The healthcare and public health sector (HPH) issued an alert about a continuing phishing campaign that uses the DocuSign e-signature software to impersonate popular companies. The target of the phishing campaign is to mislead company staff into allowing their billing...
CISA Gives Recommendations for the Security and Stability of Critical Infrastructure
The Critical Infrastructure Security and Resilience Month is celebrated this November. One month is devoted to increasing knowledge of why fortifying critical infrastructure security and resilience is important. The U.S. Cybersecurity and Infrastructure Security...
Warning Issued For Midnight Blizzard’s Spear Phishing Campaign
Microsoft tracked a foreign threat actor called Midnight Blizzard (also known as APT29, Cozy Bear). It is performing a spear phishing campaign attacking companies in several sectors, such as academia, government, defense, information technology, non-governmental...
Alert Issued About the Miracle Exploit Vulnerabilities Identified in Oracle Systems
Several Oracle products are affected by critical vulnerabilities that threat actors are exploiting. The security researchers who discovered the vulnerability named it The Miracle Exploit. This vulnerability affected all Oracle online systems and Oracle Fusion...
Two Anonymous Sudan Members Facing Charges Over February 2024 Cyberattack on Cedars-Sinai
Two men from Sudan were accused of their involvement in several cyberattacks on company networks, government organizations, and critical infrastructure organizations in the U.S. They were also connected to the attack on Cedars-Sinai Medical Center located in Los...
Great Expressions Dental Centers Pays $2.7 Million to Resolve Data Breach Lawsuit
Great Expressions Dental Centers decided to resolve a class action lawsuit arising from a 2023 data breach that affected the personal data and protected health information (PHI) of 1,925,397 people. Great Expressions Dental Centers based in Bloomfield Hills, MI, which...
Alert Issued on Iranian Threat Actors Attacking Critical Infrastructure Entities
The U.S. Cybersecurity and Infrastructure Security Agency (CISA), the Communications Security Establishment Canada (CSE), the National Security Agency (NSA), the Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC), and the Australian Federal...
Gryphon Healthcare Sends Breach Notification to 400,000 Patients
Gryphon Healthcare has reported a security incident wherein the files of approximately 400,000 people with protected health information (PHI) had been accessed by unauthorized individuals. Gryphon Healthcare based in Houston, TX is a revenue cycle, coding, HIPAA...
Omni Family Health Confirmed Data Breach Due to Cyberattack
Omni Family Health, a healthcare provider with centers across Kings, Kern, Fresno, and Tulare counties in California, has informed patients and staff about the potential theft of their protected health information (PHI) in a recent cyberattack. The organization...
Law Enforcement Arrests Individuals Connected to LockBit Ransomware Attacks and Evil Corp Members
A global law enforcement campaign called Operation Cronos has led to the arrest of four people who are allegedly involved in LockBit ransomware attacks and the shutdown of nine servers tied to the LockBit ransomware network. These actions are included in the third...
Status Report Concerning Ransomware Attacks on Healthcare Organizations
The State of Ransomware in Healthcare 2024 report by Sophos revealed that ransomware attacks on healthcare organizations continue to rise, even as incidents in other industries have declined. Across all sectors, the percentage of organizations reporting a ransomware...
MOVEit Hack on Wisconsin Physicians Service Impacted 3.1 Million Individuals
The Centers for Medicare and Medicaid Services (CMS) reported a data breach to the Department of Health and Human Services (HHS) that affected 3,112,815 people. This breach, initially announced by CMS and Wisconsin Physicians Service Insurance Corporation (WPS)...
CorrectCare Integrated Health Pays $6.49 Million to Settle Data Breach Lawsuit
CorrectCare Integrated Health LLC (CorrectCare) settled a class action lawsuit associated with a 2022 data breach impacting approximately 600,000 individuals. The court gave the final approval for the settlement that cost CorrectCare $6.49 million. Third-party...
Privacy Lawsuit Against IU Health Voluntarily Dismissed
The lawsuit against IU Health and IU Health Associates filed by Attorney General Todd Rokita of Indiana related to violations of the Indiana Deceptive Consumer Sales Act and the Health Insurance Portability and Accountability Act (HIPAA) has been dismissed. The case...
Cyberattacks on Critical Infrastructure Use Valid Credentials as Initial Access Vector
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has released a report detailing the findings from risk and vulnerability assessments (RVAs) conducted across various organizations, including state, local, tribal, and territorial (SLTT) entities,...
947K Individuals Notified by WPS and CMS About the MOVEit Hack in May 2023
The Wisconsin Physicians Service Insurance Corporation (WPS) and Centers for Medicare & Medicaid Services (CMS) are notifying approximately 947,000 people about the compromise of some of their protected health information (PHI) and personally identifiable...
HHS Sued to Overturn the Final Rule of Reproductive Healthcare Privacy
Texas Attorney General Ken Paxton took legal action against the Department of Health and Human Services (HHS) and its Secretary Xavier Becerra, for the alleged legitimacy of a new HHS final rule about reproductive healthcare privacy. The rule, HIPAA Privacy Rule to...
Ransomware Attack on Young Consulting Impacts 954K Individuals
Software solutions provider Young Consulting (also known as Connexure) based in Atlanta services the employer stop-loss insurance industry. It recently encountered a BlackSuit ransomware attack that compromised the medical insurance data of 954,177 persons. The...
The State of Ransomware Groups in 2024
Ransomware continues to be a threat in 2024, with recent reports about its persistence, profitability, and evolving tactics. Despite efforts by law enforcement to combat these cyberattacks, ransomware groups show no signs of retreating. A report by blockchain analysis...
Humana Resolves Whistleblower Lawsuit for $90 Million
Humana has consented to resolve a lawsuit filed by a whistleblower concerning the submission of fraudulent bids by the health insurer to the Centers for Medicare and Medicaid Services (CMS) for Medicare Part D contracts between 2011 and 2017. The Medicare Part D...
Guidance & Recommendations for Event Logging and Threat Identification
The Federal Bureau of Investigation (FBI), the Australian Signals Directorate’s Australian Cyber Security Centre (ACSC), the U.S. Cybersecurity and Infrastructure Security Agency (CISA), and the National Security Agency (NSA), together with their global partners, have...
Potential Cyberattack on McLaren Health Care
Health system McLaren Health Care based in Grand Blanc, MI manages 13 hospitals in Michigan and several doctor offices, ambulatory surgery centers, and other patient care facilities in the state. It reported an investigation of an outage impacting its telephone and...
PII of 4.2 Million Individuals Affected by HealthEquity Breach
In early July, a data breach report was submitted by HealthEquity, a financial technology and business services company based in Draper, UT. HealthEquity mentioned in its 8-K filing with the Securities and Exchange Commission (SEC) that suspicious activity was...
Phishing Attack on Nebraska Life Insurance Company
United of Omaha Life Insurance Company based in Nebraska has reported a phishing email that led to a protected health information (PHI) breach involving 107,894 individuals. The insurer discovered the breach on April 23, 2024 upon identification of anomalous activity...
12.9 Million Australians Affected by Ransomware Attack on Australian eScripts Provider
MediSecure, an Australian company providing electronic prescription services, encountered a ransomware attack that enabled the theft of 6.5TB of data, which included the sensitive information of approximately 12.9 million Australians - about 50% of the population of...
23andMe to Settle Class Action Data Breach Lawsuit
23andMe based in San Francisco has proposed an agreement to resolve a class action lawsuit that was submitted because of a breach of consumer information in 2023. The breach happened in October 2023 and the attacker stole the data of around 6.9 million people, about...
Pruitt Health Faces Class Action Lawsuit Over 2023 Ransomware Attack
A class action lawsuit was filed against Pruitt Health over a ransomware attack in 2023 that resulted in the compromise of the protected health information (PHI) of 56,405 individuals. Pruitt Health manages 180 care centers in Georgia, Florida, North and South...
Substitute Data Breach Notice Published by Change Healthcare
A substitute breach notice has been published on the Change Healthcare website regarding its February 2024 cyberattack and mentioned the start of sending notification letters to the impacted persons on July 20, 2024. Change Healthcare stated that the data analysis is...
PHI of Palomar Health Medical Group Patients Exposed Due to Cyberattack
Palomar Health Medical Group has informed its patients that an April 2024 cyberattack may have affected their data. The company is a primary and specialty care provider to North San Diego County locals. Patients' protected health information (PHI) may have been...
Two Mass General Brigham Employees Terminated for Privacy Violations
Mass General Brigham based in Boston, MA, reported the termination of two employees because of a privacy breach discovered on April 4, 2024. According to the investigation of the health system, the two employees permitted a third person, who wasn't working at Mass...
Raise the level of HIPAA Awareness in your organization with Learner-Friendly, Comprehensive and Affordable HIPAA Training.
COMPREHENSIVE HIPAA TRAINING
Used in 1000+ Healthcare Organizations and 100+ Universities
Privacy is key to everything that we do at J Flowers Health Institute. We require the highest data privacy standards in our daily operations between our team members and patients. The HIPAA compliance and cyber security training we provide to our teams with ComplianceJunction creates enormous value for our organization.
Kevin DeLoach
Chief Operating Officer
J. Flowers Health Institute








