Sophisticated cyberattacks have already hit hospitals and healthcare networks in Oregon, California, New York, Vermont, and other states
Attention medical laboratory managers and pathology group administrators: It’s time to ramp up your cyberdefenses. The FBI, the federal Department of Health and Human Services (HHS), and the federal Cybersecurity and Infrastructure Security Agency (CISA) issued a joint advisory (AA20-302A) warning US hospitals, clinical laboratories, and other healthcare providers to prepare for impending ransomware attacks, in which cybercriminals use malware, known as ransomware, to encrypt files on victims’ computers and demand payment to restore access.
The joint advisory, titled, “Ransomware Activity Targeting the Healthcare and Public Health Sector,” states, “CISA, FBI, and HHS have credible information of an increased and imminent cybercrime threat to US hospitals and healthcare providers.” It includes technical details about the threat—which uses a type of ransomware known as Ryuk—and suggests best practices for preventing and handling attacks.
In his KrebsOnSecurity blog post, titled, “FBI, DHS, HHS Warn of Imminent, Credible Ransomware Threat Against U.S. Hospitals,” former Washington Post reporter, Brian Krebs, wrote, “On Monday, Oct. 26, KrebsOnSecurity began following up on a tip from a reliable source that an aggressive Russian cybercriminal gang known for deploying ransomware was preparing to disrupt information technology systems at hundreds of hospitals, clinics, and medical care facilities across the United States. Today, officials from the FBI and the US Department of Homeland Security hastily assembled a conference call with healthcare industry executives warning about an ‘imminent cybercrime threat to US hospitals and healthcare providers.’”
Krebs went on to reported that the threat is linked to a notorious cybercriminal gang known as UNC1878, which planned to launch the attacks against 400 healthcare facilities.
Clinical Labs, Pathology Groups at Risk Because of the Patient Data They Keep
Hackers initially gain access to organizations’ computer systems through phishing campaigns, in which users receive emails “that contain either links to malicious websites that host the malware or attachments with the malware,” the advisory states. Krebs noted that the attacks are “often unique to each victim, including everything from the Microsoft Windows executable files that get dropped on the infected hosts to the so-called ‘command and control’ servers used to transmit data between and among compromised systems.”
Charles Carmakal, SVP and Chief Technology Officer of cybersecurity firm Mandiant told Reuters, “UNC1878 is one of the most brazen, heartless, and disruptive threat actors I’ve observed over my career,” adding, “Multiple hospitals have already been significantly impacted by Ryuk ransomware and their networks have been taken offline.”
John Riggi (above), senior cybersecurity adviser to the American Hospital Association (AHA), told the AP, “We are most concerned with ransomware attacks which have the potential to disrupt patient care operations and risk patient safety. We believe any cyberattack against any hospital or health system is a threat-to-life crime and should be responded to and pursued as such by the government.” Hospital-based medical laboratories and independent clinical laboratories that interface with hospital networks should be assess their vulnerability to cyberattacks and take appropriate steps to protect their patients’ data. (Photo copyright: American Hospital Association.)
Multiple Healthcare Provider Networks Under Attack
Hospitals in Oregon, California, and New York have already been hit by the attacks, Reuters reported. “We can still watch vitals and getting imaging done, but all results are being communicated via paper only,” a doctor at one facility told Reuters, which reported that “staff could see historic records but not update those files.”
Some of the hospitals that have reportedly experienced cyberattacks include:
In October, the Associated Press (AP) reported that a recent cyberattack disrupted computer systems at six hospitals in the University of Vermont (UVM) Health Network. The FBI would not comment on whether that attack involved ransomware, however, it forced the UVM Medical Center to shut down its computer system and reschedule elective procedures.
Threat intelligence analyst Allan Liska of US cybersecurity firm Recorded Future told Reuters, “This appears to have been a coordinated attack designed to disrupt hospitals specifically all around the country.”
He added, “While multiple ransomware attacks against healthcare providers each week have been commonplace, this is the first time we have seen six hospitals targeted in the same day by the same ransomware actor.”
An earlier ransomware attack in September targeted 250 healthcare facilities operated by Universal Health Services Inc. (UHS). A clinician at one facility reported “a high-anxiety scramble” where “medical staff could not easily see clinical laboratory results, imaging scans, medication lists, and other critical pieces of information doctors rely on to make decisions,” AP reported.
Outside of the US, a similar ransomware attack in October at a hospital in Düsseldorf, Germany, prompted a homicide investigation by German authorities after the death of a patient being transferred to another facility was linked to the attack, the BBC reported.
CISA, FBI, HHS, Advise Against Paying Ransoms
To deal with the ransomware attacks, CISA, FBI, and HHS advise against paying ransoms. “Payment does not guarantee files will be recovered,” the advisory states. “It may also embolden adversaries to target additional organizations, encourage other criminal actors to engage in the distribution of ransomware, and/or fund illicit activities.” The federal agencies advise organizations to take preventive measures and adopt plans for coping with attacks.
The advisory suggests:
Training programs for employees, including raising awareness about ransomware and phishing scams. Organizations should “ensure that employees know who to contact when they see suspicious activity or when they believe they have been a victim of a cyberattack.”
Regular backups of data and software. These should be “maintained offline or in separated networks as many ransomware variants attempt to find and delete any accessible backups.” Personnel should also test the backups.
Continuity plans in case information systems are not accessible. For example, organizations should maintain “hard copies of digital information that would be required for critical patient healthcare.”
“Without planning, provision, and implementation of continuity principles, organizations may be unable to continue operations,” the advisory states. “Evaluating continuity and capability will help identify continuity gaps. Through identifying and addressing these gaps, organizations can establish a viable continuity program that will help keep them functioning during cyberattacks or other emergencies.”
Dark Daily Publisher and Editor-in-Chief, Robert Michel, suggests that clinical laboratories and anatomic pathology groups should have their cyberdefenses assessed by security experts. “This is particularly true because the technologies and methods used by hackers change rapidly,” he said, “and if their laboratory information systems have not been assessed in the past year, then this proactive assessment could be the best insurance against an expensive ransomware attack a lab can purchase.”
Since the pandemic began, federal investigators are specifically looking for patterns of fraud in Medicare claims data for COVID-19 clinical laboratory testing
Last month, the federal Department of Health and Human Services (HHS) Office of Inspector General (OIG) announced it had been investigating trends in Medicare claims data that could indicate patterns of fraud in the billing for COVID-19 clinical laboratory tests, Modern Healthcare reported.
Stretching back to at least March, fraudulent actors offering fake SARS-CoV-2 tests have preyed on vulnerable Americans in a wide variety of ways during the public health emergency, according to published reports. Some scam operators have gone into nursing homes and long-term care facilities to collect cash from unsuspecting elders in exchange for swab collections and phony testing, the New York Times reported.
Since the declaration of the public health emergency in the US, the federal Centers for Medicare and Medicaid Services (CMS) no longer requires a lab test requisition signed by a treating physician or other provider for COVID-19 testing. “The strong demand for and limited supply of SARS-CoV-2 tests, along with the move by CMS to relax rules for certain test orders during the pandemic, makes the situation a potentially ripe one for fraud,” Modern Healthcare stated.
Plus, a lack of clarity about the medical necessity of COVID-19 tests could raise the liability risk for law-abiding clinical laboratories. All of these factors make COVID-19 testing fraud a potential bombshell for clinical laboratories conducting coronavirus testing that may get caught up in federal investigations.
Feds Step Up Enforcement
Shortly after the pandemic arrived in the US, the FBI, the Better Business Bureau (BBB), the FDA, the federal Department of Health and Human Services (HHS), and other federal and local authorities have frequently warned doctors, hospitals, and healthcare consumers about the potential for fraud by unscrupulous companies purporting to offer legitimate clinical laboratory testing for COVID-19. A June 26 FBI press release stated, “Scammers are marketing fraudulent and/or unapproved COVID-19 antibody tests, potentially providing false results.”
Some of the fraudsters behind these scams have operated online and through social media and email. While others have conducted these scams in person or over the phone, noted the press release.
And yet, despite the warnings, the scams and news articles about them have continued to spread throughout the COVID-19 pandemic.
Various Forms of Fraud and Their Consequences
In many of these scams, fraudsters seek to collect consumers’ personal information, including names, dates of birth, and Social Security numbers, as well as other forms of personal health information, such as Medicare or private health insurance data, the FBI reported. Scammers can use that information in medical insurance fraud schemes or to commit identity theft, the agency added.
Additionally, any fake or inaccurate COVID-19 tests or assays that the FDA has not allowed for use could provide doctors with false results, potentially creating a dangerous situation for patients.
The New York Times (NYT) recently reported that the FBI had issued a warning “about scammers who advertise fraudulent COVID-19 antibody tests as a way to obtain personal information that can be used for identity theft or medical insurance fraud.”
Three days after the FBI issued its warning about the COVID-19 antibody testing scam, the BBB added an alert to its website: “BBB Scam Alert: Want a COVID-19 test? There’s a scam for that.” BBB also provided advice to consumers about how to avoid testing scams.
On June 17, the FDA reported that it issued warning letters to three companies for marketing adulterated and misbranded COVID-19 antibody tests, stated an FDA news release. The agency sent warning letters to:
In the FDA’s announcement, Jeff Shuren, MD, JD (above), Director of the FDA’s Center for Devices and Radiological Health, said “When tests are marketed inappropriately, with inaccurate or misleading claims—such as the ability to perform the test completely at home, or that the test is authorized, cleared, or approved when it is not—they put the health of Americans at risk. Such conduct will not be tolerated by the FDA, and we will continue to monitor tests marketed in the US, taking appropriate action as warranted.” (Photo copyright: The Food and Drug Administration.)
Scams Reported Just in April
On April 17, the New York Times reported that a special agent with the HHS OIG noted that impostors seeking Medicare or Medicaid information posed as doctors or laboratory technicians to offer fake tests in nursing homes and assisted living facilities.
Earlier in April, The Texas Tribune reported that the owner of a freestanding emergency room in Laredo, Texas, spent $500,000 to buy 20,000 rapid COVID-19 tests for patients suspected of having COVID-19. Health officials in Laredo planned to establish a drive-through testing site and then administer tests that came from a manufacturer in China to detect active infections. After trying to validate the tests, city health officials found they were unreliable and unusable.
An April 9 report from the news department of the AARP (American Association of Retired Persons) stated that federal officials have found fake coronavirus testing sites in many states, including Alabama, Arizona, Florida, Georgia, Kentucky, New York, and Washington state.
The FBI, according to AARP, investigated several fake test sites in Louisville, Ky., after a city official reported that people in personal protective equipment (PPE) were collecting biological specimens from residents. Those seeking tests were told to pay $240 in cash or give their Medicare, Medicaid, or Social Security cards to verify their identity.
Fake drive-up testing sites were reported at gas stations and other locations in Louisville over a four-day period, the AARP reported.
On April 2, WRGB TV in Albany, N.Y., reported that scammers pretending to be from the New York State Department of Health (NYSDOH) were taking money and insurance information from people in exchange for fake coronavirus tests. One woman told police she got a fake test at a drive-up site in a Little League parking lot.
North Greenbush police said the scammers identified themselves as being with NYSDOH and collected money and insurance information from multiple people. Police and state officials said the DOH had no connection to the collection site in the parking lot.
Lessons for Lab Directors
For clinical laboratory directors and all clinical lab scientists, the lesson from these stories is to be wary of strangers offering COVID-19 testing, while also making certain to post information for customers about the legitimacy of your lab’s COVID-19 rapid molecular and serological tests. Doing so might involve providing proof that the FDA has allowed your tests to be used for the coronavirus.
Also, medical laboratories should ensure that all employees collecting specimens in public places display proper identification.
Following the raid, the company’s co-founders resigned
from the board of directors
Microbiome testing company, uBiome, a biotechnology developer that offers at-home direct-to-consumer (DTC) test kits to health-conscious individuals who wish to learn more about the bacteria in their gut, or who want to have their microbiome genetically sequenced, has recently come under investigation by insurance companies and state regulators that are looking into the company’s business practices.
CNBC
reported that the Federal Bureau of
Investigation (FBI) raided the company’s San Francisco headquarters in
April following allegations of insurance fraud and questionable billing
practices. The alleged offenses, according to CNBC, included claims that
uBiome routinely billed patients for tests multiple times without consent.
Becker’s
Hospital Review wrote that, “Billing documents obtained by The Wall Street
Journal and described in a June 24 report further illustrate uBiome’s
allegedly improper billing and prescribing practices. For example, the
documents reportedly show that the startup would bill insurers for a lab test
of 12 to 25 gastrointestinal pathogens, despite the fact that its tests only
included information for about five pathogens.”
Company Insider Allegations Trigger FBI Raid
In its article, CNBC stated that “company insiders”
alleged it was “common practice” for uBiome to bill patients’ insurance
companies multiple times for the same test.
“The company also pressured its doctors to approve tests
with minimal oversight, according to insiders and internal documents seen by CNBC.
The practices were in service of an aggressive growth plan that focused on
increasing the number of billable tests served,” CNBC wrote.
FierceBiotech reported that, “According to previous
reports, the large insurers Anthem, Aetna, and Regence BlueCross BlueShield
have been examining the company’s billing practices for its physician-ordered
tests—as has the California Department of Insurance—with probes focusing on
possible financial connections between uBiome and the doctors ordering the
tests, as well as rumors of double-billing for tests using the same sample.”
Becker’s Hospital Review revealed that when the FBI
raided uBiome they seized employee computers. And that, following the raid,
uBiome had announced it would temporarily suspend clinical operations and not
release reports, process samples, or bill health insurance for their services.
The company also announced layoffs and that it would stop
selling SmartJane and SmartGut test kits, Becker’s reported.
uBiome Assumes New Leadership
Following the FBI raid, uBiome placed its co-founders Jessica
Richman (CEO) and Zac
Apte (CTO) on administrative leave while conducting an internal
investigation (both have since resigned from the company’s board of directors).
The company’s board of directors then named general counsel, John Rakow, to be interim CEO,
FierceBiotech
reported.
John Rakow (center) is shown above with uBiome co-founders Jessica Richman (lower left) and Zac Apte (lower right). In a company statement, Rakow stressed that he believed in the company’s products and ability to survive the scandal. His belief may be based on evidence. Researchers have been developing tests based on the human microbiome for everything from weight loss to predicting age to diagnosing cancer. Such tests are becoming increasingly popular. Dark Daily has reported on this trend in multiple e-briefings. (Photo copyrights: LinkedIn/uBiome.)
After serving two months as the interim CEO, Rakow resigned
from the position. The interim leadership of uBiome was then handed over to
three directors from Goldin
Associates, a New York City-based consulting firm, FierceBiotech
reported. They include:
SmartFlu: a nasal microbiome swab that detects bacteria and viruses associated with the flu, the common cold, and bacterial infections.
What Went Wrong?
Richman and Apte founded uBiome in 2012 with the intent of
marketing a new test that would prove a link between peoples’ microbiome and their
overall health. The two founders initially raised more than $100 million from
venture capitalists, and, according to PitchBook,
uBiome was last valued at around $600 million, Forbes
reported.
Nevertheless, as a company, uBiome’s future is uncertain. Of
greater concern to clinical laboratory leaders is whether at-home microbiology
self-test kits will become a viable, safe alternative to tests traditionally performed
by qualified personnel in controlled laboratory environments.