PrivacySignal
Healthcare

British Scattered Spider Hacker Pleads Guilty to Cyberattacks on TfL; SSM Health Care; Sutter Health

HIPAA Journal · · US Federal · Healthcare Privacy

A British member of the Scattered Spider hacking group has pleaded guilty to cyberattacks on Transport for London, SSM Health Care, and Sutter Health, with a second British hacker also pleading guilty in connection with the TfL breach. The cases mark a rare instance of criminal accountability for a group linked to a string of high-profile intrusions.

Why this matters: Scattered Spider has hit some of the biggest targets around — casinos, telecoms, now hospitals and public transit. Two health systems are on this list, which means patient records were likely in the crosshairs. Health data is not like a leaked password you can change. It follows people for life. Guilty pleas are progress, but they do not undo the exposure. The real pressure this puts on organizations is simple: if a young hacker with social engineering skills can get in, the door was probably not as secure as the security budget suggested.

Who should care: Healthcare professionals · Privacy officers · Compliance

This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.

Analysis

All analysis →

Weekly Editorial Analysis from Experts and Editors

Related stories

Healthcare
HIPAA Journal · · US Federal

Data Breaches Reported by Sunshine Health; Health Payment Systems

Sunshine Health, a Florida-based Medicaid and health insurance agency, has reported a data breach involving the theft of protected health information following a vishing attack. Health Payment Systems has also disclosed a separate breach.

Who should care: Healthcare professionals · Privacy officers · Compliance

#healthcare Read original →
Healthcare
Nextgov/FCW · · US Federal

Federal agencies quietly joined health data superhighway governing council

Federal agencies have quietly joined the governing council of TEFCA, a national health data exchange network that connects thousands of hospitals, clinics, and other medical providers. The move gives federal agencies a formal role in a system designed to move health records digitally across the country.

Who should care: Healthcare professionals · Privacy officers · Compliance

#healthcare Read original →
Healthcare
EFF — Deeplinks · · International

Meta Must Stop Silencing Reproductive Health Information

The Electronic Frontier Foundation has filed a public comment with Meta's Oversight Board challenging the company's removal of posts about prescription medication, abortion care, and personal medical experiences on Instagram and other Meta platforms.

Who should care: Healthcare professionals · Privacy officers · Compliance

#healthcare Read original →
Healthcare
HIPAA Journal · · US Federal

Data Breaches Announced by Loma Linda University Health & UCLA Health

Loma Linda University Health and UCLA Health have both disclosed data security incidents. Details of the scope, affected individuals, and nature of the breaches have not been specified in available reporting.

Who should care: Healthcare professionals · Privacy officers · Compliance

#healthcare Read original →
Healthcare
HIPAA Journal · · US Federal

Five Healthcare Providers Settle Pixel Class Action Lawsuits

Five healthcare providers have reached settlements in class action lawsuits tied to their use of website tracking pixels, part of a broader wave of similar legal actions against the healthcare sector over the past 18 months.

Who should care: Healthcare professionals · Privacy officers · Compliance · Cybersecurity

#healthcare#surveillance Read original →
Healthcare
HIPAA Journal · · US Federal

Health Information Privacy Reform Act Advanced by HELP Committee

The Senate HELP Committee has advanced the Health Information Privacy Reform Act, a bill introduced last year aimed at extending privacy protections to health data that currently falls outside HIPAA's coverage.

Who should care: Healthcare professionals · Privacy officers · Compliance · General readers · Policy

#healthcare#privacy Read original →