Cybersecurity

CISA Releases Cybersecurity Guidance for Healthcare, Public Health Organizations

The US cybersecurity agency CISA has published new guidance to help healthcare and public health organizations understand the cyber threats and risks to their sector and apply mitigations. Titled Mitigation Guide: Healthcare and Public Health (HPH) Sector (PDF), the document was released as a supplemental companion to a Cyber Risk Summary distributed in July, and […]

Cybersecurity

Medical Transcriber’s Hack Breach Affects at Least 9 Million

3rd Party Risk Management , Breach Notification , Cybercrime Northwell Health Among Perry Johnson & Associates’ Healthcare Clients Affected Marianne Kolbasuk McGee (HealthInfoSec) • November 15, 2023     A data theft incident at medical transcription firm PJ&A has affected at least 9 million patients. (Image: Perry Johnson & Associates) The number of healthcare organizations […]

Cybersecurity

Medical firm reaches $100,000 settlement with HHS over 2017 ransomware attack

A Massachusetts-based medical management company has agreed to a $100,000 settlement with the U.S. Department of Health and Human Services following a 2017 ransomware attack. The company, Doctors’ Management Services — which provides medical billing and payer credentialing services — was attacked by the now-defunct GandCrab ransomware gang in April 2017, but the intrusion was […]

Cybersecurity

Arietis Health, LLC Announces MOVEit Data Breach Impacting Patients of NorthStar Anesthesia Facilities | JD Supra

On October 2, 2023, Arietis Health, LLC filed a notice of data breach with the Attorney General of Texas after discovering that a hacker exploited a vulnerability in the file-transfer application MOVEit, which was used by Arietis Health. In this notice, Arietis Health explains that the incident resulted in an unauthorized party being able to […]