After cyber attack, New York hospitals find stolen patient info stored in Massachusetts, look for its return

Jeff Cole reports: Nearly four months after a cyber attack, Claxton-Hepburn Medical Center and Carthage Area Hospital have made progress in learning what stolen data may have been leaked, and where it was being stored. Now the hospitals have filed lega… Continue reading After cyber attack, New York hospitals find stolen patient info stored in Massachusetts, look for its return

Attorney General James Secures $300,000 from NewYork-Presbyterian Hospital for Failing to Protect Patient Data

December 27 NEW YORK – New York Attorney General Letitia James today secured $300,000 from The NewYork-Presbyterian Hospital (NYP) for disclosing the health information of individuals who visited their website. An investigation by the Office of the Att… Continue reading Attorney General James Secures $300,000 from NewYork-Presbyterian Hospital for Failing to Protect Patient Data

Recent attacks on Fred Hutch and Integris: Is attempting to extort patients directly becoming the “new normal?”

DataBreaches previously reported a breach involving Integris Health in Oklahoma. The incident did not involve encryption, but the threat actors were reportedly contacting patients directly and offering to remove their protected health information for a… Continue reading Recent attacks on Fred Hutch and Integris: Is attempting to extort patients directly becoming the “new normal?”

Integris Health notifying patients of hack and warning them not to respond to the hackers

On December 24, Integris Health of Oklahoma started contacting patients about a cyberattack on November 28. The unnamed threat actors did not encrypt any of the health system’s files, but Integris learned that patients were being contacted direct… Continue reading Integris Health notifying patients of hack and warning them not to respond to the hackers

ProSmile issues breach disclosure that creates more questions than it answers

On December 22, ProSmile Holdings, LLC in New Jersey issued a press release about a data breach. If ProSmile — a dental service organization — is a business associate or otherwise covered under HIPAA, no report from them has shown up yet on… Continue reading ProSmile issues breach disclosure that creates more questions than it answers

U.S. water utilities were hacked after leaving their default passwords set to ‘1111,’ cybersecurity officials say

Wilfred Chan reports: Providers of critical infrastructure in the United States are doing a sloppy job of defending against cyber intrusions, the National Security Council tells Fast Company, pointing to recent Iran-linked attacks on U.S. water utiliti… Continue reading U.S. water utilities were hacked after leaving their default passwords set to ‘1111,’ cybersecurity officials say

AbbVie files trade secrets suit against Adcentrx and former employee

Nicole DeFeudis reports: AbbVie accused a former employee and a rival oncology developer of stealing trade secrets about its antibody-drug conjugate programs. The pharma giant on Friday filed suit in California federal court against Adcentrx and scient… Continue reading AbbVie files trade secrets suit against Adcentrx and former employee