Community Health Systems reports GoAnywhere hacked

Community Health Systems reports GoAnywhere hacked

Community Health Systems filed with the Securities and Exchange Commission that it was notified by a third-party vendor for secure file transfer of an incident that resulted in unauthorized disclosure of its patient data.WHY IT MATTERS
The GoAnywhere managed file transfer platform first warned about a zero-day remote code injection exploit on February 1, according to the technical bulletin posted by noted security researcher Brian Krebs on Infosec.exchange. 
“The attack vector of this exploit requires access to the administrative console of the application, which in most cases is accessible only from within a private company network, through [virtual private network] or by allow-listed IP…

Continue Reading
Several Louisiana hospitals face online tracking lawsuits

Several Louisiana hospitals face online tracking lawsuits

The class action lawsuits filed by Herman Herman & Katz allege Meta Pixel code potentially analyzed, gathered and shared the sensitive medical data of hundreds of thousands of patients across the LCMC Health Systems and Willis-Knighton Health System networks.WHY IT MATTERS
Pixel technology uses a Java tracking script to send an organization’s data to the technology owner, which in this case, is Meta, owner of Facebook, Instagram and WhatsApp. Tracked data could be shared with network marketing partners who target individuals with offers and advertisements.
The new class action lawsuit alleges that visitors to the health system websites may have had their protected…

Continue Reading
Third-party data breach round-up: mscripts, Diligent, Mailchimp

Third-party data breach round-up: mscripts, Diligent, Mailchimp

This month, more than 114,000 individuals may have experienced personally identifiable information and protected health information exposures from these incidents, while an email marketing hack is a new source for phishing attacks.Medication adherence platform mscripts breached
On January 17, mscripts, a cloud-based mobile pharmacy platform that focuses on patient engagement and medication adherence solutions, reported to the U.S. Department of Health and Human Services unauthorized access/disclosure that involved protected health information of 66,372 individuals, according to the Office for Civil Rights cases under investigation list.
The San Francisco-based platform, owned by Dublin, Ohio-based Cardinal Health, uses interactive SMS messaging and branded mobile apps to…

Continue Reading