The U.S. Department of Justice (DOJ) announced its “months-long disruption campaign against the Hive ransomware group that has targeted more than 1,500 victims in over 80 countries around the world, including hospitals, school districts, financial firms, and critical infrastructure.” Part of the disruption included the FBI’s penetration of Hive’s computer networks, capturing its decryption keys and providing them to victims to unlock affected systems and avoid payment of $130 million in demanded ransom. The DOJ stated that the group received over $100 million through its “double-extortion model of attack” of exfiltrating or stealing sensitive data before encrypting the victim’s systems, through the use of a ransomware-as-a-service (RaaS) model. Among the methods used by the attackers to gain access to the victim’s systems were phishing schemes and emails with malicious attachments.
One takeaway from this announcement is the importance of implementing recognized security practices that are intended to address and prevent the top cyber threats against the healthcare system. This includes having in place a robust security program, including HIPAA Security Rule policies and procedures, implemented practices, ongoing monitoring, and effective training initiatives that address security best practices and avoidance of ransomware attacks and phishing and email schemes.
If you need assistance with your HIPAA compliance program, an OCR investigation, or a data breach incident, please contact: Lani M. Dornfeld, CHPC | 973.403.3136 | ldornfeld@bracheichler.com
This site uses cookies to store information on your computer. Some of these cookies are essential, while others help us to improve your experience by providing insights into how the site is being used. Click Accept to continue using the site with recommended settings, or choose Cookie Settings make changes.Privacy Policy
Strictly Necessary Cookies
Strictly Necessary Cookie should be enabled at all times so that we can save your preferences for cookie settings.
If you disable this cookie, we will not be able to save your preferences. This means that every time you visit this website you will need to enable or disable cookies again.
3rd Party Cookies
This website uses Google Analytics to collect anonymous information such as the number of visitors to the site, and the most popular pages.
Keeping this cookie enabled helps us to improve our website.
Please enable Strictly Necessary Cookies first so that we can save your preferences!