By Jessica Davis
May 09, 2019 – Billing vendor OS recently began notifying patients of several healthcare providers that their data was breached after an email hack on an employee email account in late 2018.
OS first discovered the unauthorized email access on December 21. Upon discovery, officials said they quickly changed the employee’s user credentials and launched an investigation with help from an outside forensic team.
The investigation revealed the hacker gained access using credentials they obtained when an employee fell for a phishing email on October 15, 2018 – more than two months before it was discovered.
On February 20, the investigation concluded, and on April 1, they confirmed the patients affected by the hack. The compromised accounts contained a range of patient data, including names, dates of service, hospital encounter numbers, and account balances. A small number of patient Social Security numbers, in the form of insurance numbers, were also breached.
OS began notifying the impacted providers on May 2, which included Sauk Prairie Healthcare, Tahoe Forest Health District, Sparta Community Hospital, and the Idaho Department of Health and Welfare. Spectrum Health Lakeland was also impacted by the OS breach, and recently began notifying about 1,000 patients that their data was potentially compromised.
READ MORE: HIPAA is Clear: Breaches Must be Reported 60 Days After Discovery
Under HIPAA, breaches must be reported within 60 days of discovery, not at the conclusion of the investigation.
OS has since taken steps to bolster its email security and notified law enforcement. Officials said they’ve also review their existing security policies and procedures, implemented additional security measures, and are continuing to improve the information security.
Verity Health’s St. Vincent Medical Center Phishing Attack
California-based St. Vincent Medical Center, part of Verity Health System, recently began notifying patients of a potential breach due to a phishing attack.
This is the fourth phishing attack reported by Verity Health since December. The health system experienced two separate attacks in November and January, and a third attack discovered just weeks later.
For St. Vincent’s, a web email account of a hospital pathologist was compromised on March 15. Officials said they discovered the hack 11 days later on March 26 and secured the attack soon after.
READ MORE: Mailing Error for Inmediata, While Reporting Health Data Breach
The investigation determined the hacker used the account to send phishing emails to both internal and external contacts, which contained malicious hyperlinks and attachments, according to officials. No other employee email accounts were breached in the security incident. Employees who opened the malicious emails had their accounts secured and disabled.
It appears the hacker used the attack to gain login credentials for other email accounts and not the actual information contained in the emails. However, during the unauthorized access, the hacker could have potentially accessed emails, attachments, and folders. Further, officials could not rule out access or whether a hacker copied data.
The compromised emails contained patient data including demographic details, dates of service, medical record numbers, Social Security numbers, diagnoses, treatments, lab data, and health plan names.
In response, Verity has added more email security features to block phishing emails and implemented multi-factor authentication. The impacted employees have received counseling and additional phishing education. Verity also implemented a new security module.
Bloodworks Northwest Loses Document with Patient Information
Washington-based Bloodworks Northwest recently lost a document containing patient information and is notifying patients of a potential risk to their privacy.
READ MORE: Ransomware Attacks on Business Targets Increase by 195% in Q1
On March 31, official said they discovered the document went missing from an employee’s desk. The document contained some personal patient information like names, dates of birth, and medical diagnoses. No financial data or Social Security numbers were contained in the missing record.
Ransomware Attack on American Baptist Homes of the Midwest
American Baptist Homes of the Midwest fell victim to a ransomware attack on March 10 and is notifying patients of a potential breach of their personal health information.
The cyberattack began on or around March 10 and was discovered after the encryption process had started. Officials said they were able to stop some of the attack and secure the accounts, but not before widespread file encryption occurred. With help from its third-party forensics firm, ABHM was able to remove the ransomware from its system and restore data from backups.
The impacted files contained client records that were stored on ABHM’s general file systems and email accounts. Clinical and billing systems were not infected with the ransomware. While officials said they believe the cyberattack was designed just to extort money from ABHM, they could not rule out unauthorized access.
The impacted files contained patient names an addresses, as well as some Social Security numbers, diagnoses, financial data, medications, lab results, and some health information.
The ABHM locations impacted by the attack include: Colorado’s Health Center at Franklin Park and Mountain Vista Senior Living; Minnesota’s Crest Services and Thorne Crest Senior Living; Trail Ridge Senior Living in Sioux Falls, South Dakota; Nebraska’s Maple Crest Health Center; Iowa’s Crest Services and Elm Crest Senior Living; and Wisconsin-based Tudor Oaks Senior Living.
ABHM hired a cybersecurity leader who completed a risk assessment, along with bolstering its security with stronger password requirements, limiting attempted account access, and continuous monitoring.
