Four details:
1. The hacker, Jelle Ursem, released a report with DataBreaches that found data leaks associated with healthcare providers, a health plan and third-party vendors exposed thousands of patients’ records. Just three of the nine entities patched the leaks after being notified about them.
2. The leaks occurred for several reasons, including: embedding hard-coded login credentials instead of making it a configuration option on the server the code runs on; using public repositories; no two-factor authentication; not deploying IP address whitelists.
3. In some cases the organizations didn’t enforce password resets or provide a responsible disclosure mechanism.
4. The report named Glover, Mereacre and GnosticPlayers as threat actors misusing GitHub.
More articles on cybersecurity:
Malware attack exposes info of 129,000+ Behavioral Health Network patients
Blackbaud hack exposes info of 657,392 Maine health system donors
Rite Aid pharmacy thefts expose information of 9,200 patients
At the Becker's 11th Annual IT + Revenue Cycle Conference: The Future of AI & Digital Health, taking place September 14–17 in Chicago, healthcare executives and digital leaders from across the country will come together to explore how AI, interoperability, cybersecurity, and revenue cycle innovation are transforming care delivery, strengthening financial performance, and driving the next era of digital health. Apply for complimentary registration now.