Events Calendar

Mon
Tue
Wed
Thu
Fri
Sat
Sun
M
T
W
T
F
S
S
30
31
2
4
5
10
11
12
13
14
15
20
21
22
23
24
25
26
27
12:00 AM - Arab Health 2020
29
1
2
5th International Conference On Recent Advances In Medical Science ICRAMS
2020-01-01 - 2020-01-02    
All Day
2020 IIER 775th International Conference on Recent Advances in Medical Science ICRAMS will be held in Dublin, Ireland during 1st - 2nd January, 2020 as [...]
01 Jan
2020-01-01 - 2020-01-02    
All Day
The Academics World 744th International Conference on Recent Advances in Medical and Health Sciences ICRAMHS aims to bring together leading academic scientists, researchers and research [...]
03 Jan
2020-01-03 - 2020-01-04    
All Day
Academicsera – 599th International Conference On Pharma and FoodICPAF will be held on 3rd-4th January, 2020 at Malacca , Malaysia. ICPAF is to bring together [...]
The IRES - 642nd International Conference On Food Microbiology And Food SafetyICFMFS
2020-01-03 - 2020-01-04    
All Day
The IRES - 642nd International Conference on Food Microbiology and Food SafetyICFMFS aimed at presenting current research being carried out in that area and scheduled [...]
World Congress On Medical Imaging And Clinical Research WCMICR-2020
2020-01-03 - 2020-01-04    
All Day
The WCMICR conference is an international forum for the presentation of technological advances and research results in the fields of Medical Imaging and Clinical Research. [...]
International Conference On Agro-Ecology And Food Science ICAEFS
2020-01-06    
All Day
The key intention of ICAEFS is to provide opportunity for the global participants to share their ideas and experience in person with their peers expected [...]
RW- 743rd International Conference On Medical And Biosciences ICMBS
2020-01-07 - 2020-01-08    
All Day
RW- 743rd International Conference on Medical and Biosciences ICMBS is a prestigious event organized with a motivation to provide an excellent international platform for the [...]
International Conference On Nursing Ethics And Medical Ethics ICNEME
2020-01-08 - 2020-01-09    
All Day
An elegant and rich premier global platform for the International Conference on Nursing Ethics and Medical Ethics ICNEME that uniquely describes the Academic research and [...]
International Conference On Medical And Health SciencesICMHS-2020
2020-01-09 - 2020-01-10    
All Day
The ICMHS conference is an international forum for the presentation of technological advances and research results in the fields of Medical and Health Sciences. The [...]
12th Annual ICJR Winter Hip And Knee Course
2020-01-16 - 2020-01-19    
All Day
Make plans to join us in Vail, Colorado, for the 12th Annual Winter Hip And Knee Course, the premier winter meeting focused on primary and [...]
3rd Big Sky Cardiology Update 2020
2020-01-17 - 2020-01-18    
All Day
ABOUT 3RD BIG SKY CARDIOLOGY UPDATE 2020 Following the success of the 2nd edition, I am pleased to invite you to the “3rd Big Sky [...]
A4M India Conference
2020-01-18 - 2020-01-20    
All Day
ABOUT A4M INDIA CONFERENCE Taking place for the first time in New Delhi, India, this two-day event will serve as a foundational course in the [...]
International Conference On Oncology & Cancer Research ICOCR-2020
2020-01-19 - 2020-01-20    
All Day
The ICOCR conference is an international forum for the presentation of technological advances and research results in the fields of Oncology & Cancer Research. The [...]
Arab Health 2020
2020-01-27 - 2020-01-30    
All Day
ABOUT ARAB HEALTH 2020 Arab Health is an industry-defining platform where the healthcare industry meets to do business with new customers and develop relationships with [...]
12th International Conference on Acute Cardiac Care
2020-01-28 - 2020-01-29    
All Day
ABOUT 12TH INTERNATIONAL CONFERENCE ON ACUTE CARDIAC CARE Acute Cardiac Care has been undergoing a substantial transformation in recent years as the population ages and [...]
30 Jan
2020-01-30 - 2020-01-31    
All Day
The ICMHS conference is an international forum for the presentation of technological advances and research results in the fields of Medical and Health Sciences. The [...]
Annual Lower and Upper Canada Anesthesia Symposium 2020 (LUCAS)
2020-01-31 - 2020-02-02    
All Day
ABOUT ANNUAL LOWER & UPPER CANADA ANESTHESIA SYMPOSIUM 2020 (LUCAS) On behalf of the Departments of Anesthesia of McGill University, Queen’s University, and the University [...]
RF - 577th International Conference On Medical & Health Science - ICMHS 2020
2020-02-02 - 2020-02-03    
All Day
577th International Conference on Medical & Health Science - ICMHS 2020. It will be held during 2nd-3rd February, 2020 at Berlin , Germany. ICMHS 2020 [...]
ISER- 747th International Conference On Science, Health And Medicine ICSHM
2020-02-02 - 2020-02-03    
All Day
ISER- 747th International Conference on Science, Health and Medicine ICSHM is a prestigious event organized with a motivation to provide an excellent international platform for [...]
Events on 2020-01-08
Events on 2020-01-09
Events on 2020-01-16
Events on 2020-01-17
Events on 2020-01-18
A4M India Conference
18 Jan 20
Haridwar
Events on 2020-01-27
Arab Health 2020
27 Jan 20
Dubai
Events on 2020-01-28
Events on 2020-01-30
Events on 2020-01-31
Articles News

A Ransomware Attack Affects American Associated Pharmacies

EMR Industry

These hacks on significant healthcare organizations should serve as a reminder to clinical labs and anatomic pathology groups to strengthen their cybersecurity defenses.

Public health records, including data from clinical laboratory tests, are still being accessed by hackers, endangering the protected health information (PHI) of thousands of individuals. American Associated Pharmacies (AAP) is the most recent significant healthcare organization to fall prey to a ransomware attack. The Register reports that the AAP declared that more than 1.4 terabytes (TB) of data had been taken by a ransomware operation known as Embargo, which then encrypted the files and demanded $1.3 million to restore them.

According to Embargo, AAP, located in Scottsboro, Alabama, spent $1.3 million to have its systems fixed. According to the HIPAA Journal, “The attack follows ransomware attacks on Memorial Hospital and Manor, an 80-bed community hospital and 107 long-term care facility in Georgia, and Weiser Memorial Hospital, a critical access hospital in Idaho.” They are now requesting an extra $1.3 million to protect the stolen data.

AAP has not released an official statement on the hack or officially acknowledged the ransomware attack. However, it did publish a “Important Notice” on its website stating that ” APIRx.com now has limited ordering capabilities for API Warehouse again.”

Through wholesale purchasing programs, API Warehouse, a division of AAP, assists members in saving money on both brand-name and generic prescription drugs. It has more than 2,500 stock keeping units (SKUs) in its inventory and manages more than 2,000 independent pharmacies around the United States.

“All user passwords associated with both APIRx.com and RxAAP.com have been reset, so existing credentials will no longer be valid to access the sites,” the notice adds. To reset your password, please select “forgot password” from the log-in screen and adhere to the instructions.

“Embargo does not appear to be concentrating on a particular victim profile and appears to have victims from a variety of countries and industries. Mike Hamilton (above), the founder and chief information security officer (CISO) of the cybersecurity company Critical Insight, told HealthcareInfoSecurity, “They seem opportunistic.” They should not be disregarded, nevertheless, because they do have a number of victims in the medical field and have highly advanced tools to thwart detection. We may anticipate that others will utilize their resources and infrastructure if they do, in fact, operate through affiliates, and Embargo might become a major danger to the healthcare industry. Laboratory patients are especially at risk because clinical laboratory tests data comprise 80% of all medical records. (Image courtesy of Critical Insight.)

Embargo on the PHI Hunt

It’s probable that the hackers were able to obtain account information and medical records from every client of the pharmacies that were part in the attack because of the volume of data that Embargo took from the AAP servers.

In June of this year, researchers at the internet security firm ESET discovered the Embargo ransomware group. ESET claimed in a press release that Embargo stole AAP’s data using an endpoint detection and response (EDR) killing toolset.

Embargo appears to be a well-resourced organization based on its methods of operation. In order to communicate with victims, it establishes its own infrastructure. Additionally, the gang uses double extortion to coerce victims into paying: the operators not only encrypt victims’ personal data but also exfiltrate it and threaten to post it on a leak website, according to a news release from ESET.

Recently, Embargo also targeted other healthcare-related businesses. It took credit for breaking into Memorial Hospital and Manor in Bainbridge, Georgia, in November. According to The Cyber Express, Memorial had to switch to a paper-based system as a result of the intrusion that compromised its email and electronic medical record (EHR) systems.

About 200 terabytes (GB) of private information were stolen during Embargo’s attack on Weiser Memorial Hospital in Weiser, Idaho, which also resulted in a four-week computer system outage.

Additional Cyberattacks Targeting Healthcare Institutions

Over the previous few years, Dark Daily has published numerous ebriefs covering numerous cyberattacks against hospital health systems.

We outlined how Ascension’s inability to access medical information during the attack resulted in significant interruptions to patient care in “Cyberattack Renders Healthcare Providers across Ascension’s Hospital Network Unable to Access Medical Records Endangering Patients.” The complete restoration of Ascension’s electronic health record system took almost a month.

The February cyberattack on Change Healthcare prompted its parent company, UnitedHealth Group, to submit a Material Cybersecurity Incidents Report (form 8-K) to the US Securities and Exchange Commission (SEC), stating that it had “identified a suspected nation-state associated cybersecurity threat actor [that] had gained access to some of the Change Healthcare information technology systems,” according to Dark Daily’s article, “Change Healthcare Cyberattack Disrupts Pharmacy Order Processing for Healthcare Providers Nationwide.”

According to Reuters, the threat actor’s true identity was discovered a few days later to be a ransomware organization called BlackCat (also known as ALPHV).

Additionally, in “Continued Cyberattacks on Hospitals, Clinical Laboratories, and Other Providers Cause Closures as Hackers Grow in Sophistication,” we detailed how hospitals of all sizes are still frequently the target of sophisticated cyberattacks in which hackers remotely take down computer systems within a healthcare network, including the clinical laboratory information system (LIS), and demand ransomware payments.

Protecting patient information is essential, and more healthcare institutions are learning the hard way that they are susceptible to cyberattacks. Managers of clinical laboratories and pathology groups are once again reminded by this circumstance to take aggressive measures to safeguard their information systems and to regularly upgrade their digital security.

Patients are constantly at risk of having their confidential records stolen since hackers are working hard to gain access to protected health information.