless of whether your organization uses GitHub, HIPAA Journal believes the report to be essential reading.

The collaborative report from Jelle Ursem and DataBreaches.net explains how the leaks occurred, why they have gone undetected for so long, and details several recommendations on how data breaches on GitHub can be prevented – and detected and addressed quickly in the event that mistakes are made. You can download the full PDF report on this link.

Many thanks to Dissent Doe for notifying HIPAA Journal, to Jelle Ursem for discovering the data leaks, and for the hard work of both parties investigating the leaks, contacting the entities concerned, and highlighting the problem to help HIPAA-covered entities and their business associates take steps to prevent GitHub data breaches moving forward.

The post Healthcare Data Leaks on GitHub: Credentials, Corporate Data and the PHI of 150,000+ Patients Exposed appeared first on HIPAA Journal.

Medical Software Database Containing Personal Information of 3.1 Million Patients Exposed Online

A database containing the personal information of more than 3.1 million patients has been exposed online and was subsequently deleted by the Meow bot.

Security researcher Volodymyr ‘Bob’ Diachenko discovered the database on July 13, 2020. The database required no password to access and contained information such as patients’ names, email addresses, phone numbers, and treatment locations. Diachenko set about trying to identify the owner of the database and found it had been created by a medical software company called Adit, which makes online booking and patient management software for medical and dental practices. Diachenko contacted Adit to alert the company to the exposed database but received no response. A few days later, Diachenko discovered the data had been attacked by the Meow bot.

The Meow bot appeared in late July and scans the internet for exposed databases. Security researchers such as Diachenko conduct scans to identify exposed data and then make contact with the data owners to try to get the data secured. The role of the Meow bot is search and destroy. When exposed database are found, the Meow bot’s script overwrites the data with random numerical strings, appended with the word “meow”.

The individual or group behind the Meow bot is unknown, nor the motives behind the attacks, of which there have been hundreds. Many threat actors search for exposed cloud databases and steal or encrypt data and issue a ransom demand, but there appears to be no financial motive behind the Meow bot attacks.

It is not entirely clear whether data is stolen prior to being overwritten, but several security researchers have suggested data theft is not the aim, instead the purpose may be to prevent the information of data subjects from being obtained by cybercriminals and/or to send a message to data holders that the failure to secure data will result in data being destroyed.

The deletion of the database may have prevented the data from falling into the hands of cybercriminals, but a previous study conducted by Comparitech showed malicious actors are constantly searching for exposed data and often find exposed Elasticsearch databases and Amazon S3 buckets within hours of them being exposed. Since the database was exposed for at least 10 days before the search and destroy Meow bot attack, it is probable that it was found and obtained prior to its destruction; potentially by multiple parties.

In this case, the personal data was limited, but that information could still be of use to cybercriminals for phishing campaigns.

The post Medical Software Database Containing Personal Information of 3.1 Million Patients Exposed Online appeared first on HIPAA Journal.

Protected Health Information of 129K Individuals Potentially Compromised in Behavioral Health Network Malware Attack

Behavioral Health Network (BHN), the largest behavioral health service provider in Western Massachusetts, has announced that malware was downloaded onto its computer systems that prevented files from being accessed.

The security breach was discovered on May 28, 2020 when staff were prevented from accessing files. An investigation was immediately launched to determine the extent of the attack and whether any data had been exfiltrated by the attacker. Around July 17, 2020, BHN determined that an unauthorized individual had gained access to its systems on May 26, two days before the malware was introduced.

While it was not possible to determine whether any data had been stolen by the attacker prior to the deployment of the malware, the possibility of data theft could not be totally ruled out. No reports have been received to date indicating patient data has been misused.

An analysis of the affected systems revealed the protected health information of 129,571 current and former patients was potentially compromised. The systems that were accessible to the attacker contained names, addresses, dates of birth, Social Security numbers, medical/diagnosis/treatment information, and/or health insurance claim information.

Out of an abundance of caution, individuals affected by the incident have been offered complimentary credit monitoring and identity theft protection services. To help prevent further data breaches, policies and procedures are being reviewed, staff are being provided with further training on data privacy and security, and additional safeguards are being put in place to prevent further unauthorized data access.

9,200 Rite Aid Customers Notified PHI was Potentially Compromised During Period of Civil Unrest

Rite Aid Corporation has confirmed that the protected health information of 9,200 customers was potentially compromised during the period of civil unrest in late May. Several break-ins occurred at Rite Aid pharmacies. On and after May 27 and thieves stole prescription orders awaiting collection, along with hard copies of prescription records that contained customer information. The types of data exposed or stolen included names, addresses, and details of prescribed medications.

Rite Aid is far from the only pharmacy chain to have suffered break-ins and looting. Walgreens, Walmart, CVS, Cub, and Kroger pharmacies all suffered similar incidents, as did many independent pharmacies.

The post Protected Health Information of 129K Individuals Potentially Compromised in Behavioral Health Network Malware Attack appeared first on HIPAA Journal.

Data Breaches Reported by University of Maryland Faculty Physicians and Highpoint Foot & Ankle Center

The University of Maryland Faculty Physicians, Inc. (FPI) has suffered a phishing attack in which the protected health information of patients of University of Maryland Medical Center (UMMC) may have been accessed by unauthorized individuals.

FPI is the faculty practice plan for University of Maryland School of Medicine affiliated physician practice groups and provides support to physicians and staff who provide services at UMMC locations.

Following the discovery of the unauthorized accessing of an FPI email account, the account was secured and a comprehensive investigation was conducted to determine the nature and scope of the breach. On May 26, 2020, FPI determined the email account was accessed by an unauthorized individual between February 6, 2020 and February 11, 2020. The email account contained the protected health information of 33,896 individuals.

The types of information in the account varied from patient to patient and may have included the following data types in addition to patient names: Date of birth, medical record number, and clinical information related to the care received at a UMMC location or from an FPI-affiliated physician. A small number of Social Security numbers were also found in emails and email attachments. No evidence was uncovered suggesting patient data was viewed or obtained by the attacker.

FPI and UMMC have conducted a review of policies and procedures and steps have been taken to improve email security to prevent further breaches in the future.

Records of 25,554 Patients of Highpoint Foot & Ankle Center Potentially Compromised

Highpoint Foot & Ankle Center in Chalfont, PA has discovered an unauthorized individual conducted a remote access attack and gained access to systems containing 25,554 patient records. The security breach was detected on May 20, 2020 and prompt action was taken to prevent further unauthorized system access.

An internal investigation was immediately launched which revealed the hacker had access to patient records that contained patient names, addresses, dates of birth, phone numbers, Social Security numbers, and diagnosis and treatment information. While unauthorized access was confirmed, no evidence was found that indicated patient information was viewed or copied and no reports have been received suggesting patient data has been misused.

Highpoint Foot & Ankle Center has implemented additional safeguards to prevent further security breaches and has offered affected patients complimentary membership to credit monitoring and identity theft protection services through MyIDCare.

The post Data Breaches Reported by University of Maryland Faculty Physicians and Highpoint Foot & Ankle Center appeared first on HIPAA Journal.

Ashley County Medical Center Nurse Terminated for Improper Medical Record Access

A former employee of Ashley County Medical Center has been discovered to have accessed the medical records of 722 patients without authorization.

Ashley County Medical Center launched an investigation into the HIPAA violation and determined the nurse had viewed limited patient data for reasons unrelated to the provision of care or treatment. Ashley County Medical Center does not believe any patient information was shared with a third party or accessed with a view to misusing the data. Patient information is believed to have been accessed out of curiosity.

Ashley County Medical Center has a sanctions policy in place covering unauthorized medical record access, and in line with that policy the nurse was terminated for the HIPAA violation.

“Patient privacy is an extremely serious matter and any failure to protect patient information will subject employees to disciplinary actions,” said Phillip Gilmore, Chief Executive Officer, ACMC. “We are continuing to take steps to report the actions of this employee, notify any additional patients whose information was viewed, continuing to diligently monitor and protect patient information, and provide additional education to our staff.”

San Antonio Hospital Exposed Patient Data Online

The protected health information of 1,237 patients of Foundation Surgical Hospital of San Antonio in Texas has been accidentally exposed over the internet.

On January 29, 2020, the hospital posted a link on its website to a file that was supposed to show average hospital charges; however, the file linked via the website contained patients’ names, diagnosis codes, patient account numbers, procedure dates, charges and amount paid, and whether the charges had been paid, were due, or had been written off. The incorrect document was reported to the hospital and the link was removed on May 27, 2020.

The post Ashley County Medical Center Nurse Terminated for Improper Medical Record Access appeared first on HIPAA Journal.

Almost 20,000 Patients Affected by Owens Ear Center Ransomware Attack

Owens Ear Center in Fort Worth, TX, suffered a ransomware attack on May 28, 2020 in which patient information was encrypted. The computer systems that were encrypted contained patients’ medical records, which included information such as names, addresses, dates of birth, health insurance information, health information, and Social Security numbers.

Many ransomware attacks on healthcare organizations see healthcare data stolen before it is encrypted. These double extortion attacks require a ransom to be paid in order to decrypt files and prevent the sale or publication of the stolen data. Owens Ear Center investigated the attack and found no evidence to indicate patient information was accessed or copied prior to file encryption and believes this was solely an attempt to extort money from the practice and that the attackers were not interested in patient data.

However, since unauthorized data access could not be ruled out, all affected patients have been notified and, out of an abundance of caution, have been offered complimentary identity theft protection services. Steps have since been taken to improve defenses against ransomware attacks.

According to the breach summary on the HHS’ Office for Civil Rights breach portal, the PHI of 19,908 patients was encrypted in the attack.

Children’s Hospital of Pittsburgh Foundation Affected by Blackbaud Inc. Ransomware Attack

Children’s Hospital of Pittsburgh Foundation has been notified by one of its business associates that the protected health information of some of its patients has potentially been accessed by unauthorized individuals.

Blackbaud Inc., a provider of customer relationship management systems for non-profit organizations, suffered a ransomware attack and a file containing limited patient data was accessed by the attacker. The incident occurred between February 7, 2020 and May 20, 2020.

The file contained information such as patients’ names, addresses, birth dates and other general demographic data. Blackbaud paid the ransom and was able to recover its data. Blackbaud does not believe any data was shared with any third party or was made public.

Blackbaud was able to quickly identify and correct the vulnerability that was exploited, and security of its IT systems has been hardened, including making improvements to access management, network segmentation, and the deployment of additional endpoint and network-based platforms.

Email Account Breach Identified by Premier Healthcare Partners

Premier Healthcare Partners in Dayton, OH has discovered an unauthorized individual has gained access to the email accounts of some of its employees and potentially viewed or obtained the protected health information of certain patients of the Clinical Neuroscience Institute, Help Me Grow Brighter Futures, Samaritan Behavioral Health Inc. (SBHI), and CompuNet Clinical Laboratories.

Upon discovery of the breach the accounts were immediately secured, and an investigation was launched to determine the nature and scope of the breach. The breach was detected on June 8, 2020 and it was confirmed on July 17 that email accounts had been accessed by an individual with no connection to Premier Healthcare Partners.

A comprehensive review of the breached email accounts is currently underway and affected patients will be notified if their PHI has been exposed when the review has been completed. At this stage, no evidence has been found to indicate PHI has been accessed, copied, or misused.

The post Almost 20,000 Patients Affected by Owens Ear Center Ransomware Attack appeared first on HIPAA Journal.

Four Healthcare Providers and a Ventilator Manufacturer Attacked with Ransomware

Long Island City, NY-based Boyce Technologies Inc, which makes transport communication systems and recently switched its production facilities to produce ventilators for hospitals during the pandemic, has been attacked with DoppelPaymer ransomware. Data was stolen prior to file encryption and a sample of the stolen data has been published on the threat actor’s blog. The stolen data includes purchase orders, assignment forms, and other sensitive data.

Boyce Technologies Inc. was approved by the FDA to manufacture ventilators and was producing around 300 machines a day. Those ventilators have been used in hospitals in New York and the company is now making ventilators for other areas. The ransomware attack has threatened the production of those ventilators and has potentially put lives at risk.

Piedmont Orthpedics/OrthoAtlanta, a network of orthopedic and sports medicine centers in the greater Atlanta area, has been attacked by threat actors using Pysa (Mespinosa) ransomware. As with the attack on Boyce Technologies, prior to the encryption of files the threat actors exfiltrated sensitive data. According to databreaches.net, around 3.5 GB of data have been published online, including files that contain patients’ protected health information. Olympia House Rehab in Petaluma, CA and the Center for Fertility and Gynecology in Los Angeles, CA have both been attacked with Netwalker ransomware and have had data stolen and published online, including patients’ protected health information.

Muskingum Valley Health Centers in Zanesville, OH notified has recently notified 7,447 patients that some of their protected health information was potentially obtained by threat actors prior to the use of ransomware on the medical record system used by OB GYN Specialists of Southeastern Ohio Inc.

The EHR contained the records of patients who received care between 2012 and 2017. The attack occurred on May 31, 2020 and was identified on June 2. The investigation found no evidence suggesting patient information was stolen prior to the use of ransomware, although the possibility of data theft could not be ruled out. The attackers potentially had access to names, dates of birth, addresses, Social Security numbers, diagnoses, medical conditions, lab test results, treatment information, insurance claim information, and financial information. Affected individuals have been offered 24 months of complimentary credit monitoring and identity theft recovery services. Security policies, procedures and password requirements have been updated to prevent further attacks.

41 healthcare providers reported ransomware attacks in the first half of 2020 according to Emsisoft. The double-extortion attacks involving threats to publish or sell data if the ransom is not paid are growing, with many threat groups now adopting this tactic. According to Emsisoft, around 1 in 10 ransomware attacks now involve data theft.

The post Four Healthcare Providers and a Ventilator Manufacturer Attacked with Ransomware appeared first on HIPAA Journal.

Children’s Hospital Colorado Suffers Phishing Attack

Children’s Hospital Colorado is notifying 2,553 patients that some of their protected health information was stored in an email account that was accessed by an unauthorized individual between April 6-12, 2020.

Credentials to access the account were obtained when an employee responded to a phishing email. The phishing attack was identified by the hospital on June 22, 2020 and the account was immediately secured. A review of the emails and email attachments in the account revealed they contained patient names, zip codes, dates of service, medical record numbers, and clinical diagnosis information.

Steps have since been taken to harden email security defenses, platforms are being evaluated for educating staff on cybersecurity, and technical controls related to email are also being reviewed.

Stolen Hoag Clinic Laptop Contained Unencrypted PHI

On June 5, 2020, a laptop computer issued to an employee of the Hoag Clinic in Costa Mesa, CA was stolen from a vehicle parked in the worksite parking lot in Newport Beach. The theft was discovered the same day and law enforcement was notified, but the laptop computer has not been recovered.

The IT security team determined the laptop contained the protected health information of 738 individuals, including first and last names, middle initial, address, phone number, date of birth, age, medical record number, e-mail address, physician name, whether the patient is being followed by case management, if a COVID-19 test has been conducted, if the individual had been transferred to case management, if a telehealth visit had been scheduled, communication status notes, and if the individual was interested in home health.

The Hoag clinic has re-educated the workforce on security safeguards, enhanced policies covering the transportation of laptop computers between worksites, and a thorough security assessment has been conducted to ensure all appropriate cybersecurity safeguards are in place. Affected individuals have been offered complimentary membership to the Experian IdentityWorks identity theft detection and resolution service for 12 months.

The post Children’s Hospital Colorado Suffers Phishing Attack appeared first on HIPAA Journal.