Cybersecurity Updates
- CynergisTek published report on cybersecurity in healthcare:
- 34% of IT employees surveyed indicate privacy is one of their core
responsibilities - $20.8 billion is total cost per year in the U.S. healthcare industry for EHR downtime causes by ransomware attacks.
- 64% of healthcare facilities have a “below passing score” for cybersecurity measures in place
- 34% of IT employees surveyed indicate privacy is one of their core
- The U.S. Justice Department announced that Russian hackers have accessed email accounts of 80% of employees working in the U.S.
- UF Health Central Florida notified an unknown number of patients that their PHI was exposed after ransomware attack on Leesburg Hospital of Florida.
- Wisconsin Institute of Urology is notifying an unknown number of patients that their PHI was exposed after email phishing attack.
- The federal government stated that the following were the largest healthcare breaches in July, 2021:
- Advocate Aurora Health of Wisconsin and Illinois
- McLaren Health of Michigan
- Intermountain Health of Utah
- Wayne County Health of Iowa
- Adena Fayette Medical Center of Ohio
- Oklahoma Heart Hospital
- CentraCare Health of Minnesota
- Texas Health Presbyterian
- St. Peter’s University Hospital of New Jersey
- West Holt Memorial Hospital of Nebraska
- Gastoenterology Consultants of Houston, TX notified 162,163 patients that their PHI was exposed after ransomware attack.
- Advanced Technology Ventures of Menlo Park, CA notified an unknown number of investors and customers that their info was exposed after ransomware attack.
- Lehigh Valley Health Network of Allentown, PA notified an unknown number of patients that their PHI was exposed after cybersecurity incident.
- Samaritan Medical Center of Watertown, NY encountered a data breach more than a year ago. Now, the hospital is still facing financial repercussions as its credit rating drops, according to an Aug. 4 Bloomberg Law report.
- had its credit rating "cut to junk," in a rare downgrade tied to cyberattacks, according to the report.
- University of New Mexico Health in Ålbuquerque, New Mexico notified an unknown number of patients that their PHI was exposed after recent hacking incident.
- KELA Intelligence published report that states the average price of access to a compromised company's network is only $1,000 from a Dark Web site
- credentials for virtual private networks (VPNs) and remote desktop protocol (RDP) servers the most common types of access sold
- access to large firms cost more and skewed the mean offering price to $5,400
- Enterprise Strategy Group reports on lack of people to fill open cybersecurity jobs.
- 57% of executives say shortage of cybersecurity skills has impacted place they work
- 62% say this has increased workload on existing employees
- 38% of security professionals report feeling burned out
- 50% report increase in stress
- 33% of cybersecurity workers report being harassed at work
- Coghlin Electrical Corp. of Worcester, Massachusetts notified an unknown number of customers that their info was exposed after ransomware attack.
- Arthur J. Gallagher Insurance of Rolling Meadows, IL was sued by clients as a result of their info being exposed during recent ransomware attack.
- Paxton Media Group of Paducah, KY notified an unknown number of employees and customers that their info was exposed after cyber attack.
- Pabalan Eye Center of Riverside, CA notified 50,000 patients their PHI was exposed after ransomware attack.
- The Los Angeles Fire Department of California notified 4,900 employees that their PHI was exposed after it was inadvertently placed on a publicly accessible website.
- Harris County government of Texas notified 26,000 citizens that their PHI was exposed after it was illegally accessed online.
- Express MRI, headquartered in Peachtree, GA notified an unknown number of patients that their PHI was exposed after email phishing attack.
- Star Refining of West Palm Beach, FL notified 1,910 dental patients that their PHI was exposed after email phishing attack.
- Wisconsin Institute of Urology of Neenah, WI notified an unknown number of patients that their PHI was exposed after email phishing attack.
- Translogic is notifying hospital customers of its pneumatic tube system that its Nexus Control Panel has security vulnerabilities.
- Standard Modern Company of Bedford, Massachusetts notified 2,707 patients of MassHealth that their PHI was exposed after data breach.
- Cayuga Medical Center of Ithaca, NY notified an unknown number of patients that their PHI was exposed after data breach.
- San Dieguito Public School District of California is being sued by a student who claims that a hacker access her info, changed her grades, and cyberstalked her.
- SonicWall Security published report on global cyberattack trends in 2021:
- Malware attacks down 22% to 2.5 billion
- Intrusion attempts up 9% to 2.5 trillion
- Cryptojacking attacks up 23% to 51.1 million
- Encrypted threats up 26% to 2.1 million
- IoT attacks up 59% to 32.2 million
- Ransomware attacks up 151% to 304.7 million
- Forescout Research Labs reports on 14 security vulnerabilities found in network connected devices that use NicheStack code to manage the TCP/IP stack.
- Named the vulnerability “INFRA:HALT”
- (did not name brands of MFPs that may use NicheStack)