Cyberattack on Native American Health Center in California

by | Jun 16, 2024

Native American Health Center (NAHC) is a nonprofit government-qualified health center that provides services to the local community (American Indians and Alaska Natives) in the California Bay Area. The health center encountered a cybersecurity attack on November 19, 2023. and took immediate action to protect its system disconnecting it from the online world. Third-party cybersecurity specialists helped investigate the attack and confirmed in January that an unauthorized actor accessed patient records. An analysis of the files was done to find out which data was affected.

After the completion of the analysis on May 28, 2024, the Native American Health Center got a listing of the impacted persons and the types of information affected. The exposed patient data included names, birth dates, and health data. The attack did not affect Social Security numbers, but as a safety measure, the impacted persons were provided free Single Bureau Credit Monitoring, report, and score services.

Native American Health Center stated that all logins are already using multifactor authentication. It is currently working on using a system that uses fingerprint scans/badge taps instead of passwords to mitigate the risk of harm. Selected departments are using this system on a trial basis. All hard drives were updated and HIPAA privacy and security checks will be done every year, including the review of policies, procedures, and employee training awareness on cybersecurity, HIPAA certification, and privacy. Access to IT department offices & server rooms will be restricted to physical activity. Buildings and sites equipped with key card access will have restricted access and monitored entry.

The breach report was submitted to OCR but the incident is not yet posted on the HHS’ Office for Civil Rights breach website, thus the number of impacted persons is still uncertain.

Raise the level of HIPAA Awareness in your organization with Learner-Friendly, Comprehensive and Affordable HIPAA Training.

COMPREHENSIVE HIPAA TRAINING

Please enable JavaScript in your browser to complete this form.

Ryan Coyne

Ryan Coyne is a results-driven leader in the healthcare compliance industry, specializing in regulatory compliance, compliance training, and assisting healthcare organizations and business associates in achieving and maintaining compliance. With a deep knowledge of healthcare regulations and a keen understanding of the challenges faced by the industry, Ryan has developed a reputation as a trusted advisor and advocate for ethical and compliant practices in healthcare. Ryan has successfully advised and guided numerous healthcare organizations, business associates, and healthcare professionals on achieving and maintaining compliance with regulatory training requirements. Ryan's professional focus is using his in-depth expertise and leading a world class team of subject matter experts at ComplianceJunction in regulatory compliance to help organisations navigate the complex landscape of ensuring staff adhere to healthcare regulations. You can connect with Ryan via LinkedIn and follow on Twitter

Raise the level of HIPAA Awareness in your organization with Learner-Friendly, Comprehensive and Affordable HIPAA Training.

Comprehensive HIPAA Training

Used in 1000+ Healthcare Organizations and 100+ Universities

    Full Course - Immediate Access

    Privacy Policy