Search site
Find podcasts, news, articles, webinars, and contributors in one search.
Health IT News
Browse by topic
Most-read stories in the last 7 days
1,000 stories
Jan 16, 2025·U.S. Department of Justice
The Justice Department and FBI have launched a major international operation to eradicate "PlugX" malware, attributed to the Mustang Panda hacking group backed by the Chinese government. Collaborating with international partners, including French law enforcement and cybersecurity firm Sekoia.io, the operation targeted a specific version of PlugX that has been stealing sensitive information globally since 2014. The campaign successfully removed the malware from approximately 4,258 computers in the U.S., underlining the DOJ's commitment to disrupting cyber threats and holding perpetrators accountable. Officials stressed the significance of international cooperation in addressing threats from state-sponsored hackers.
Jan 16, 2025·BankInfoSecurity
The proliferation of artificial intelligence (AI) tools has significantly increased API security threats, with 55% of IT teams worldwide reporting API-related incidents. Cybercriminals are leveraging AI to automate and enhance attacks, making them more sophisticated and harder to detect. In response, security firms are integrating AI into their defenses; for instance, Salt Security's AI-based assistant, Pepper, aids in API discovery and rapid threat response. Additionally, companies like Snyk are acquiring specialized firms to bolster API security for AI applications. Despite these advancements, the dynamic nature of AI agents presents unique challenges, necessitating continuous monitoring and comprehensive threat modeling to mitigate risks effectively.
Jan 16, 2025·HHS.gov
The HHS Office for Civil Rights has settled a case with Memorial Healthcare System over violations of HIPAA related to delays in patient access to medical records. The settlement requires the healthcare provider to implement corrective measures, including staff training on HIPAA regulations and improved procedures for handling access requests. This case emphasizes the importance of timely access to health information, reinforcing the need for healthcare organizations to adhere to federal regulations that protect patient rights and privacy.
Jan 15, 2025·CFODive
A recent study by Chubb reveals that cybersecurity threats, particularly data breaches, are now the primary financial concern for businesses, as identified by 40% of executives. The findings, based on a Harris poll, indicate a shift over the last decade towards recognizing risks associated with cyber incidents, artificial intelligence, climate change, and reputational damage. The report highlights the significant financial impact of cyber incidents, with the average data breach costing nearly $4.9 million, a 10% increase from the previous year. The cyberattack on UnitedHealth's Change Healthcare, which affected 100 million individuals and incurred an estimated $2.5 billion in costs, exemplifies these risks. In light of these challenges, 86% of surveyed companies are considering or have adopted business interruption coverage to mitigate potential disruptions, including those caused by cyberattacks.
Jan 15, 2025·BankInfoSecurity
Nitin Natarajan, the outgoing Deputy Director of CISA, conveyed optimism about the continuation of cybersecurity initiatives in healthcare under the upcoming Trump administration. In a recent interview, he discussed CISA's achievements during the Biden administration, particularly in helping critical infrastructure, like healthcare, address vulnerabilities amid rising ransomware threats. He highlighted the agency’s pre-ransomware notification program as vital support for healthcare organizations and acknowledged the resource challenges faced by smaller entities in enhancing their cybersecurity measures. Furthermore, Natarajan reflected on lessons learned from past cybersecurity incidents, including a significant ransomware attack on Change Healthcare in February 2023.
Jan 15, 2025·Krebs on Security
Microsoft's latest update addresses 161 security vulnerabilities in Windows, representing the largest patch deployment since 2017. This release includes three zero-day vulnerabilities, actively being exploited, emphasizing the need for immediate system updates. Among the critical issues are nine remote code execution vulnerabilities, with some receiving a CVSS score of 9.8, particularly concerning CVE-2025-21298, which allows code execution through a malicious .rtf file. These updates aim to strengthen defenses against ongoing cybersecurity threats.
Jan 14, 2025·LinkedIn
Building a strong cybersecurity brand is critical for Chief Information Security Officers (CISOs) to boost their organization's reputation and effectiveness. This involves establishing a positive identity that fosters trust and sets the organization apart in the market, which requires alignment with the company's vision and stakeholder needs. Key strategies for cultivating this brand include promoting transparency, consistent messaging, and avoiding jargon, alongside enhancing cybersecurity awareness programs and showcasing achievements. Additionally, CISOs should focus on operational efficiencies, innovate through projects that demonstrate value, and utilize metrics to convey cybersecurity's strategic significance to stakeholders, while investing in team development to maintain engagement and commitment.
Jan 14, 2025·BankInfoSecurity
Tampa General Hospital has settled a class action lawsuit for $6.8 million following a 2023 data breach that compromised the information of 2.1 million individuals. The lawsuit accused TGH of negligence in protecting sensitive patient data, citing violations of multiple legal standards. While TGH managed to thwart a ransomware attack, attackers managed to access files over three weeks, exposing a variety of personal and medical information. The settlement reflects an increasing trend in healthcare breach lawsuits, especially as the U.S. Department of Health and Human Services prepares to propose updates to the HIPAA Security Rule that could impose stricter compliance standards on healthcare organizations, potentially leading to more lawsuits and larger settlements in the future.
Jan 14, 2025·Security Info Watch
The increasing reliance on emerging technologies has resulted in a notable rise in data-security class-action lawsuits, primarily due to the growing amount of sensitive data generated by online activities. High-profile companies like Meta and Apple have faced significant settlements as consumers, now more informed about their data privacy rights, are increasingly willing to litigate. The fragmented regulatory framework in the U.S. complicates compliance for companies, which are also experiencing heightened scrutiny from both consumers and regulators. In response, organizations are investing more in data security measures and professional training to mitigate risks, while corporate data security experts recommend adhering to industry standards and conducting regular security audits to strengthen defenses against potential breaches.
Jan 13, 2025·Nextgov
The Biden administration is preparing a cybersecurity executive order that promotes the use of digital identity documents, such as mobile driver's licenses (mDLs), for identity verification in public benefit programs to combat rising identity theft, particularly noted since the pandemic. Deputy National Security Director Anne Neuberger mentioned that the initiative, which has been in development for several months, will direct the National Institute of Standards and Technology to establish guidelines for online verification and encourage funding for states to adopt mDLs. However, the order does not address wider identity theft measures that were initially expected, and a separate executive order tackling identity fraud remains pending, facing obstacles related to privacy and bias concerns. Currently, approximately 15 states offer mDLs, mainly for in-person use.
Jan 13, 2025·Forbes
In 2024, the importance of effective digital and cybersecurity governance has been underscored by a series of high-profile incidents that revealed vulnerabilities in organizational oversight. Stakeholders, particularly institutional investors, are calling for reforms as they recognize cybersecurity as a critical enterprise risk amid the disruption caused by advancing technologies such as AI. This has led to a demand for board members with specialized expertise in these areas, with initiatives like Berkshire Hathaway's proposed AI committee illustrating the push for stronger governance in response to evolving risks.
Jan 13, 2025·Healthcare Finance News
Indiana University Health (IU Health) disclosed a cyberattack that compromised data from a team member's email account, with unauthorized access detected between August 27 and October 2, 2024. The investigation revealed that affected personal information could include addresses, medical records, and, in some cases, Social Security numbers. IU Health is offering impacted individuals 12 months of credit monitoring and has set up a dedicated call center for inquiries. The organization is also enhancing its security protocols in light of increasing cyber threats targeting healthcare entities.
Jan 12, 2025·Forbes
Healthcare CIOs and CISOs are analyzing a new proposal from HHS's Office for Civil Rights to update the HIPAA Security Rule with an emphasis on enhancing cybersecurity for electronic protected health information (ePHI). The proposed changes include stricter documentation requirements, such as maintaining a detailed inventory of technology assets and mapping ePHI flow, which organizations must update annually or after major operational shifts. This may pose challenges for smaller healthcare facilities that lack technical resources, leading some to consider external consulting for compliance. Additionally, organizations will be required to restore critical electronic systems within 72 hours following a loss, prompting necessary revisions to disaster recovery plans and budget allocations.
Jan 9, 2025·Cybersecurity Dive
The White House has launched the U.S. Cyber Trust Mark program, a voluntary labeling initiative designed to help consumers understand the security of smart devices. The program urges manufacturers to enhance security in the design of interconnected products, addressing growing concerns over cyber vulnerabilities associated with devices like smart TVs and security cameras. As American households average around 21 connected devices, the White House is considering an executive order mandating that federal purchases adhere to these security standards by 2027, reflecting a commitment to improving Internet of Things (IoT) product security. The initiative has also garnered bipartisan support from the Federal Communications Commission (FCC).
Jan 9, 2025·SecurityWeek
Amit Yoran, the CEO of Tenable, has died at 54, leaving a notable impact on the cybersecurity sector. Known for his strategic leadership, Yoran helped establish Tenable as a key player in cybersecurity solutions, particularly in vulnerability management and continuous network monitoring. His unexpected passing has raised concerns about the company's future and leadership transition as it aims to continue his legacy of innovation and commitment to enhancing cybersecurity practices amidst a rapidly changing landscape.
Jan 8, 2025·HIPAA Journal
Tampa General Hospital has reached a $6.8 million settlement in a class action lawsuit related to a data breach that affected over 2.4 million patients, initially reported to involve 1.2 million. The breach, detected on May 31, 2023, compromised sensitive information, including names, Social Security numbers, and health insurance data. The lawsuit alleged negligence in the hospital's cybersecurity practices, though the hospital denies wrongdoing and opted for the settlement to avoid trial costs. The settlement includes a fund for reimbursing affected individuals, with ordinary losses capped at $1,500.
Jan 8, 2025·PR Newswire
A recent Chubb report, based on a Harris Poll of 500 business leaders, identifies cybersecurity and technology disruption as the primary threats to business growth, with 40% of executives highlighting cyber breaches and data leaks as significant risks. Cybersecurity was also recognized as the main geopolitical risk by 60% of respondents, indicating heightened awareness of digital vulnerabilities. While 86% of companies are adopting business interruption coverage for cyberattacks and supply chain issues, many executives feel inadequately prepared to manage these emerging risks. Furthermore, 79% of respondents are integrating artificial intelligence into risk management, although concerns about AI-related issues, such as deepfakes, remain prevalent, impacting over half of the organizations surveyed.
Jan 7, 2025·Help Net Security
Recent reports from 2024 highlight that organizations are experiencing prolonged recovery times and rising costs from data breaches, with average recovery taking 7.3 months, exceeding initial expectations by 25%. Companies cutting cybersecurity budgets faced the most severe impacts, averaging 68 incidents and recovery times of 10.9 months. Identity-related breaches, reported by 40% of respondents, were deemed particularly costly, with significant financial fallout in sectors like agriculture and aerospace. Additionally, the increase in breaches has spurred over 1,300 class action lawsuits related to data privacy, more than doubling claims from the previous year.
Jan 7, 2025·BleepingComputer
A series of cyberattacks linked to the Chinese state-backed threat group Salt Typhoon has targeted several U.S. telecommunications companies, including Charter Communications, Consolidated Communications, and Windstream, following similar breaches at major carriers like AT&T and Verizon. These attacks enabled access to sensitive information, such as text messages and wiretap data from law enforcement investigations. Additionally, T-Mobile reported an unrelated incident involving compromised routers but did not attribute it to Salt Typhoon. Concerns about the security of U.S. telecom infrastructure have increased, as nine telecoms were reported compromised, sparking recommendations from the Cybersecurity and Infrastructure Security Agency for improved security measures among government officials.
Jan 7, 2025·Yahoo Finance
Yahoo underscores its commitment to user privacy and data security by utilizing cookies across its platforms for purposes such as user authentication, security enhancements, and usage measurement. Users consent to data collection, which may include location and browsing history, by clicking "Accept All," allowing Yahoo to personalize advertisements and improve user engagement. An alternative "Reject All" option is available for those who do not wish to share their data, along with customizable settings for data preferences. Users can modify their privacy choices anytime via designated links on Yahoo’s sites and apps.