Email phishing attack impacts over 200,000 ClearBalance patients
ClearBalance is a patient financing company that has recently reported an email data breach which led to over 200,000 patients' sensitive...
3 min read
Dean Levitt
March 27, 2023
According to the New York Attorney General’s office, a law firm was fined $200,000 for data security failures that led to a 2021 data breach.
New York Attorney General Letitia James secured a $200,000 settlement from the law firm HPMB for their failure to protect the personal and healthcare data of over 60,000 New Yorkers. The case emphasizes the responsibility of law firms to maintain adequate data security measures, especially when handling sensitive personal and healthcare information that belongs to their healthcare clients.
In 2021, HPMB experienced a data breach that compromised the private information of around 114,000 patients, including more than 60,000 New Yorkers. The law firm represents New York City area hospitals and maintains sensitive private information from patients. HPMB’s data security failures violated both state law and the Health Insurance Portability and Accountability Act (HIPAA), which required the law firm to adhere to specific data security practices.
HPMB must pay $200,000 in penalties to the state and strengthen its cybersecurity measures to protect consumers’ personal and private health information.
An attacker exploited a vulnerability in HPMB’s Microsoft Exchange email server to access the firm’s systems. Patches for this vulnerability had been released by Microsoft months earlier, but HPMB failed to apply them in a timely manner, leaving the vulnerability exposed for potential exploitation.
In December 2021, an attacker deployed malware on HPMB’s systems, disrupting their email system and potentially exposing the personal and healthcare data of 114,979 individuals, including 61,438 New York residents.
As a result of the agreement, HPMB is required to adopt several measures to better protect the personal and private health information of its clients’ patients, including:
Law firms working with sensitive information must ensure compliance with data protection regulations and implement robust security measures to prevent breaches and protect their clients’ information.
Law firms handling sensitive personal and healthcare information must prioritize data protection to prevent breaches and maintain compliance with regulations. Here are some specific, actionable tips for law firms working with healthcare organizations to protect PHI:
By adopting these measures, law firms can significantly reduce the risk of data breaches and protect the sensitive information entrusted to them by healthcare organizations and other clients.
ClearBalance is a patient financing company that has recently reported an email data breach which led to over 200,000 patients' sensitive...
4 min read
Baton Rouge General Health System (GHS) recently confirmed a data breach in its computer system. They operate 20 clinics and medical facilities in...
Utah has announced an amendment to its data breach laws, which now requires breached organizations to notify individuals involved and the Attorney...
Every Friday we bring you the most important news from Paubox. Our aim is to make you smarter, faster.