Why health care has become a top target for cybercriminals

posted in: Politics | 0

Elise Takahama | (TNS) The Seattle Times

When a cyberattack hit Seattle’s Fred Hutchinson Cancer Center late last year and exposed the personal data of nearly a million patients, many were caught off guard, stunned a breach could infiltrate such a large and highly resourced health care organization.

But those working in computer security weren’t surprised. In recent years, they’ve watched other hospitals and health care facilities across the country get hit by similar attacks, some that have crashed systemwide operations and caused delays in patient procedures or tests, or rerouted ambulances to other emergency rooms.

Cyberattacks of all sorts have plagued large corporations, small businesses and individuals for decades now, but in the past several years, health care has become a top target, according to federal and local cybersecurity experts. These organizations hold a massive amount of patient data — including medical records, financial information, Social Security numbers, names and addresses. They’re also among the few businesses that stay open 24/7, meaning they might be more likely to prioritize avoiding disruptions and, therefore, more likely to pay a hacker’s ransom.

“They’re basically a one-stop shop for an adversary,” said Chris Callahan, chief of cybersecurity for the Northwest region of the federal Cybersecurity and Infrastructure Security Agency, or CISA. The agency, housed in the U.S. Department of Homeland Security, also works to defend against government and election hacking, but recently health care — along with K-12 education and the water supply — has emerged as one of its most urgent priorities, Callahan said.

In December, the U.S. Department of Health and Human Services reported that the medical data of more than 88 million people was exposed in the first 10 months of 2023. The department also saw a 93% increase in large, health care-related breaches reported to the agency between 2018 and 2022.

The Cybersecurity and Infrastructure Security Agency has a regional office based in the Henry M. Jackson Federal Building in Seattle. (Ken Lambert/The Seattle Times/TNS)

While fewer data breaches in Washington state were reported to the state Attorney General’s Office last year compared with 2021 and 2022, which both saw a record number of cases, experts say cyberattack numbers are still much higher than they were before the pandemic.

In the past three months, 13 health care-related businesses have detailed large breaches to state Attorney General Bob Ferguson, as is required by Washington law when more than 500 residents have been impacted by a cyberattack.

Attacks against computer systems at Proliance Surgeons and Western Washington Medical Group last February and July, respectively, allowed unauthorized access to the data of hundreds of thousands of patients, the medical groups wrote to Ferguson’s office. Dental insurer Delta Dental, Vancouver-based Hi-School Pharmacy, and California-based vision care provider Medical Eye Services (known as MESVision) were also hit last year, impacting thousands more.

Patients’ health information is worth a lot of money to hackers, said Geetha Thamilarasu, an associate professor of computing and software systems at the University of Washington, Bothell. Once someone gets hold of a stolen medical record, they can buy fake prescriptions, file bogus insurance claims, participate in identity theft and sell it online, among other things, she said.

“There is a huge underground market on the dark web,” said Thamilarasu, who specializes in health care security. “Research shows that if a compromised credit card sells for about $1 to $5 each, a compromised medical record can sell anywhere from $400 to $500 — sometimes even $1,000.”

Once a hacker obtains someone’s personal information, they’ll often try to use it as leverage to extort an organization or victim for money, Callahan said. If that fails, they’ll try to sell it to other organized crime groups that generally have “one objective — to make as much money on your information as fast as possible,” he said.

Risk of being doxxed — when someone, usually with ill intent, posts a victim’s personal information online — has become more common, too, he added. After the Fred Hutch breach, many patients whose data was leaked also received a barrage of email threats and spam messages.

Health care organizations, like many others, have spent the last decade moving toward total digitization, creating some new risks.

“Health records are no longer paper,” Thamilarasu said. “While having digital technologies is often great and provides more convenience, it also opens them up to these security vulnerabilities.”

This not only includes patient records, but also medical devices like X-ray and CT scanning machines, which are now often connected to a network or the internet, Thamilarasu said.

“And if you are connected to the internet, you can be hacked,” she said.

While an X-ray machine itself might not carry any patient data, it can act as an entry point for attackers trying to break into an organization’s broader network. In a health care facility, there could be hundreds of Internet-connected devices, which require different types of security measures not always prioritized, she said.

One cyberattack on health care giant Ardent Health Services last year forced hospitals in New Jersey, Oklahoma, Texas, New Mexico and other states to divert ambulances to other emergency rooms and reschedule some nonemergency procedures while systems were offline.

“I think this is becoming more of a problem in health care than any other institution,” Thamilarasu said. “And with health care, you’re no longer just talking about money and loss of data. … This could potentially endanger human lives.”

Anatomy of a cyberattack

It often starts with a simple email.

Maybe an employee gets a message from a familiar name. They don’t notice the name is slightly misspelled, or recognize it could be a phishing attempt. They open it and click the link.

And just like that, a hacker can gain access to the employee’s credentials and the organization’s entire network system.

“The biggest risk sector is employees,” said Callahan of CISA. “If you don’t have the defenses or the user education and awareness, then it’s a super easy way to get into a system.”

Ransomware threats — when a specific malicious software blocks a victim’s personal data until a ransom is paid — are also on the rise, Callahan said.

In 2022, the Federal Bureau of Investigation recorded about 870 ransomware incidents that hit “critical infrastructure” businesses, like transportation, health care, energy, government and food and agriculture. Of those, almost 25% were attacks against health care and public health organizations, compared with about 22% in 2021.

AI technology has played a “huge role” in more sophisticated hacking attempts, Thamilarasu said.

“Attackers are able to generate all these emails, which no longer appear as (obvious) phishing emails,” she said. “Nowadays, they look so genuine and authentic.”

Cybersecurity can be an afterthought for many health care systems because they’re primarily focused on patient care, Callahan said.

Those who manufacture medical devices should also make sure their products are secure, Thamilarasu added.

“We all get that health care systems are one of the most overworked organizations,” she said. “And security is not the priority. Patients are the priority. So I think a lot of these staff and health care providers do not understand the level of damage somebody can cause.”

Push toward cyber safety

Recent cyberattacks have sparked a renewed push among many health care organizations to bolster protections.

Washington state’s Moses Lake Community Health Center, which was targeted last year, is in the middle of several cybersecurity improvements.

“We believe (cybersecurity) is not a destination, but a continuous improvement process,” said Mark Lauteren, the health center’s chief information officer, who joined after the breach. “The bad actors are always changing their environment and their attack methods, so if we put something up and say ‘Done,’ guaranteed, they’ll find a way around it within a few weeks.”

Lauteren declined to discuss the breach, which leaked data of about 1,200 people, but noted that cybersecurity is “not a new priority.” The Moses Lake center has since teamed up with CISA, which offers free, weekly cybersecurity scans to organizations that look for potential vulnerabilities in their system and offer recommendations. CISA officers also run through “tabletop” exercises that mimic real cyberattacks, hoping to prepare organizations in case one occurs.

During these exercises, experts walk organization leadership and IT teams through a dry run of a breach, prompting them with questions. How might they respond? Are they going to pay the ransom? How are they going to start rebuilding their systems afterward?

“We (all) need to be better at protecting ourselves,” Lauteren said.

Since the Fred Hutch breach last fall, an organization spokesperson said it has implemented “additional defensive tools and increased monitoring,” but declined to elaborate on what those entail.

At UW Medicine, whose data was also impacted during the Fred Hutch cyberattack, “we continuously strengthen our cybersecurity measures and actively adapt our strategies to address evolving cyber threats,” hospital spokesperson Susan Gregg said in a statement.

The Washington State Hospital Association has started to hold regular cybersafety sessions for its members, though organization spokesperson Beth Zborowski said she was hesitant to describe specifics to avoid sharing strategies with hackers and prevent any individual hospitals from becoming a target.

“We are paying attention to this. We take people’s health information seriously,” Zborowski said. “If you ask hospital CEOs what keeps them up at night, this would be one of the things.”

Catching a cybercriminal

Falling for a cyber scam can happen in seconds. But it sometimes takes years for an investigation to unfold.

Fred Hutch, for example, is still working on confirming details around its recent breach, though the organization believes hackers overseas “exploited a vulnerability” in a workspace software called Citrix that allowed them to gain access to its clinical network.

The weakness, known as the “Citrix Bleed,” has gained attention from federal cybersecurity teams, who say it allows attackers to bypass password requirements and multifactor authentication measures.

In several other cyberattacks in Washington and throughout the country, investigators found hackers targeted a file-transfer tool called MOVEit, a software application used to exchange data. According to TechCrunch, a group of hackers found a weakness in the software that allowed them to install a backdoor and steal data.

Cybercrime investigations can be complicated, especially if hackers are working from a different country that may not want to work with the U.S., said Kevin Brennan, a supervisory special agent with FBI Seattle’s cyber task force.

“Some of it is going to be through more traditional investigative techniques,” Brennan said. “You know, follow the money — or in this case, cryptocurrency.”

The FBI encourages against paying ransoms because it doesn’t guarantee hackers will delete or stop sharing people’s data, but if companies choose to, the agency also tracks online communications between victims and hackers, searching for small details that might illuminate where a suspect is. It’s becoming much less common for victims to pay ransoms, Brennan said, but the practice still happens; the FBI doesn’t collect data on how frequently ransoms are paid.

Once officers identify a suspect overseas, they have a couple of options, Brennan said. If the FBI is working with a country whose laws don’t require them to arrest someone based on an alleged crime they committed in the U.S., agents might look for potential crimes the suspect committed in that country, he said.

In other cases, agents might have to wait for the suspect to travel somewhere that will extradite them to the U.S.

FBI Seattle doesn’t generally track “success” rates for closing cybercrime cases, but Brennan noted various challenges involved when working with international law enforcement. It can also be hard to report an accurate number of closed cases because sometimes cybercriminals are only charged with one breach when law enforcement officials might know or suspect they’re involved with many more, he added.

“It can be a waiting game at times,” Brennan said. “It can be frustrating, both for us and the victims. But it’s not something we’re going to give up on just because they’re hiding in a country that might not cooperate with the U.S.”

Staying safer online

As our collective reliance on technology grows, it can be easy to panic about further opening ourselves up to hacking and data leaks, experts said. But they noted there’s also a lot we can do to limit risk.

Health care organizations are “basically a one-stop shop for an adversary,” said Chris Callahan, chief of cybersecurity for the Northwest region of the federal Cybersecurity and Infrastructure Security Agency. (Ken Lambert/The Seattle Times/TNS)

Cybersecurity experts have a list of tips about how to stay safe online, which can be found at CISA website StopRansomware.gov. HHS has also created a health care-specific tool kit, which includes information about how health care systems can mitigate known vulnerabilities, bolster email security, enable multifactor authentication, deploy strong encryption and roll out basic cybersecurity training.

“You don’t want to call us in your darkest hour,” Callahan said. Institutions “want to make sure you know who your local FBI or CISA contact is. There’s all kinds of things we can do to help protect yourselves before an attack.”

According to CISA, some of the most simple changes to boost individual cybersecurity include:

—Recognizing and reporting phishing

—Using strong passwords

—Turning on multifactor authentication

—Updating software

If you think you’ve been targeted by a hacker, you can also report the incident to the FBI website ic3.gov, which is open to the public.

“I take some comfort in knowing that, as sad as it sounds, so much personally identifiable information has been stolen, the odds of any individual person being a victim is not very high,” said Brennan of FBI Seattle. “We all drive down the highway at 70 miles an hour and think, ‘I’m not going to be the one that gets into an accident.’ And odds are we’re not.”

___

(c)2024 The Seattle Times. Visit The Seattle Times at www.seattletimes.com. Distributed by Tribune Content Agency, LLC.

Forest Lake officials opt for expedited search for city administrator

posted in: News | 0

Forest Lake City Council members are moving forward with an expedited search for the next city administrator — and interim city administrator Kristina Handt is at the top of their list of candidates.

Handt, in fact, is the only candidate currently under consideration.

Kristina Handt (Courtesy photo)

Handt, the former Lake Elmo city administrator, was hired in mid-January after the Forest Lake City Council voted unanimously to terminate former city administrator Patrick Casey’s employment contract and hire her as interim administrator and interim clerk. The vote came after a closed session to discuss Casey’s annual performance evaluation.

Handt is currently searching for a permanent city administrator position and has been presented with “a few opportunities … that have timelines … that would be in conflict with running through the standard executive search,” City Attorney Amanda Johnson told the council on Monday night.

Council members decided Monday to pause the general search process and proceed with an expedited review of Handt, Johnson said.

“The components of the process are the same as the general process would be,” she said. “This includes a background check, reference review, personality assessment and interviews.”

Handt’s interview with the council and a community stakeholder panel will be on March 14 and will be open to the public.

The council is expected to hold a special meeting on March 18 to vote on Handt’s possible hiring for the permanent position.

If the council does not vote to move forward with Handt, officials with DDA Human Resources will proceed “with the full-scope executive search as originally planned,” Mayor Mara Bain said.

“Our goal for Forest Lake is to consider as many candidates as possible,” Bain said. “Because of the timing of other municipalities’ searches for city administrator, this expedited timing is the only possible way to consider Kristina for the Forest Lake position.”

Related Articles

Local News |


Lake Elmo attorney suspended for misleading statement in custody case

Local News |


Lake Elmo Airport working on decreasing noise complaints with preventative measures

Local News |


Woodbury grad party shooting: Gunman who fired shot that killed boy, 14, pleads guilty to unintentional murder

Local News |


Now open in Stillwater: Mike and Kat’s Other Place, a cozy espresso bar

Local News |


There’s only one place to score ‘Fargo’-themed Bisquick boxes. In Scandia, of course.

After ‘real’ interest from UCLA, Gophers give P.J. Fleck significant retention bonuses

posted in: News | 0

Three weeks after being linked to UCLA, the Gophers have awarded head football coach P.J. Fleck with a contact amendment that includes annual retention bonuses worth $5.7 million over the six years remaining in Fleck’s term.

The Bruins reached out to Fleck in early February for their vacant head coach position, but the following day, Fleck publicly reaffirmed his commitment to the Gophers.

The U said Friday, pending Board of Regent approval, Fleck will now receive bonuses on top of his total salary, which remains at $6 million per year. Last year, he received a seven-year contract extension, and that length remains: through the 2029 season.

Fleck, who posted a 6-7 record in 2023, will now receive substantial retention bonus for each year of the contract. (Year 1 starts the day the deal is approved by regents and ends Dec. 31, 2024.)

Year 1 (2024): $700,000

Year 2 (2025): $800,000

Year 3 (2026): $900,000

Year 4 (2027): $1 million

Year 5 (2028): $1.1 million

Year 6 (2029): $1.2 million

Fleck’s salary, including retention bonuses, currently ranks ninth in the 18-team Big Ten Conference, according to U documents.

The contract also calls for a $500,000 increase in a salary pool for assistant coaches/staff. Recent Gophers coordinators Joe Rossi and Kirk Ciarrocca left Minnesota in the last two years and received significant salary raises at their next schools — Michigan State and Rutgers, respectively.

The contract amendment also changes the buyout, if Fleck were to leave for another coaching position at any level, or for a job in broadcasting.

Year 1 (2024): $7 million

Year 2 (2025): $5 million

Year 3 (2026): $4 million

Year 4 (2027): $3 million

Year 5 (2028): $2 million

During Year 6 (2029): $0

Fleck’s buyout for 2024 was $5 million.

The contact also includes bowl bonuses: $500,000 for College Football Playoff national championship game; $350,000 for CFP semifinal; $300,000 for CFP quarterfinal; $250,000 for CFP first-round; $150,000 for Citrus or Tampa Bay Bowl; $100,000 other bowls not mentioned above. The amounts shall not be cumulative.

If the U terminates Fleck’s contract without cause, the U would owe him 65% of base salary, supplemental compensation and retention bonuses that would have been paid over the remainder of the contract’s term.

Gophers Athletics Director Mark Coyle said the UCLA interest was “real” during his appearance on the Golden Gophers Podcast this week.

“When that started to percolate and gain momentum … he and I talked on Friday night,” Coyle shared on the podcast. “We had a long conversations on Friday night. He and I had long conversations on Saturday morning.”

On that Saturday, Feb. 10, Coyle said he also talked with interim U president Jeff Ettinger and the Board of Regents about what Fleck has done at the U.

Fleck is 50-34 overall, including 29-32 in the Big Ten, across seven seasons. He has reached nine or more wins in three seasons, including 11-2 in 2019. Gopher players have been setting record grade-point averages and have built a high standing in the community.

“His name is going to come up every year because what he does is unique.” Coyle told host Justin Gaard. “I can tell you in the athletic director circle, people talk about him. … People get confused about Row the Boat. They get confused about him jumping up and down on the sideline. They get confused of him running around, all that type of stuff. At the end of the day he is old-fashioned values packaged hi-def.”

Related Articles

College Sports |


Brevyn Spann-Ford was a blocking tight end for the Gophers. He could shine as a pass catcher in the NFL.

College Sports |


Safety Tyler Nubin found inspiration in former Gophers teammate Antoine Winfield Jr.

College Sports |


Gophers football nets big and menacing offensive lineman Andrew Trout for 2026 class

College Sports |


Amid UCLA speculation, P.J. Fleck says he’s ‘honored’ to coach Gophers

College Sports |


Charley Walters: Totino Grace’s Joe Alt following father’s NFL footsteps

Business owners face unique challenges when going through a divorce. Here’s what you should know

posted in: Society | 0

Gene Marks | (TNS) The Philadelphia Inquirer

Although research varies, it is estimated that anywhere between 40% and 50% of marriages end in divorce. A divorce can be emotional, painful — and expensive. And if you’re running a small business, it could have a significant impact on your cash flow.

If you own a small business, here are few things to consider:

Get your books in order

It’s important to make sure your books are as clean as possible. Many business owners I know mix too many of their personal and business expenses, usually due to sloppy bookkeeping. During discovery, an opposing attorney can request just about anything related to your business, and this could put you at a disadvantage during negotiation. Pennsylvania laws, in particular, can “tend to be on the liberal side” regarding what documents can be requested, according to Linda Kerns, a family law attorney based in Philadelphia.

“A spouse can request all the details of your business even if they don’t own the assets,” Kerns said. “When you go through a divorce, you’re putting a microscope on your business and on your accounting habits and if small discrepancies are found, they can blow up into bigger headaches.”

Consider an arbitrator

Both Kerns and John Zurzola, a divorce specialist and partner at Weber Gallagher in Philadelphia, say that arbitration — where you hire an independent attorney or judge — may be the best and most cost effective route for a divorce negotiation. Kerns says that in arbitration, all matters are private and not subject to reporting. Zurzola agrees that arbitration tends to be a smoother process and “hopefully” results in a more fair settlement.

“It would be beneficial to the business owner if a neutral arbitrator has knowledge in an industry, particularly if the business is technical,” Zurzola said. “Otherwise you’ll need to educate the court on how the business works, and this could lead to asset valuation problems.”

Your cash flow will be affected

Consider the impact that your divorce will have on your future cash flow. Whereas your business might fluctuate depending on the season or your projects and customers, a divorce settlement — particularly when there’s alimony or child support — requires a consistent payment being made.

“I often have clients that have challenges when it comes time to pay a monthly amount when their cash flow doesn’t always support that,” Kerns said. “It can also put a ton of pressure on a small-business owner, particularly when their business is subject to ebbs and flows.”

According to Kerns, one of the reasons cash flow becomes a challenge is that a business often gets valued during divorce proceedings, and the value of the business may contain noncash assets such as customer lists or a company’s reputation.

“If, for example, your business is valued at $1 million, it’s not all cash, and you have half of that to pay your spouse,” Kerns said. “So you may have to finance that amount … then you’re paying a loan back in addition to trying to run your business after a divorce. It can be very, very difficult strain.”

Think ahead when you can

No one goes into a marriage with the expectation that it will end in divorce. But regardless of the state of your marriage, it’s important to take steps in advance to protect your company’s assets — and even your business partners’ interests.

One of these steps is to have a buy-sell agreement with your partners. This is a legally binding document that stipulates in writing what happens when one partner dies, wants to be bought out, or experiences other significant events that may impact a business.

Doing this in advance creates a defined road map and significantly reduces any confusion when a situation — like divorce — arises. Most buy-sell agreements require that a business has insurance to cover the costs of these types of events.

“I find that divorces when there are [business] partners can be even worse because the partners are trying to go into the office every day and earn money, and they’re not too thrilled about dealing with lawyers and having the staff gathering information to turn over to attorneys,” Kerns said. “It’s a huge, huge distraction and could even personally impact their cash flow.”

Find the right attorney

The right attorney can ease what is for most people a very difficult — and emotional — experience.

Zurzola advises finding an attorney that has had a history dealing with divorcing couples when either both or one has a stake in a small business. He also recommends attorneys that have good networks of advisers, such as forensic accountants, tax specialists, valuation firms, and insurance professionals. Kerns agrees.

“The choice of a divorce attorney can be a very personal one because you’re putting a lot of trust in that person,” she said. “And remember that the more you hide or act like something’s not important, the harder you’re going to make their job.”

_____

©2024 The Philadelphia Inquirer. Visit inquirer.com. Distributed by Tribune Content Agency, LLC.