Signify Health notifies covered entities’ patients of possible access to their PHI

Signify Health, LLC is a business associate to entities covered under HIPAA.  On October 12, 2020, they discovered that an employee had published his login credentials to a subscription-based job board. The employee, described as a low-level IT Support… Continue reading Signify Health notifies covered entities’ patients of possible access to their PHI

310,000 Records Compromised In University Of Colorado Data Breach, Including Social Security Numbers & University Financial Information

Audra Streetman reports: The University of Colorado released new information on Friday about the Accellion data breach that compromised more than 310,000 university records. Officials say the data accessed in the breach includes personally identifiable… Continue reading 310,000 Records Compromised In University Of Colorado Data Breach, Including Social Security Numbers & University Financial Information

Administrative Advantage notifies patients of Remedy Medical Group after email hack

Remedy Medical Group is a pain management specialty practice in California. Their web site indicates that they are consultants to some professional sports teams in their area.  Did a breach involving some of their patients’ data also impact any p… Continue reading Administrative Advantage notifies patients of Remedy Medical Group after email hack

Class action lawsuit filed against Roper St. Francis Healthcare over multiple data breaches

Regular readers may recall that September, 2020 was not a good month for St. Roper Francis, and DataBreaches.net had to explain that the healthcare system was dealing with notifications from two unrelated breaches. One involved 6,000 patients impacted … Continue reading Class action lawsuit filed against Roper St. Francis Healthcare over multiple data breaches

Good Luck Explaining to HHS Why Your PHI is in GitHub’s Vault for the Next 1,000 Years

You may see a number of hospitals and covered entities issuing statements this week about a data security incident involving Med-Data (Med-Data, Incorporated). So far, Memorial Hermann, U. of Chicago, Aspirus, and OSF Healthcare have posted notices. Ot… Continue reading Good Luck Explaining to HHS Why Your PHI is in GitHub’s Vault for the Next 1,000 Years

Update on education sector clients impacted by Blackbaud ransomware incident

I don’t know how he finds the energy to do it, but Marco A. DeFelice (@amvinfe on Twitter) continues to track disclosures involving Blackbaud’s ransomware incident of 2020.  He has organized his tabulations by whether the entities are hospi… Continue reading Update on education sector clients impacted by Blackbaud ransomware incident

GA: Cyberattack on Cobb schools enabled by contractor’s weak password, police say

Kristal Dixon reports: An attack on the Cobb County School District’s crisis management system that forced all schools into lockdown last month happened because of a weak password, according the police. The password was not created by a school district… Continue reading GA: Cyberattack on Cobb schools enabled by contractor’s weak password, police say

FL: School officials investigate possible breach involving firm they never used

John Henderson reports: Alachua County school officials are investigating whether students’ personal information was compromised after a data breach in a computer system connected to school meal programs. The district notified families of school … Continue reading FL: School officials investigate possible breach involving firm they never used