Events Calendar

Mon
Tue
Wed
Thu
Fri
Sat
Sun
M
T
W
T
F
S
S
31
12:00 AM - EXPO.health
5
6
8
9
10
11
13
15
16
18
19
20
21
22
23
24
26
27
28
30
1
32nd Annual Summer Seminar in Health Care Ethics & Surgical Ethics
2019-07-29 - 2019-08-02    
All Day
32nd Annual Summer Seminar in Health Care Ethics & Surgical Ethics is organized by University of Washington School of Medicine (UWSOM) Continuing Medical Education (CME) [...]
3-Day Physician Assistant PANCE / PANRE Board Review Course by Certified Medical Educators (CME) - Salt Lake City
2019-07-29 - 2019-07-31    
All Day
3-Day Physician Assistant PANCE / PANRE Board Review Course is organized by Certified Medical Educators (CME) and will be held from Jul 29 - 31, [...]
Four Week Radiologic Pathology Correlation Course (Jul 29 - Aug 23, 2019)
2019-07-29 - 2019-08-23    
All Day
Four Week Radiologic Pathology Correlation Course is organized by American Institute for Radiologic Pathology (AIRP) and will be held from Jul 29 - Aug 23, [...]
Third Annual Philadelphia Trauma Training Conference
2019-07-30 - 2019-08-01    
All Day
Third Annual Philadelphia Trauma Training Conference is organized by Thomas Jefferson University (TJU) and will be held from Jul 30 - Aug 01, 2019 at [...]
IDAA Annual Meeting 2019
2019-07-31 - 2019-08-04    
All Day
International Doctors in Alcoholics Anonymous (IDAA) 70th Annual Meeting 2019 is organized by International Doctors in Alcoholics Anonymous (IDAA) and will be held from Jul [...]
EXPO.health
2019-07-31 - 2019-08-02    
All Day
EXPO.health Schedule July 31 - August 2, 2019 - Location: Boston, MA Join us at EXPO.health (Formerly Healthcare IT Expo – HITExpo) 2019 happening July [...]
01 Aug
2019-08-01 - 2019-08-03    
All Day
UCSF CME: Neurosurgery Update 2019 is organized by The University of California, San Francisco (UCSF) Office of Continuing Medical Education and will be held from [...]
PBI Medical Ethics & Professionalism (ME-22) - Irvine
2019-08-02 - 2019-08-03    
All Day
PBI Medical Ethics & Professionalism (ME-22) is organized by Professional Boundaries, Inc. (PBI) and will be held from Aug 02 - 03, 2019 at Wyndham [...]
The 8th Beijing International Top Health & Medical Exhibition (BIHM)
2019-08-02 - 2019-08-04    
All Day
The 8th Beijing International Private Health and Medical Exhibition will be held at the China International Exhibition Center from August 2nd to August 4th, 2019. [...]
Angiogenesis Gordon Research Seminar (GRS) 2019
2019-08-03 - 2019-08-04    
12:00 am
Angiogenesis Gordon Research Seminar (GRS) is organized by Gordon Research Conferences (GRC) and will be held from Aug 03 - 04, 2019 at Salve Regina [...]
Lung Development, Injury and Repair Gordon Research Seminar (GRS) 2019
2019-08-03 - 2019-08-04    
All Day
Lung Development, Injury and Repair Gordon Research Seminar (GRS) is organized by Gordon Research Conferences (GRC) and will be held from Aug 03 - 04, [...]
Platelet Rich Plasma for Aesthetics Course - Miami (Aug 2019)
Platelet Rich Plasma for Aesthetics Course is organized by Empire Medical Training (EMT), Inc and will be held on Aug 04, 2019 at GALLERYone - [...]
Physician Medical Weight Loss Training (Aug 04, 2019)
2019-08-04    
All Day
Physician Medical Weight Loss Training is organized by Empire Medical Training (EMT), Inc and will be held on Aug 04, 2019 at The Platinum Hotel [...]
Grand opening for Saint Alphonsus Regional Rehabilitation Hospital
2019-08-07    
4:00 pm - 6:00 pm
Grand opening for Saint Alphonsus Regional Rehabilitation Hospital 711 North Curtis Road | Boise, Idaho Aug 7, 2019 4:00 p.m. MDT A new home for Saint Alphonsus [...]
7th International Conference on  Medical Informatics & Telemedicine
2019-08-12 - 2019-08-13    
All Day
Conference Date : August 12-13, 2019 Rome, Italy Theme: Innovative information technologies for the improvement of patient care “7th International Conference on Medical Informatics and Telemedicine” will take [...]
CMBBE 2019 - 16th International Symposium on Computer Methods in Biomechanics and Biomedical Engineering and the 4th Conference on Imaging and Visualization
2019-08-14 - 2019-08-16    
8:00 am - 6:00 pm
CMBBE 2019 - 16th International Symposium on Computer Methods in Biomechanics and Biomedical Engineering and the 4th Conference on Imaging and Visualization is organized by [...]
Joint / Extremity / Non Spinal Injection Course (Aug 17, 2019)
2019-08-17    
All Day
Joint / Extremity / Non Spinal Injection Course is organized by Empire Medical Training (EMT), Inc and will be held on Aug 17, 2019 at [...]
Wilderness Medicine Expedition Course 2019
2019-08-25 - 2019-09-02    
All Day
Wilderness Medicine Expedition Course is organized by National Outdoor Leadership School (NOLS) and will be held from Aug 25 - Sep 02, 2019 at Wyss [...]
Diabetes, Lipidology, Pulmonary Medicine, and Critical Care Conference
2019-08-25 - 2019-09-01    
All Day
Diabetes, Lipidology, Pulmonary Medicine, and Critical Care Conference is organized by Continuing Education, Inc and will be held from Aug 25 - Sep 01, 2019 [...]
Neurology Certification Review 2019
2019-08-29 - 2019-09-03    
All Day
Neurology Certification Review is organized by The Osler Institute and will be held from Aug 29 - Sep 03, 2019 at Holiday Inn Chicago Oakbrook, [...]
Ophthalmology Lecture Review Course 2019
2019-08-31 - 2019-09-05    
All Day
Ophthalmology Lecture Review Course is organized by The Osler Institute and will be held from Aug 31 - Sep 05, 2019 at Holiday Inn Chicago [...]
Emergency Medicine, Sex and Gender Based Medicine, Risk Management/Legal Medicine, and Physician Wellness
2019-09-01 - 2019-09-08    
All Day
Emergency Medicine, Sex and Gender Based Medicine, Risk Management/Legal Medicine, and Physician Wellness is organized by Continuing Education, Inc and will be held from Sep [...]
Events on 2019-07-30
Events on 2019-07-31
IDAA Annual Meeting 2019
31 Jul 19
Knoxville
EXPO.health
31 Jul 19
Boston
Events on 2019-08-01
01 Aug
Events on 2019-08-29
Events on 2019-08-31
Articles News

A Ransomware Attack Affects American Associated Pharmacies

EMR Industry

These hacks on significant healthcare organizations should serve as a reminder to clinical labs and anatomic pathology groups to strengthen their cybersecurity defenses.

Public health records, including data from clinical laboratory tests, are still being accessed by hackers, endangering the protected health information (PHI) of thousands of individuals. American Associated Pharmacies (AAP) is the most recent significant healthcare organization to fall prey to a ransomware attack. The Register reports that the AAP declared that more than 1.4 terabytes (TB) of data had been taken by a ransomware operation known as Embargo, which then encrypted the files and demanded $1.3 million to restore them.

According to Embargo, AAP, located in Scottsboro, Alabama, spent $1.3 million to have its systems fixed. According to the HIPAA Journal, “The attack follows ransomware attacks on Memorial Hospital and Manor, an 80-bed community hospital and 107 long-term care facility in Georgia, and Weiser Memorial Hospital, a critical access hospital in Idaho.” They are now requesting an extra $1.3 million to protect the stolen data.

AAP has not released an official statement on the hack or officially acknowledged the ransomware attack. However, it did publish a “Important Notice” on its website stating that ” APIRx.com now has limited ordering capabilities for API Warehouse again.”

Through wholesale purchasing programs, API Warehouse, a division of AAP, assists members in saving money on both brand-name and generic prescription drugs. It has more than 2,500 stock keeping units (SKUs) in its inventory and manages more than 2,000 independent pharmacies around the United States.

“All user passwords associated with both APIRx.com and RxAAP.com have been reset, so existing credentials will no longer be valid to access the sites,” the notice adds. To reset your password, please select “forgot password” from the log-in screen and adhere to the instructions.

“Embargo does not appear to be concentrating on a particular victim profile and appears to have victims from a variety of countries and industries. Mike Hamilton (above), the founder and chief information security officer (CISO) of the cybersecurity company Critical Insight, told HealthcareInfoSecurity, “They seem opportunistic.” They should not be disregarded, nevertheless, because they do have a number of victims in the medical field and have highly advanced tools to thwart detection. We may anticipate that others will utilize their resources and infrastructure if they do, in fact, operate through affiliates, and Embargo might become a major danger to the healthcare industry. Laboratory patients are especially at risk because clinical laboratory tests data comprise 80% of all medical records. (Image courtesy of Critical Insight.)

Embargo on the PHI Hunt

It’s probable that the hackers were able to obtain account information and medical records from every client of the pharmacies that were part in the attack because of the volume of data that Embargo took from the AAP servers.

In June of this year, researchers at the internet security firm ESET discovered the Embargo ransomware group. ESET claimed in a press release that Embargo stole AAP’s data using an endpoint detection and response (EDR) killing toolset.

Embargo appears to be a well-resourced organization based on its methods of operation. In order to communicate with victims, it establishes its own infrastructure. Additionally, the gang uses double extortion to coerce victims into paying: the operators not only encrypt victims’ personal data but also exfiltrate it and threaten to post it on a leak website, according to a news release from ESET.

Recently, Embargo also targeted other healthcare-related businesses. It took credit for breaking into Memorial Hospital and Manor in Bainbridge, Georgia, in November. According to The Cyber Express, Memorial had to switch to a paper-based system as a result of the intrusion that compromised its email and electronic medical record (EHR) systems.

About 200 terabytes (GB) of private information were stolen during Embargo’s attack on Weiser Memorial Hospital in Weiser, Idaho, which also resulted in a four-week computer system outage.

Additional Cyberattacks Targeting Healthcare Institutions

Over the previous few years, Dark Daily has published numerous ebriefs covering numerous cyberattacks against hospital health systems.

We outlined how Ascension’s inability to access medical information during the attack resulted in significant interruptions to patient care in “Cyberattack Renders Healthcare Providers across Ascension’s Hospital Network Unable to Access Medical Records Endangering Patients.” The complete restoration of Ascension’s electronic health record system took almost a month.

The February cyberattack on Change Healthcare prompted its parent company, UnitedHealth Group, to submit a Material Cybersecurity Incidents Report (form 8-K) to the US Securities and Exchange Commission (SEC), stating that it had “identified a suspected nation-state associated cybersecurity threat actor [that] had gained access to some of the Change Healthcare information technology systems,” according to Dark Daily’s article, “Change Healthcare Cyberattack Disrupts Pharmacy Order Processing for Healthcare Providers Nationwide.”

According to Reuters, the threat actor’s true identity was discovered a few days later to be a ransomware organization called BlackCat (also known as ALPHV).

Additionally, in “Continued Cyberattacks on Hospitals, Clinical Laboratories, and Other Providers Cause Closures as Hackers Grow in Sophistication,” we detailed how hospitals of all sizes are still frequently the target of sophisticated cyberattacks in which hackers remotely take down computer systems within a healthcare network, including the clinical laboratory information system (LIS), and demand ransomware payments.

Protecting patient information is essential, and more healthcare institutions are learning the hard way that they are susceptible to cyberattacks. Managers of clinical laboratories and pathology groups are once again reminded by this circumstance to take aggressive measures to safeguard their information systems and to regularly upgrade their digital security.

Patients are constantly at risk of having their confidential records stolen since hackers are working hard to gain access to protected health information.