Hemo Alliance Newsletters

Legal Update, January 2024

Legal Update

Legal Team Update: Beware! Scammers Steal Funds from Department of Health and Human Services (HHS) Grant Recipients
by Elizabeth “Issie” Karan, Karan Legal Group, Hemophilia Alliance Legal Counsel

Last week, news outlets reported that hackers gained access to the Payment Management Services (PMS) system utilized by HHS to process civilian grant payments and, from late March to mid-November, these hackers withdrew about $7.5 million intended to be awarded to five accounts. According to anonymous sources, the hackers have not been identified by federal authorities and the intended grantees still have not received their awards.

We regularly hear from IT experts, including those on the Alliance team like Kiet, that cybersecurity must be a priority for organizations. Yet, the risks still feel abstract and difficult to quantify. The latest attack on the government brings the chickens home to roost for Hemophilia Treatment Centers Regional grantees who utilize PMS to draw down grant funds.

The HHS’s Office of Information Security and the Health Sector Cybersecurity Coordination Center (HC3) reports that ransomware and data breaches were the most common cyberattacks in health care and often begin with a successful phishing attempt. Additionally, artificial intelligence has made these phishing attempts more effective.

In the most recent attack, HHS determined the hackers got into the grantees’ domain email accounts and used spearphishing emails to target specific individuals or organizations. The attacks worked and hackers were able to trick US payment staff into providing access to the grantees’ PMS accounts. Posing as actual users, the government sent the hackers the money believing they were the legitimate grant recipients.

HC3 provides recommendations for health care organizations to protect against cyberattacks.

  • First, security begins with ensuring that your mail server is configured to filter unwanted e-mails. These will not prevent all phishing e-mails, but they should reduce some unwanted traffic.
  • Second, end users should be periodically trained on themes emerging in phishing e-mails, such as references to an invoice (and related attachment), requests for personal information, offers of coupons and discounts or even government refunds.
  • Third, HC3 highly recommends multi-factor authentication.
  • Finally, security software should be employed where possible.

If your HTC is concerned about its cyber security, please reach out to the Alliance team for assistance.

Also in this Issue…


· Welcome 2024

Advocacy Update
· Hemophilia Alliance 2024 Hill Day – The United Voices of Our Community

Washington Update
· Proposed Rule on Affordable Care Act Provisions Published
· Congress Puts Off Funding Bills Until March
· CMS Publishes Prior Authorization Final Rule

Member and Community Relations Update
· “The January Blues”

Alliance Update
· Viva Engage! Hemophilia Alliance Virtual Networking Platform
· 2024 Meeting Schedules

Notes from the Community
· WFH 2024 World Congress taking place this April

Team Alliance Contact Information

We work for you! Please don’t hesitate to contact any of us with any questions or concerns:

Name Email Phone
Jeff Blake jeff@hemoalliance.org 317-657-5913
Jennifer Borrillo, MSW, LCSW, MBA borrillo@hemoalliance.org 504-376-5282
Heidi Lane, PT, DPT, PCS heidi@hemoalliance.org 435-659-1230
Jeff Amond amond@hemoalliance.org 608-206-3132
Jennifer Anders jennifer@hemoalliance.org 954-218-8509
Angela Blue, MBA angela@hemoalliance.org 651-308-3902
Karen Bowe-Hause karen@hemoalliance.org 717-571-0266
Zack Duffy zack@hemoalliance.org 503-804-2581
Michael B. Glomb MGlomb@ftlf.com 202-466-8960
Johanna Gray, MPA jgray@artemispolicygroup.com 703-304-8111
Kiet Huynh kiet@hemoalliance.org 917-362-1382
Elizabeth Karan elizabeth@karanlegalgroup.com 612-202-3240
Kollet Koulianos, MBA kollet@hemoalliance.org 309-397-8431
Roland P. Lamy, Jr. roland@hemoalliance.org 603-491-0853
Dr. George L. Oestreich, Pharm.D., MPA george@gloetal.com 573-230-7075
Theresa Parker theresa@hemoalliance.org 727-688-2568
Mark Plencner mark@hemoalliance.org 701-318-2910
Ellen Riker eriker@artemispolicygroup.com 202-257-6670