home.social

#healthsec — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #healthsec, aggregated by home.social.

fetched live
  1. Des failles dans des systèmes de données médicales, ignorées pendant 5 ans. Ce n'est pas une anomalie — c'est un pattern connu : des systèmes critiques, souvent peu mis à jour, avec des cycles de patch qui ne suivent pas le rythme des menaces. La sensibilité des données de santé rend chaque délai particulièrement coûteux. #infosec #healthsec #vulnérabilité
    zdnet.fr/actualites/vos-donnee

  2. The largest regional healthcare administration system in Colombia appears to have been hacked.

    Nueva EPS serves about 11.3 million people, and the hacker claims to have data on all of them. They've already leaked data on 30k people after Nueva EPS issued a public statement that they didn't like.

    Although it's not in their forum posts, the TA told me they're demanding $15M in Bitcoin to delete the data nd not leak it.

    My post is at:
    databreaches.net/2026/10/05/nu

    #databreach #healthsec #hack #extortion #cybersecurity

    @campuscodi

  3. Well, this is a pleasant change. A breach disclosure that says that although they found ransomware on their server:

    "our investigation determined that the threat actor would likely not have been able to view or acquire any of the data, as all data on the server was encrypted.... and there is no indication that the threat actor possessed the encryption keys necessary to view the underlying data."

    It is so rare to read something like that.

    Bravo to Bright Smile Dental Care in Indiana.

    #ransomware #encryption #healthsec #infosec #cybersecurity

  4. So Japan is trying something to help boost cybersecurity for #hospitals. According to The Japan News:

    "Medical institutions have faced challenges when implementing effective cybersecurity measures as there are multiple IT vendors for different medical devices. This means that facilities have to maintain numerous network connections linking their systems to the outside world.

    To address this, the ministry will provide subsidies to hospitals that consolidate their external connection points, simplifying monitoring and allowing for systems to be isolated faster in the event of an attack."

    The govt will also dispatch cybersecurity experts in the event of a cyberattack.

    Source: japannews.yomiuri.co.jp/scienc

    #cybersecurity #Japan #healthsec

  5. SCOOPY: Time’s Up: Ransomware Group Claims 150,000+ Cardiology Patient Records. We’ve Seen the Data.

    Neither Cardiology Associates of Port Huron nor McLaren responded to email inquiries sent to them weeks ago or now, so this breach has not been confirmed even though it looks real.

    #HealthSec #cybersecurity #HIPAA #databreach #ransomware

    @campuscodi

  6. One of the dozens of new #ransomware groups this year is a group calling itself #Orova. Since early May, they appear to have dozens of victims in about half a dozen countries.

    Three of the listings are U.S. medical entities, so, of course, I reached out to them to find out more.

    My new report:

    Cardiology Associates of Port Huron remains silent although they were allegedly hacked and had patient data stolen in June.

    databreaches.net/2026/08/06/ca

    #databreach #healthsec #cybersecurity #extortion #encryption

  7. Developing: AnMed reports phone and internet outage impacting all 4 hospital locations in South Carolina and Georgia. Emergency rooms remain open.

    No group has claimed responsibility as yet.

    #cyberattack #healthsec

  8. Also new by me:

    Cherry Health provides preliminary notice of recent data breach:

    databreaches.net/2026/06/22/ch

    They had an earlier breach in December 2023 that affected pretty much the same types of patient information. How did these attackers gain access compared to the 2023 attackers? None of that has been made public.

    #databreach #healthsec #transparency #infosec #HIPAA #HHS

  9. A bit of data breach history:

    Today, The Gentlemen added Athens Orthopedic Clinic (AOC) to its DLS without any proof of claims.

    I looked at the name and blinked because it is almost a decade to the day that I first notified AOC that they had been hacked by thedarkoverlord (TDO). I did extensive reporting on that incident, including exposing the business associate responsible for the breach, civil litigation by upset patients, and HHS charges against AOC that were settled with a corrective action plan and a $1.5 million monetary penalty. I also reported on the arrest and sentencing of one member of TDO who was involved in that incident.

    At one point I learned that I was doing so much exclusive reporting on TDO that the FBI served Twitter with legal process to get my information because they weren't sure whether I was a co-conspirator or not (they eventually realized I wasn't).

    For my multi-year reporting on that incident and follow-up, search databreaches.net for "Athens Orthopedic."

    For the HHS settlement, see:
    databreaches.net/2020/09/21/at

    As to the civil suit (Collins v. Athens Orthopedic), the case went up to the Georgia Supreme Court, which reversed the lower court's dismissal of the case and ruled that the plaintiffs did have standing to sue for negligence. They remanded, and the Court of Appeals adopted their decision as their own (see caselaw.findlaw.com/court/ga-c)

    Having had their attempt to get the case dismissed, Athens Orthopedic then settled privately with the plaintiffs. I do not know the terms of that settlement.

    I just wonder how AOC will respond to this incident in light of their disastrous experience in 2016. And I wonder what #HHS will find when they investigate.

    #databreach #extortion #HIPAA #healthsec #cybersecurity #infosec
    #TDO #thedarkoverlord #athensorthopedic

  10. UK: More than one year later, HCRG is first notifying patients of a ransomware attack:

    databreaches.net/2026/06/18/uk

    This is the one where they ran to the High Court in the UK to get injunctions that their lawyers sent to @amvinfe and me.

    It seems they are first notifying patients now -- 16 months after the attack.

    #healthsec #cybersecurity #incidentresponse #HCRG #injunction
    #databreach #ransomware

  11. iRhythm confirms data was stolen in a breach — a medical device company, so the data in question isn't just names and emails. When health monitoring hardware meets patient records, the attack surface becomes a clinical concern, not just a compliance checkbox. Details on scope and affected data types are still emerging. #infosec #breach #healthsec
    securityweek.com/irhythm-confi

  12. @chum1ng0 I wonder if #HHSOCR pays attention to any of these leak reports where the entity has not responded to responsible disclosure nor acknowledged any problem.

    The patients are lucky you persisted, Chu.

    #dataleak #HealthSec #infosecurity #HIPAA

  13. NEW:

    Yesterday, the USAO in Maryland issued a press release stating that Matthew Bathula, a clinical pharmacy specialist, had been charged with unauthorized access and ID theft involving patients at "Company A" -- a medical system in Maryland. 195 patients have been notified.

    If you read the DOJ presser, it alleges a lot of activities that go waaaay beyond the usual insider "snooping."

    A little digging revealed that "Company A" is the University of Maryland Medical Center, where Bathula was employed during the years of alleged wrongdoing.

    Read the presser and more at:

    databreaches.net/2026/05/02/ma

    #databreach #IDtheft #HIPAA #infosec #insider #healthsec

  14. Almost one year after discovery, Sandhills Medical Foundation notifies 169,017 people affected by a cyberattack

    This was an attack by INC Ransom, who dumped the data in June 2025. INC didn't tag it as an encryption invcident -- just as hack, exfil, ransom demand. So I'm not sure why it took Sandhills about a year to make notifications

    databreaches.net/2026/04/29/al

    #databreach #HIPAA #incidentresponse #INCransom #healthsec

  15. If you were or are a federal employee or are a family member of one, you might want to read this and share it with others who might be concerned:

    Trump’s Personnel Agency Is Asking for Federal Workers’ Medical Records

    kffhealthnews.org/news/article

    #privacy #healthsec #workplace #infosec

  16. I am a big fan of BakerHostetler's annual data security incident response reports because they are based on actual client experiences and data.

    I just posted about their 2026 report, and commented on their healthcare sector data. As I had mentioned to @siguza, healthcare breaches tend to get higher ransom demands and higher settlements. Take a look at the 2025 data -- the highest initial ransom demand for a health entity client was $98M.

    I'd love to know who the victim was and what TA or group demanded that much.

    That said, the highest ransom actually paid for a healthcare sector breach by one of their clients last year was $5M.

    Big delta.

    My post: databreaches.net/2026/04/03/ba

    #ransomware #healthsec #incidentresponse #statistics #phishing #ransom #malware #databreach #cybersecurity

    @campuscodi @amvinfe

  17. Also NEW by me:

    "If threat actors gave you a chance to redact the patient data they hacked before they leak it, would you take them up on the offer? Read about the Woundtech incident."

    I've never encountered any threat actors spending so much time redacting patient data before they leak it -- and even giving their victim the opportunity to redact the hacked data tranche before the threat actors leak it.

    Read more about this one at:

    databreaches.net/2026/03/23/if

    #databreach #healthsec #woundtech #cybersecurity #redaction #incidentresponse #FulcrumSec

    @zackwhittaker @campuscodi @euroinfosec @DysruptionHub @amvinfe

  18. NEW, by me:

    3.7 Million Telehealth Patients Allegedly Affected By Two Recent Breaches

    An individual calling himself "Stuckin2019" or just "Stuck" claims responsibility for attacks on OpenLoop Health and Zealthy.

    The former has notified the California AG's Office, but the latter has not notified any regulator as far as I can determine, and they haven't responded to inquiries.

    Read more at:
    databreaches.net/2026/03/23/3-

    #databreach #healthsec #cybersecurity #OpenLoop #Zealthy #HIPAA

    @campuscodi @euroinfosec @jgreig

  19. This has always been one of my nightmares, and it came true:

    A New Zealand medication charting platform used by numerous providers was hacked. But not only was it hacked, but the attackers also changed some patients' names to "Charlie Kirk," and changed other patients' records to "deceased."

    There has been no report of any extortion attempt.

    #MediMap started investigating on Sunday afternoon when problems were first reported.

    stuff.co.nz/nz-news/360942689/

    #databreach #healthsec #hack #cybersecurity

    @campuscodi

  20. OK, I feel sorry for this dentist, but I am really happy to see someone quickly informing patients about what happened and what they have done and are doing in response. I think his approach will go a long way to maintaining his patients' trust in him.

    impartialreporter.com/news/258

    #hack #healthsec #databreach #incidentresponse #GDPR #transparency #cybersecurity

  21. When I rule the world, new ransomware/extortion gangs will have to take a number and wait until an existing one retires or gets arrested (preferably the latter).

    Anyone have any info on the group calling itself "Insomnia?"

    #databreach #healthsec #cybersecurity

  22. I recently asked #HHS #OCR how any personnel and regional cuts would affect their investigation of breaches of the #HIPAA #SecurityRule and #Notification Rule.

    They didn't exactly answer my question as to how many investigators have been laid off, but they did outline their priorities for 2026.

    You can read their response to my inquiries in my new post at:

    databreaches.net/2026/01/15/hh

    #databreach #healthsec #cybersecurity #ransomware #hacking #risk

  23. New Zealand's high court seems to be handing out injunctions to victim entities. Have they really considered the impact on press/journalism and whether such injunctions are effective at all?

    In the past month, we have learned that Manage My Health, Canopy Health, and Neighbourly were all granted injunctions to prevent downloading or sharing of data.

    But do these injunctions really protect consumers and patients? Well, no, not really if the criminals leak data anyway.

    Is the court just enabling entities to claim they have done everything they can to protect patients or consumers (well, other than actually preventing the breaches)?

    Maybe entities should only be granted injunctions if they can first demonstrate that they had reasonable security protections in place and MFA, etc.?

    #healthsec #cybersecurity #injunctions #incidentresponse #databreach

  24. Updated my post on the Anubis attack on Mid South Pulmonary Specialists after getting additional info from Anubis.

    It seems they used their wiper to delete all of MSPS's backups, and then encrypted all of their systems.

    That sounds pretty grim. MSPS has not posted anything (perhaps they can't) or issued any notice anywhere about whether patient care has been affected at all by any breach.

    databreaches.net/2025/12/07/th

    #HIPAA #healthsec #cybersecurity #databreach #ransomware #Anubis #wiper #backups #incidentresponse

    @campuscodi @amvinfe

Share on Mastodon

Enter the server where you have an account.