Brazil's Health Ministry is looking at extended downtime for the system that processes Covid-19 vaccination data as it attempts to recover from two ransomware attacks that came just four days apart.
By and large, the companies that Epic is suing seemed to be seeking medical data to sell to attorneys looking to establish mass tort cases involving many patients suffering similar injuries or conditions. In total the companies accessed 300,000 medical records under these alleged false pretenses.
It's not a surprise that there has been a significant increase in healthcare cyber attacks, but the numbers revealed by a new Bitglass study are nevertheless eye-popping: an increase of over 55% in 2020.
Healthcare giant CVS exposed over a billion health records through a misconfigured cloud database leak, including visitor and session IDs, device information and multiple records for medications.
Johnson & Johnson’s IT service provider IBM has notified over 1 million Janssen CarePath customers of a data breach that leaked personal and medical information.
Healthcare provider Kaiser Permanente has disclosed a data breach stemming from online tracking that inadvertently shared with third-party advertisers how users interacted with and navigated through the website and mobile applications, and search terms used in the health encyclopedia patient information.
Healthcare tech solutions provider HealthEC LLC has experienced a data breach impacting nearly 4.5 million individuals across various states.
Healthcare web application attacks increased by 51% since the introduction of COVID-19 vaccines. Cross-site scripting (XSS) and SQL injections were the most detected by volume.
HealthEquity is notifying 4.3 million individuals of a third-party breach that leaked their personal (PII) and protected health information (PHI) after an unauthorized actor accessed a vendor’s data repository.
The large amount of the Booking.com fine is a point of contention as it stretches to the limit of what the GDPR allows for a data breach notification incident that involved relatively little sensitive personal information.









