A health data breach appears to have exposed the sensitive personal information of members of Congress and their employees. DC Health Link is used by many (but not all) members and their assorted staff.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
A major data breach at health insurance giant Blue Shield of California appears to be a case of misconfiguring advertising analytics tools. Between April 2021 and January 2024, Google Analytics was misconfigured causing some personal information and potentially sensitive health data related to claims and searches to be available to Google’s ad network.
Brazil's Health Ministry is looking at extended downtime for the system that processes Covid-19 vaccination data as it attempts to recover from two ransomware attacks that came just four days apart.
It's not a surprise that there has been a significant increase in healthcare cyber attacks, but the numbers revealed by a new Bitglass study are nevertheless eye-popping: an increase of over 55% in 2020.
Healthcare giant CVS exposed over a billion health records through a misconfigured cloud database leak, including visitor and session IDs, device information and multiple records for medications.
Johnson & Johnson’s IT service provider IBM has notified over 1 million Janssen CarePath customers of a data breach that leaked personal and medical information.
Healthcare provider Kaiser Permanente has disclosed a data breach stemming from online tracking that inadvertently shared with third-party advertisers how users interacted with and navigated through the website and mobile applications, and search terms used in the health encyclopedia patient information.
Healthcare tech solutions provider HealthEC LLC has experienced a data breach impacting nearly 4.5 million individuals across various states.
Healthcare web application attacks increased by 51% since the introduction of COVID-19 vaccines. Cross-site scripting (XSS) and SQL injections were the most detected by volume.
HealthEquity is notifying 4.3 million individuals of a third-party breach that leaked their personal (PII) and protected health information (PHI) after an unauthorized actor accessed a vendor’s data repository.









