Healthcare

Industry

Texan Level 1 Trauma Center Diverts Patients after Cyberattack Hits IT System

September 16, 2024

A ransomware attack on the only level 1 trauma center within 400 miles of Lubbock, Texas was forced to divert newly incoming emergency and non- emergency patients. The attack disrupted their IT systems.

A ransomware group identifying itself as Interlock claimed responsibility for the attack. Neither the HSCs nor UMC have confirmed or denied Interlock as the attacker. Insurance covered both the paid ransom amount paid and recovery costs.

read more

Half of Estonian Population affected in Data Breach at Healthcare Supplier Allium UPI OÜ

April 4, 2024

Allium UPI OÜ, a major supplier of pharmacy and hospital supplies in Estonia, Latvia and Lithuania is informing its Estonian customers about a data leak. According to the report almost half of the Estonian population is affected by a cyberattack on a customer card system for pharmacies. Those affected are now being informed. The data breach comprised information from the years 2014 to 2020, since it concerned a backup copy of a database that did not hold real-time information.

read more

Cyberattack at Belgium Goed pharmacies and home care stores

March 18, 2024

The network of Goed pharmacies and home care stores, has been the target of a cyber attack. Hackers managed to steal and encrypt data.

Goed’s home care stores and pharmacies remain open in the meantime, but are experiencing some disruptions. For example, payment with Bancontact is not possible everywhere and there are problems consulting digital prescriptions.

“A restart plan is being worked on to restart our systems step by step and in a controlled manner in the coming hours and days.”

read more

Cyberattack on US Provider of Medical Products

March 27, 2024

On or about March 27, 2024, OraSure Technologies determined that it had experienced a cybersecurity incident in which an unauthorized third party gained access to portions of its information environment.

On April 10, 2024, OraSure Technologies reported the incident in a Form 8-K filing, according to the filing, OraSure Technologies’ investigation into the extent of the incident remains ongoing.

read more

Customers affected after Cyberattack at Swedish IT Company

February 6, 2024

IT provider Advania was hit by a cyber attack on Tuesday attack.
Around 60 of the company’s customers are affected, of which between 10 and 15 are healthcare centres. “We cannot read any medical records or take any samples and can only write paper prescriptions. We cannot receive any patients,” says Per Svensson, director of operations at Herkules care center in Borås, to Borås Tidning. Some health centers have closed completely on Wednesday, while others receive patients on drop-in and write with paper and pencil because they do not have access to the medical record system.

There is no indication that ransomware has been introduced into the system. There is currently no forecast for when the problem may be fixed.

read more

Systems Offline at National Health Laboratory Service (NHLS) in South Africa

June 26, 2024

The National Health Laboratory Service (NHLS) has confirmed that it experienced an information technology (IT) security breach compromising its systems and infrastructure. A preliminary investigation, suggests that no patient data has been lost or compromised. The organisation’s systems remain inaccessible both internally and externally, including to and from healthcare facilities until the integrity of the environment is secured and repaired.

“It has been established that sections of our system have been deleted, including in our backup server and this will require rebuilding the affected parts. Stakeholders and the public will be informed as soon as more information becomes available. all of its laboratories are currently fully functional and are receiving and processing clinical samples.

Under normal circumstances, the laboratory reports are automatically generated and sent to clinicians or made available on web view, but the incident has disabled that functionality. “However, all urgent results are communicated telephonically to requesting clinicians.”

read more

Safety Equipment Giant Cadre Holdings’ Shut Down some Systems after Cyberattack

July 15, 2024

Florida-based safety equipment giant Cadre Holdings disclosed a cyberattack. In response to the incident, some systems were shut down, which impacted some of the company’s operations.

Cadre Holdings has stated that while some operations have been impacted, it is currently unclear whether the breach will materially affect the company’s financial health or operational results.

read more

Philippines Maxicare Hit by Cyberattack

June 21, 2024

Health maintenance organization Maxicare on June 19, confirmed a data breach that exposed personal information of 13,000 members representing less than 1 percent of its membership base

The exposed records are believed to be of those who used Lab@Home, a booking platform of their third-party home-care provider. It added that Lab@Home maintained a separate database for booking requests, which is not integrated with Maxicare’s system. The company also affirmed customers that its business operations, network, and customer data has not been impacted in any way.

read more

HHS Settles BCAA HIPAA Cybersecurity Violations Investigation for $90K

November 12, 2022

The breach at BCAA (Brian County Ambulance Authority), reported to OCR in May 2022, resulted in the encryption of files containing the ePHI of 14,273 patients. OCR’s investigation revealed that BCAA had not conducted a compliant risk analysis to identify potential risks and vulnerabilities to ePHI in its systems, a fundamental requirement under the HIPAA Security Rule.

Under the terms of the resolution agreement, BCAA has agreed to pay $90,000 and adopt a corrective action plan, which will be monitored by OCR over the next three years

read more