https://www.channelfutures.com/wp-content/themes/channelfutures_child/assets/images/logo/footer-new-logo.png
  • Home
  • Technologies
    • Back
    • Analytics
    • Artificial Intelligence
    • Cloud
    • Data Centers
    • Desktop
    • IoT
    • Mobility
    • Networking
    • Open Source
    • RMM/PSA
    • Security
    • Virtualization
    • Voice/Connectivity
  • Strategy
    • Back
    • Best Practices
    • Business Models
    • Channel 101
    • Channel Programs
    • Channel Research
    • Digital Transformation
    • Diversity & Inclusion
    • Leadership
    • Mergers and Acquisitions
    • Sales & Marketing
    • Specialty Practices
  • MSSP Insider
    • Back
    • Business of Security
    • Cloud and Edge
    • Endpoint
    • Network
    • People and Careers
    • Training and Policies
  • MSP 501
    • Back
    • 2020 MSP 501 Rankings
    • 2020 Hot 101 Rankings
    • 2020 MSP 501 Report
  • Intelligence
    • Back
    • Our Sponsors
    • From the Industry
    • Content Resources
    • COVID-19 Partner Help
    • Galleries
    • Podcasts
    • Reports
    • Videos
    • Webinars
    • White Papers
  • EMEA
  • Awards
    • Back
    • Excellence in Digital Services
    • 2020 MSP 501
    • Top Gun 51
  • Events
    • Back
    • CP Conference & Expo
    • Channel Partners Evolution
    • Channel Evolution Europe
    • Channel Partners Event Coverage
    • Webinars
  • Channel Mentor
    • Back
    • Channel Market Intelligence
    • Channel Educational Series
Channel Futures
  • NEWSLETTER
  • Home
  • Technologies
    • Back
    • Analytics
    • Artificial Intelligence
    • Cloud
    • Data Centers
    • Desktop
    • IoT
    • Mobility
    • Networking
    • Open Source
    • RMM/PSA
    • Security
    • Virtualization
    • Voice/Connectivity
  • Strategy
    • Back
    • Best Practices
    • Business Models
    • Channel 101
    • Channel Programs
    • Channel Research
    • Digital Transformation
    • Diversity & Inclusion
    • Leadership
    • Mergers and Acquisitions
    • Sales & Marketing
    • Specialty Practices
  • MSSP Insider
    • Back
    • Business of Security
    • Cloud and Edge
    • Endpoint
    • Network
    • People and Careers
    • Training and Policies
  • MSP 501
    • Back
    • 2020 MSP 501 Rankings
    • 2020 Hot 101 Rankings
    • 2020 MSP 501 Report
  • Intelligence
    • Back
    • Our Sponsors
    • From the Industry
    • Content Resources
    • COVID-19 Partner Help
    • Galleries
    • Podcasts
    • Reports
    • Videos
    • Webinars
    • White Papers
  • EMEA
  • Awards
    • Back
    • Excellence in Digital Services
    • 2020 MSP 501
    • Top Gun 51
  • Events
    • Back
    • CP Conference & Expo
    • Channel Partners Evolution
    • Channel Evolution Europe
    • Channel Partners Event Coverage
    • Webinars
  • Channel Mentor
    • Back
    • Channel Market Intelligence
    • Channel Educational Series
    • Newsletter
  • REGISTER
  • MSPs
  • VARs / SIs
  • Digital Service Providers
  • Cloud Service Providers
  • CHANNEL PARTNERS ONLINE
 Channel Futures

MSSP Insider


Shutterstock

Cybersecurity Roundup

Law Firm Cyberattack Exposes Tens of Thousands of Patient Records

  • Written by Edward Gately
  • February 17, 2021
Cybercriminals prefer to target entities like law firms because of the enterprise data they possess.

A law firm cyberattack potentially exposed the personal health information of more than 36,000 University of Pittsburgh Medical Center (UPMC) patients.

That’s according to a Text IQ analysis of the attack on Charles J. Hilton & Associates.

The law firm provides legal services to UPMC. According to Infosecurity, the firm discovered suspicious activity in its employee email system last June. An investigation determined hackers gained access to several employee email accounts between April 1 and June 25.

Cybercriminals prefer to target entities like law firms since they have enterprise data. In addition, law firms, unlike enterprises, may not spend tens of millions of dollars each year on cybersecurity.

We spoke with Apoorv Agarwal, Text IQ‘s co-founder and CEO, to find out more about the law firm cyberattack.

Channel Futures: How did cybercriminals carry out the law firm cyberattack? Why was this cyberattack successful?

Text IQ's Apporv Agarwal

Text IQ’s Apporv Agarwal

Apoorv Agarwal: Generally, digital forensics handles the cyber investigation of a data breach, and should identify the cause and scope of the attack. In this case, the specific details have not yet been released. But during the COVID-19 pandemic, we have seen a staggering 109% year-over-year increase in U.S. ransomware attacks in the first half of 2020. With employees working from home, away from the safety of office firewalls and strict protocols, companies have scrambled to bolster their cyber defenses and perpetrators have run rampant.

CF: What will be the likely impact of this law firm cyberattack?

AA: The sensitive information that was compromised included several employees and possibly patients who likely reside in different states and possibly countries. The current regulatory landscape includes a patchwork of data privacy and data breach laws. That means the notification obligations and corresponding penalties vary widely. For example, much of the exposed health care data is regulated by HIPAA, while the personal information that was exposed is covered by state-level data breach laws. Without understanding whose data has been breached, impacted entities are compelled to issue blanket notifications for all the people potentially impacted. This means the law firm will have to provide notifications to all the states in which the patients reside, as well as the U.S Department of Health and Human Services, even if the amount of data and information types do not meet the reporting threshold for some states.

CF: Are we seeing an increase in law firms targeted by cybercriminals? If so, why?

AA: According to the American Bar Association and the U.S. Department of Justice, 25% of all law firms have been subjected to or experienced some form of a data breach involving hackers. Law firms are a vulnerable target for cybercriminals for three reasons. First, they tend to have access to highly sensitive data. Generally, the kind of information you exchange with a law firm has a higher degree of sensitivity than that exchanged with other partners. Second, a law firm has access to data from several enterprise clients, which for a cybercriminal can mean more reward for a similar level of effort. Third, they invest much less in cybersecurity compared to enterprises. 

Deloitte estimates large enterprises such as major financial institutions spend on average about $2,300 per employee on cybersecurity. Microsoft alone will spend $1 billion annually for cybersecurity.

CF: What aren’t law firms doing that they should be doing to fend off these attacks?

AA: There are three things law firms should be doing to fend off these attacks. First, investing in their own cybersecurity capabilities, including processes, technologies and training for lawyers within the firm to boost awareness of the risks to sensitive information. Second, investing in technologies, including [machine learning], which operate in highly secure remote cloud environments and reduce the number of humans that are needed to review sensitive data. Each body that has access to sensitive information adds a degree of risk. An additional security precaution to limit access to sensitive data is to redact personal or health information in reports or other documents.

Finally, there are a number of vendors with highly secure data centers or cloud deployments which law firms can work with to …

  • Page 1
  • Page 2
  • Page 3
Tags: MSPs Endpoint MSSP Insider Network Specialty Practices Training and Policies

Related


  • Mergers and acquisitions_M&A
    Calligo Acquires Decisive Data, Beefs Up Data Insights Services
    This is Calligo's 10th acquisition since it launched in 2012, and the fifth during the pandemic.
  • Cloud security
    IT Facing Major Security Issues, But Cloud Security May Be Most Immense
    A number of reports point to security problems within client environments, but cloud could be the biggest.
  • Threats
    Despite SIEM Software Adoption, Threat Coverage Comes Up Short
    Enterprise SIEMs are unprepared for 84% of certain tactics and techniques.
  • Industrial waterworks
    Florida Water Supply Hack Chilling Reminder of Infrastructure Vulnerability
    Similar attacks are likely on the horizon.

Leave a comment Cancel reply

-or-

Log in with your Channel Futures account

Alternatively, post a comment by completing the form below:

Your email address will not be published. Required fields are marked *

Related Content

  • HelpSystems Acquires Digital Defense to Add Cybersecurity Capabilities
  • HPE Distributors Key to as-a-Service Strategy
  • Blame IT Pros for Data Privacy Failures?
  • MSSPs, Beware: Threat Analysis Group Warns of North Korean Social Engineering

Galleries

View all

Threat Protection Vendors: Why MSSPs Have to Ramp Up Efforts Right Now

February 23, 2021

Industry Perspectives

View all

Three Ways MSPs Can Improve Supply Chain Security

February 24, 2021

SASE: The Key to Mitigating Business Transformation Risk

February 22, 2021

Public Sector IT Funding Outlook for 2021–and What It Means for Our Reseller Partners

February 18, 2021

Webinars

View all

XDR and Why it Matters to MSPs

March 24, 2021

Top Security Trends Impacting Technology Security Providers In 2021

March 25, 2021

In Case of Emergency: The Importance of Proactive Critical Event Management

February 23, 2021
  • 1

White Papers

View all

Kaspersky Endpoint Detection and Response Optimum

February 19, 2021

Product Brief: Kaseya VSA Integrated Workflows with BMS and IT Glue

January 26, 2021

Why Subscription Business Model

January 15, 2021

Upcoming Events

View all

Channel Partners Virtual

March 2, 2021 - March 4, 2021

Channel Partners Conference & Expo

November 1, 2021 - November 4, 2021

Videos and Fastchats

View all

FASTCHAT: How SOAR Eliminates Security Challenges and Elevates Service Provider Revenues

January 6, 2021

Happy Holidays from Channel Partners & Channel Futures!

December 21, 2020

FASTCHAT: How Old, Unpatched Technologies Are Creating New Security Threats for MSPs and Their Customers

December 3, 2020

Twitter

ChannelFutures

#CPVirtual is going live in just 5 days! Get your pass before rates go up, and join us next week for the premier vi… twitter.com/i/web/status/1…

February 25, 2021
ChannelFutures

#ZeroTrust approach boosts #cybersecurity, aids #datalossprevention, says @tgravel. @appgatesecurity… twitter.com/i/web/status/1…

February 25, 2021
ChannelFutures

.@BlackBerry report shows rise in hacker-for-hire groups targeting #MSSPs. dlvr.it/RtQjD9 https://t.co/VYr5cEXCCm

February 25, 2021
ChannelFutures

.@PTsecurity_UK discovers #vulnerabilities in @VMware vCenter server. dlvr.it/RtQjD5 https://t.co/WQbn5SJdFL

February 25, 2021
ChannelFutures

Take #supplychainsecurity to the next level. @Sophos #MSP #MSSP #ransomware #cybersecurity #managedservice… twitter.com/i/web/status/1…

February 25, 2021
ChannelFutures

[email protected]_inc rolls out first partner program. #securityanalytics dlvr.it/RtQhlW https://t.co/c1Xhxaf3qr

February 25, 2021
ChannelFutures

.@AteraCloud receives $25 million investment to help more #MSPs, IT pros. dlvr.it/RtPbBG https://t.co/UxHqhrUKgx

February 24, 2021
ChannelFutures

.@Infoblox rolls out new #Cloud Specialization program to increase partners' #SaaS sales. dlvr.it/RtPb7f https://t.co/CmZTwYiv1u

February 24, 2021

MSSP Insider

Newsletters and Updates

Sign up for The Channel Report, Channel Futures Update, MSP 501 Newsletter and more.

Live Channel Events

Get the latest information on the next industry-leading Channel Partners event.

Channel Partners Online

Want more? Find more channel news and analysis on our sister site, Channel Partners.

Media Kit And Advertising

Want to reach our audience? Access our media kit

DISCOVER MORE FROM INFORMA TECH

  • Channel Partners Online
  • Channel Partners Events
  • MSP 501
  • MSSP Insider
  • IoT World Today
  • Webhostingtalk

WORKING WITH US

  • Contact
  • About us
  • Advertise
  • Newsletter

FOLLOW Channel Futures ON SOCIAL

  • Privacy
  • CCPA: “Do Not Sell My Data”
  • Cookie Policy
  • Terms
Copyright © 2021 Informa PLC. Informa PLC is registered in England and Wales with company number 8860726 whose registered and Head office is 5 Howick Place, London, SW1P 1WG.
This website uses cookies, including third party ones, to allow for analysis of how people use our website in order to improve your experience and our services. By continuing to use our website, you agree to the use of such cookies. Click here for more information on our Cookie Policy and Privacy Policy.
X