Hello world,
Today’s Paubox Weekly is 770 words - a 3 minute read.
Want to get this type of content delivered to your inbox every Friday? Subscribe to Paubox Weekly.
Roper St. Francis Healthcare, a hospital network with over 117 facilities, faced a massive data breach. The attacker accessed email accounts through phishing and impacted approximately 189,761 patients.
Going deeper: Unfortunately for Roper, this is far from the first data breach the hospital network has faced. The hospital network has faced several other breaches in recent years, and a lawsuit alleges that the trend shows continued carelessness.
Is phishing considered a preventable attack vector?
Paubox CEO Hoala Greevy caught up with Joe Oliveri of Easter Seals Louisiana over coffee in New Orleans.
About Easter Seals: Joe is the COO and CFO of Easter Seals Louisiana. Their mission is to change the way the world defines and views disabilities by making profound, positive differences in people's lives every day.
About the art: Joe gave Hoala an art piece from one of their autistic clients. Mahalo!
What was said: It made Hoala's day when Joe said, "we don't have to turn the encryption on."
Visiting customers is one of the best parts of the job
The recent cyberattack on Change Healthcare has prompted the HHS to seek input from payers on how to effectively respond to such incidents.
What was said: AMA president Dr. Ehrenfeld slammed insurer group AHIP's inaction. “It is dumbfounding that following weeks of silence and a lack of assistance to struggling practices in the wake of the Change Healthcare cyberattack, AHIP's response is a 'business as usual' approach to prior authorization.”
Service outages have worsened administrative burdens
The Paubox Zoom social mixer for March 2024 began with a presentation on texting, HIPAA compliance, and TCPA.
Our takeaways:
98% of patients like text message communication
Cybercriminals are using Tycoon 2FA to bypass 2FA in Microsoft 365 and Gmail software.
What happened: The use of the new phishing-as-a-service platform is gaining popularity among cybercriminals targeting Microsoft 365 and Gmail accounts in an attempt to bypass two-factor authentication (2FA) protection.
The server in the middle captures session cookies
The Office for Civil Rights updated guidance on the use of online tracking technologies by covered entities.
What happened: This update came in response to criticism and legal challenges, including a lawsuit filed by the American Hospital Association (AHA) and other healthcare organizations last November.
The AHA is still dissatisfied with the updates