A bit of data breach history:
Today, The Gentlemen added Athens Orthopedic Clinic (AOC) to its DLS without any proof of claims.
I looked at the name and blinked because it is almost a decade to the day that I first notified AOC that they had been hacked by thedarkoverlord (TDO). I did extensive reporting on that incident, including exposing the business associate responsible for the breach, civil litigation by upset patients, and HHS charges against AOC that were settled with a corrective action plan and a $1.5 million monetary penalty. I also reported on the arrest and sentencing of one member of TDO who was involved in that incident.
At one point I learned that I was doing so much exclusive reporting on TDO that the FBI served Twitter with legal process to get my information because they weren't sure whether I was a co-conspirator or not (they eventually realized I wasn't).
For my multi-year reporting on that incident and follow-up, search databreaches.net for "Athens Orthopedic."
For the HHS settlement, see:
https://databreaches.net/2020/09/21/athens-orthopedic-clinic-pays-1-5-million-to-settle-hhs-charges-of-systemic-noncompliance-with-hipaa-rules/
As to the civil suit (Collins v. Athens Orthopedic), the case went up to the Georgia Supreme Court, which reversed the lower court's dismissal of the case and ruled that the plaintiffs did have standing to sue for negligence. They remanded, and the Court of Appeals adopted their decision as their own (see https://caselaw.findlaw.com/court/ga-court-of-appeals/2087515.html)
Having had their attempt to get the case dismissed, Athens Orthopedic then settled privately with the plaintiffs. I do not know the terms of that settlement.
I just wonder how AOC will respond to this incident in light of their disastrous experience in 2016. And I wonder what #HHS will find when they investigate.
#databreach #extortion #HIPAA #healthsec #cybersecurity #infosec
#TDO #thedarkoverlord #athensorthopedic

