writing.exchange is one of the many independent Mastodon servers you can use to participate in the fediverse.
A small, intentional community for poets, authors, and every kind of writer.

Administered by:

Server stats:

334
active users

#healthsec

1 post1 participant1 post today
Dissent Doe :cupofcoffee:<p>UnitedHealth's Change Healthcare got a ton of what some might consider well-deserved bad press last year after a ransomware attack by AlphV/BlackCat. </p><p>Now they're getting more bad press. </p><p>UnitedHealth is demanding that some struggling doctors immediately repay loans issued after last year’s cyberattack. That wasn't the way the providers were told repayment would work in terms of when and how. </p><p><a href="https://infosec.exchange/tags/CNBC" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>CNBC</span></a> has the story:</p><p><a href="https://www.cnbc.com/2025/04/11/unitedhealth-makes-doctors-repay-loans-issued-after-change-cyberattack.html" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">cnbc.com/2025/04/11/unitedheal</span><span class="invisible">th-makes-doctors-repay-loans-issued-after-change-cyberattack.html</span></a></p><p><a href="https://infosec.exchange/tags/IncidentResponse" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>IncidentResponse</span></a> <a href="https://infosec.exchange/tags/databreach" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>databreach</span></a> <a href="https://infosec.exchange/tags/ransomware" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>ransomware</span></a> <a href="https://infosec.exchange/tags/healthsec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>healthsec</span></a></p>
Dissent Doe :cupofcoffee:<p>From the We-Wish-This-Was-An-April-Fools-Joke-But-It’s-Not department:</p><p>Vitenas Cosmetic Surgery patient data hacked and leaked</p><p><a href="https://databreaches.net/2025/04/01/vitenas-cosmetic-surgery-patient-data-hacked-and-leaked/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">databreaches.net/2025/04/01/vi</span><span class="invisible">tenas-cosmetic-surgery-patient-data-hacked-and-leaked/</span></a></p><p><a href="https://infosec.exchange/tags/databreach" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>databreach</span></a> <a href="https://infosec.exchange/tags/extortion" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>extortion</span></a> <a href="https://infosec.exchange/tags/healthsec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>healthsec</span></a></p>
Dissent Doe :cupofcoffee:<p>Oracle Health is becoming the poster child for how NOT to respond to a breach:</p><p><a href="https://www.bleepingcomputer.com/news/security/oracle-health-breach-compromises-patient-data-at-us-hospitals/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">bleepingcomputer.com/news/secu</span><span class="invisible">rity/oracle-health-breach-compromises-patient-data-at-us-hospitals/</span></a></p><p><a href="https://infosec.exchange/tags/healthsec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>healthsec</span></a> <a href="https://infosec.exchange/tags/cybersecurity" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>cybersecurity</span></a> <a href="https://infosec.exchange/tags/databreach" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>databreach</span></a> <a href="https://infosec.exchange/tags/incidentresponse" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>incidentresponse</span></a> <a href="https://infosec.exchange/tags/HIPAA" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>HIPAA</span></a> <a href="https://infosec.exchange/tags/transparency" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>transparency</span></a></p>
Dissent Doe :cupofcoffee:<p>Four months after learning of a vendor's breach, Concord Orthopaedics in NH notifies almost 68,000 patients. </p><p>At the same time that they were mailing notifications, <a href="https://infosec.exchange/tags/EverestTeam" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>EverestTeam</span></a> was leaking 2.9 GB of files with patient info from 2018-2024. </p><p><a href="https://databreaches.net/2025/03/27/four-months-after-learning-of-a-vendors-breach-concord-orthopaedics-notifies-almost-68000-patients/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">databreaches.net/2025/03/27/fo</span><span class="invisible">ur-months-after-learning-of-a-vendors-breach-concord-orthopaedics-notifies-almost-68000-patients/</span></a></p><p><a href="https://infosec.exchange/tags/databreach" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>databreach</span></a> <a href="https://infosec.exchange/tags/healthsec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>healthsec</span></a> <a href="https://infosec.exchange/tags/cybersecurity" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>cybersecurity</span></a> <a href="https://infosec.exchange/tags/ThirdParty" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>ThirdParty</span></a> <a href="https://infosec.exchange/tags/vendor" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>vendor</span></a> <a href="https://infosec.exchange/tags/HIPAA" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>HIPAA</span></a></p>
Dissent Doe :cupofcoffee:<p>Health-care billing company Medical Billing Specialists Inc. (MBS Select) has been hit with a potential class action lawsuit over their 2024 breach.</p><p>Notifications first went out a year after the attack by Akira ransomware group. </p><p><a href="https://databreaches.net/2025/02/26/medical-billing-vendor-sued-over-health-data-leak-gold-mine/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">databreaches.net/2025/02/26/me</span><span class="invisible">dical-billing-vendor-sued-over-health-data-leak-gold-mine/</span></a></p><p>h/t, Bloomberg Law.</p><p>Direct link to complaint: <a href="https://www.bloomberglaw.com/public/desktop/document/MarianoGuerravMedicalBillingSpecialistsIncDocketNo125cv10453DMass?doc_id=X7V6GF8O0QV9EOAVLKEKKSJCO87" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">bloomberglaw.com/public/deskto</span><span class="invisible">p/document/MarianoGuerravMedicalBillingSpecialistsIncDocketNo125cv10453DMass?doc_id=X7V6GF8O0QV9EOAVLKEKKSJCO87</span></a></p><p><a href="https://infosec.exchange/tags/BAA" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>BAA</span></a> <a href="https://infosec.exchange/tags/databreach" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>databreach</span></a> <a href="https://infosec.exchange/tags/healthsec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>healthsec</span></a> <a href="https://infosec.exchange/tags/ransomware" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>ransomware</span></a> <a href="https://infosec.exchange/tags/notification" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>notification</span></a></p>
Dissent Doe :cupofcoffee:<p>From Bluesight's press release for the 2025 Breach Barometer, some of the key findings:</p><ul><li><p>More than 300 million patient records breached in 2024, a 26% increase over 2023. This included the largest healthcare breach ever recorded, affecting 1 in 2 Americans.</p></li><li><p>Insider threats, hackers and third-party relationships drove breach impact in 2024, with business associates accounting for the majority of breached records (77%) in the 2025 Breach Barometer dataset.</p></li><li><p>Breach notifications took an average of 205 days&nbsp;after an incident in 2024, compared to 177 days in the previous year.</p></li></ul><p>I'll have more details on some of these issues on my blog in the near future, but encourage you to download the full report now: </p><p><a href="https://bluesight.com/wp-content/uploads/2025/02/2025-Breach-Barometer-Annual-Report.pdf" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">bluesight.com/wp-content/uploa</span><span class="invisible">ds/2025/02/2025-Breach-Barometer-Annual-Report.pdf</span></a></p><p>For those of you that read the Protenus Breach Barometer report I produced with Protenus every year beginning in 2016, Bluesight recently acquired Protenus and is continuing to produce the report in collaboration with my work. </p><p><a href="https://infosec.exchange/tags/databreach" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>databreach</span></a> <a href="https://infosec.exchange/tags/healthsec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>healthsec</span></a> <a href="https://infosec.exchange/tags/statistics" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>statistics</span></a> <a href="https://infosec.exchange/tags/analysis" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>analysis</span></a> <a href="https://infosec.exchange/tags/BAA" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>BAA</span></a></p>
Dissent Doe :cupofcoffee:<p>Update: On February 24, 2025, the Termite ransomware group claimed responsibility for the attack on Genea, a network of fertility (IVF) clinics in Australia.</p><p>On their dark web leak site, Termite claims to have ~700 GB of data from Genea's servers,, including patient data. They posted a number of screenshots with patient records as proof of claims.&nbsp;</p><p><a href="https://infosec.exchange/tags/Genea" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Genea</span></a> <a href="https://infosec.exchange/tags/databreach" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>databreach</span></a> <a href="https://infosec.exchange/tags/IVF" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>IVF</span></a> <a href="https://infosec.exchange/tags/ransomware" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>ransomware</span></a> <a href="https://infosec.exchange/tags/healthsec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>healthsec</span></a> <a href="https://infosec.exchange/tags/cybersecurity" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>cybersecurity</span></a> <a href="https://infosec.exchange/tags/Termite" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Termite</span></a></p><p><span class="h-card" translate="no"><a href="https://mastodon.social/@David_Hollingworth" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>David_Hollingworth</span></a></span></p>
Dissent Doe :cupofcoffee:<p>Beverly Hills Plastic Surgeon Jaime Schwartz M.D. Sued for Not Timely Notifying Patients of Two Hacks: <a href="https://databreaches.net/2025/02/22/beverly-hills-plastic-surgeon-jaime-schwartz-m-d-sued-for-not-timely-notifying-patients-of-two-hacks/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">databreaches.net/2025/02/22/be</span><span class="invisible">verly-hills-plastic-surgeon-jaime-schwartz-m-d-sued-for-not-timely-notifying-patients-of-two-hacks/</span></a></p><p>h/t, <a href="https://infosec.exchange/tags/404media" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>404media</span></a> <a href="https://infosec.exchange/tags/Courtwatch" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Courtwatch</span></a> </p><p><a href="https://infosec.exchange/tags/databreach" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>databreach</span></a> <a href="https://infosec.exchange/tags/extortion" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>extortion</span></a> <a href="https://infosec.exchange/tags/incident_response" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>incident_response</span></a> <a href="https://infosec.exchange/tags/notification" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>notification</span></a> <a href="https://infosec.exchange/tags/transparency" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>transparency</span></a> <a href="https://infosec.exchange/tags/hack" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>hack</span></a> <a href="https://infosec.exchange/tags/healthsec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>healthsec</span></a></p>
Dissent Doe :cupofcoffee:<p>So remember the ransomware attack discovered last July by Columbus, Ohio -- who raced to court to chill the speech of a researcher (David Ross, aka "Goodwolf") who disputed their claims about the breach? </p><p>Well, now it comes out that there was also some medical info from emergency services involved in the breach: </p><p><a href="https://spectrumnews1.com/oh/columbus/news/2025/02/04/health-information-columbus-cyberattack" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">spectrumnews1.com/oh/columbus/</span><span class="invisible">news/2025/02/04/health-information-columbus-cyberattack</span></a></p><p>They discovered the medical stuff in December and are first sending out letters to those affected now. </p><p><a href="https://infosec.exchange/tags/databreach" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>databreach</span></a> <a href="https://infosec.exchange/tags/govsec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>govsec</span></a> <a href="https://infosec.exchange/tags/healthsec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>healthsec</span></a> <a href="https://infosec.exchange/tags/ransomware" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>ransomware</span></a> <a href="https://infosec.exchange/tags/Rhysida" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Rhysida</span></a></p>
Dissent Doe :cupofcoffee:<p>Delta County Memorial Hospital District reveals more about 2024 cyberattack that affected 148,363 people: </p><p><a href="https://databreaches.net/2025/02/03/delta-county-memorial-hospital-district-reveals-more-about-2024-cyberattack-that-affected-148363-people/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">databreaches.net/2025/02/03/de</span><span class="invisible">lta-county-memorial-hospital-district-reveals-more-about-2024-cyberattack-that-affected-148363-people/</span></a></p><p><a href="https://infosec.exchange/tags/healthsec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>healthsec</span></a> <a href="https://infosec.exchange/tags/databreach" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>databreach</span></a> <a href="https://infosec.exchange/tags/cyberattack" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>cyberattack</span></a> <a href="https://infosec.exchange/tags/HIPAA" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>HIPAA</span></a></p>
Dissent Doe :cupofcoffee:<p>Cover-up Follow-up: Westend Dental starts notifying patients of October 2020 ransomware attack: </p><p><a href="https://databreaches.net/2025/02/02/cover-up-follow-up-westend-dental-starts-notifiying-patients-of-october-2020-ransomware-attack/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">databreaches.net/2025/02/02/co</span><span class="invisible">ver-up-follow-up-westend-dental-starts-notifiying-patients-of-october-2020-ransomware-attack/</span></a></p><p><a href="https://infosec.exchange/tags/databreach" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>databreach</span></a> <a href="https://infosec.exchange/tags/ransomware" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>ransomware</span></a> <a href="https://infosec.exchange/tags/incidentresponse" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>incidentresponse</span></a> <a href="https://infosec.exchange/tags/coverup" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>coverup</span></a> <a href="https://infosec.exchange/tags/healthsec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>healthsec</span></a> <a href="https://infosec.exchange/tags/HIPAA" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>HIPAA</span></a></p>
Dissent Doe :cupofcoffee:<p>As an update to previous reporting: </p><p>0mid16B leaked Apex Custom Software's Controlled Substance management software code... and employee login info from one of their healthcare clients. </p><p>Background here: </p><p><a href="https://databreaches.net/2025/01/30/exclusive-apex-custom-software-hacked-threat-actors-threaten-to-leak-the-software/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">databreaches.net/2025/01/30/ex</span><span class="invisible">clusive-apex-custom-software-hacked-threat-actors-threaten-to-leak-the-software/</span></a></p><p><a href="https://infosec.exchange/tags/databreach" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>databreach</span></a> <a href="https://infosec.exchange/tags/business_associate" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>business_associate</span></a> <a href="https://infosec.exchange/tags/HIPAA" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>HIPAA</span></a> <a href="https://infosec.exchange/tags/healthsec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>healthsec</span></a> <a href="https://infosec.exchange/tags/cybersecurity" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>cybersecurity</span></a></p>
Dissent Doe :cupofcoffee:<p>So... apart from the fact that I don't think they should have dropped charges against this doctor, is HHS going to investigate why the hospital gave access to patient data to a former employee/resident who no longer worked there and was never these patients' doctor? </p><p>US Justice Department drops case against Texas doctor charged with leaking transgender care data:<br><a href="https://www.wfaa.com/article/news/local/us-justice-department-drops-case-against-doctor-charged-with-leaking-transgender-care-data/287-3e8a394d-41fb-41bf-bf72-fd012b87851b" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">wfaa.com/article/news/local/us</span><span class="invisible">-justice-department-drops-case-against-doctor-charged-with-leaking-transgender-care-data/287-3e8a394d-41fb-41bf-bf72-fd012b87851b</span></a></p><p><a href="https://infosec.exchange/tags/HealthSec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>HealthSec</span></a> <a href="https://infosec.exchange/tags/HIPAA" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>HIPAA</span></a> <a href="https://infosec.exchange/tags/SecurityRule" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SecurityRule</span></a> <a href="https://infosec.exchange/tags/databreach" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>databreach</span></a> <a href="https://infosec.exchange/tags/privacy" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>privacy</span></a> <a href="https://infosec.exchange/tags/confidentiality" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>confidentiality</span></a> <a href="https://infosec.exchange/tags/insiderthreat" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>insiderthreat</span></a> <a href="https://infosec.exchange/tags/HHS" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>HHS</span></a> <a href="https://infosec.exchange/tags/HHSOCR" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>HHSOCR</span></a></p>
Dissent Doe :cupofcoffee:<p>HCF Management healthcare facilities hit by ransomware attack; more than 70,000 patients affected:</p><p><a href="https://databreaches.net/2025/01/24/hcf-management-healthcare-facilities-hit-by-ransomware-attack-more-than-70000-patients-affected/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">databreaches.net/2025/01/24/hc</span><span class="invisible">f-management-healthcare-facilities-hit-by-ransomware-attack-more-than-70000-patients-affected/</span></a></p><p><a href="https://infosec.exchange/tags/ransomware" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>ransomware</span></a> <a href="https://infosec.exchange/tags/databreach" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>databreach</span></a> <a href="https://infosec.exchange/tags/healthsec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>healthsec</span></a> <a href="https://infosec.exchange/tags/businessassociate" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>businessassociate</span></a> <a href="https://infosec.exchange/tags/disclosure" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>disclosure</span></a> <a href="https://infosec.exchange/tags/transparency" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>transparency</span></a> <a href="https://infosec.exchange/tags/notification" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>notification</span></a> <a href="https://infosec.exchange/tags/RansomHub" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>RansomHub</span></a></p>
Dissent Doe :cupofcoffee:<p>NEW: MedSave Health Insurance TPA hacked; firm has yet to comment or respond</p><p><a href="https://databreaches.net/2025/01/17/medsave-health-insurance-tpa-hacked-firm-has-yet-to-comment-or-respond/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">databreaches.net/2025/01/17/me</span><span class="invisible">dsave-health-insurance-tpa-hacked-firm-has-yet-to-comment-or-respond/</span></a></p><p><a href="https://infosec.exchange/tags/databreach" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>databreach</span></a> <a href="https://infosec.exchange/tags/healthsec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>healthsec</span></a> <a href="https://infosec.exchange/tags/TPA" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>TPA</span></a> <a href="https://infosec.exchange/tags/cybersecurity" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>cybersecurity</span></a> <a href="https://infosec.exchange/tags/hack" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>hack</span></a> <a href="https://infosec.exchange/tags/MedSave" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>MedSave</span></a></p>
Dissent Doe :cupofcoffee:<p>Nine months after discovering a ransomware attack, Teton Orthopaedics notifies patients: <a href="https://databreaches.net/2025/01/12/nine-months-after-discovering-a-ransomware-attack-teton-orthopaedics-notifies-patients/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">databreaches.net/2025/01/12/ni</span><span class="invisible">ne-months-after-discovering-a-ransomware-attack-teton-orthopaedics-notifies-patients/</span></a></p><p><a href="https://infosec.exchange/tags/databreach" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>databreach</span></a> <a href="https://infosec.exchange/tags/ransomware" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>ransomware</span></a> <a href="https://infosec.exchange/tags/healthsec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>healthsec</span></a> <a href="https://infosec.exchange/tags/HIPAA" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>HIPAA</span></a> <a href="https://infosec.exchange/tags/incidentresponse" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>incidentresponse</span></a> <a href="https://infosec.exchange/tags/DragonForce" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>DragonForce</span></a></p>
Dissent Doe :cupofcoffee:<p>Westend Dental agrees to pay Indiana $350K and to implement a corrective action plan to settle charges of multiple HIPAA violations.</p><p>This is one of THE WORST incident responses I have ever read and I've read a lot of bad ones over the years. But it's not just an incident response disaster. They were routinely violating HIPAA privacy and security rules.</p><p>Kudos to the state of Indiana for going after the dental practice and investigating to find out all the problems. </p><p>Don't ask me what HHS OCR did, because I don't think they were ever even told about this 2020 ransomware attack.</p><p>Read more here, where you will also find the court filings I've uploaded so you can read how bad this one was:</p><p><a href="https://databreaches.net/2024/12/31/westend-dental-agrees-to-pay-indiana-350k-and-to-implement-corrective-action-plan-to-settle-charges-of-multiple-hipaa-violations/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">databreaches.net/2024/12/31/we</span><span class="invisible">stend-dental-agrees-to-pay-indiana-350k-and-to-implement-corrective-action-plan-to-settle-charges-of-multiple-hipaa-violations/</span></a></p><p><a href="https://infosec.exchange/tags/ransomware" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>ransomware</span></a> <a href="https://infosec.exchange/tags/compliance" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>compliance</span></a> <a href="https://infosec.exchange/tags/HIPAA" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>HIPAA</span></a> <a href="https://infosec.exchange/tags/healthsec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>healthsec</span></a> <a href="https://infosec.exchange/tags/encryption" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>encryption</span></a> <a href="https://infosec.exchange/tags/backup" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>backup</span></a> <a href="https://infosec.exchange/tags/PrivacyRule" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>PrivacyRule</span></a> <a href="https://infosec.exchange/tags/SecurityRule" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SecurityRule</span></a> <a href="https://infosec.exchange/tags/ransparency" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>ransparency</span></a> <a href="https://infosec.exchange/tags/disclosure" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>disclosure</span></a> <a href="https://infosec.exchange/tags/notification" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>notification</span></a> </p><p><span class="h-card" translate="no"><a href="https://mastodon.social/@zackwhittaker" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>zackwhittaker</span></a></span> <span class="h-card" translate="no"><a href="https://ioc.exchange/@jgreig" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>jgreig</span></a></span></p>
Dissent Doe :cupofcoffee:<p>It appears Brain Cipher did leak the RIBridges data on their leak site, and it appears to be the same data they had provided to me pre-leak and that I described yesterday:</p><p><a href="https://databreaches.net/2024/12/30/more-details-emerge-about-ribridges-data-breach-deloitte-tells-state-threat-actors-have-leaked-data/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">databreaches.net/2024/12/30/mo</span><span class="invisible">re-details-emerge-about-ribridges-data-breach-deloitte-tells-state-threat-actors-have-leaked-data/</span></a></p><p>And no, none of the data I inspected was encrypted. </p><p>The leak site is still iffy to connect to.</p><p><a href="https://infosec.exchange/tags/databreach" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>databreach</span></a> <a href="https://infosec.exchange/tags/ransom" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>ransom</span></a> <a href="https://infosec.exchange/tags/healthsec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>healthsec</span></a> <a href="https://infosec.exchange/tags/govsec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>govsec</span></a> <a href="https://infosec.exchange/tags/Deloitte" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Deloitte</span></a> <a href="https://infosec.exchange/tags/cybersecurity" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>cybersecurity</span></a></p>
Dissent Doe :cupofcoffee:<p><span class="h-card" translate="no"><a href="https://infosec.exchange/@chum1ng0" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>chum1ng0</span></a></span> The notice on FALP's website today seems to acknowledge they are having some problems, but they do not say it is even a cyberattack. </p><p>But given their "problems" are occurring at the same time INC claims to have attacked them: heck no, I wouldn't fill out a form giving the entity my name, phone number, and rut. If we assume, for now, that INC did attack them, then we don't know if INC still has access. </p><p><a href="https://infosec.exchange/tags/databreach" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>databreach</span></a> <a href="https://infosec.exchange/tags/healthsec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>healthsec</span></a> <a href="https://infosec.exchange/tags/disclosure" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>disclosure</span></a> <a href="https://infosec.exchange/tags/transparency" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>transparency</span></a> <a href="https://infosec.exchange/tags/cybersecurity" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>cybersecurity</span></a> <a href="https://infosec.exchange/tags/FALP" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>FALP</span></a> <a href="https://infosec.exchange/tags/LATAM" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>LATAM</span></a></p>
Dissent Doe :cupofcoffee:<p><span class="h-card" translate="no"><a href="https://infosec.exchange/@chum1ng0" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>chum1ng0</span></a></span> According to the icons they use for the incident, INC did not encrypt/lock FALP. I'm not sure I understand what the "Stocks" icon means in terms of what they have done, or why nothing is available on FALP's site unless they are just being very cautious and pulled everything down to investigate?</p><p><a href="https://infosec.exchange/tags/databreach" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>databreach</span></a> <a href="https://infosec.exchange/tags/ransom" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>ransom</span></a> <a href="https://infosec.exchange/tags/healthsec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>healthsec</span></a> <a href="https://infosec.exchange/tags/Latam" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Latam</span></a> <a href="https://infosec.exchange/tags/oncology" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>oncology</span></a></p>