Search site
Find podcasts, news, articles, webinars, and contributors in one search.
Health IT News
Browse by topic
Most-read stories in the last 7 days
1,000 stories
Dec 8, 2024·Forbes
A recent CyberArk survey reveals that 65% of employees are circumventing essential cybersecurity protocols to enhance productivity, posing significant risks for organizations increasingly dependent on digital tools. Key risky behaviors identified include password reuse by 49% of respondents, password sharing by 30%, and 80% accessing workplace applications on unsecured personal devices. The findings highlight a tension between enforcing security measures and maintaining workflow efficiency, as employees often view these protocols as obstructive and prioritize productivity in fast-paced environments, demonstrating a need for better awareness and training on cybersecurity risks.
Dec 5, 2024·CSO Online
A recent IBM report indicates that 63% of companies plan to pass the costs of data breaches onto customers, up from 57% the previous year. This trend highlights a growing reliance on consumers to absorb the financial burden of security failures, though the report does not detail how much will be transferred. Experts underscore the importance of transparency in communicating these changes to avoid potential backlash via social media. Additionally, this situation may provide Chief Information Security Officers with leverage to secure more funding for cybersecurity initiatives, as rising breach costs could justify greater investment in security measures.
Dec 5, 2024·Cybersecurity Dive
A cyberattack campaign named Salt Typhoon, believed to be linked to the Chinese government, has compromised at least eight U.S. telecommunications providers over the past one to two years, according to Anne Neuberger, Deputy National Security Advisor for Cyber and Emerging Technology. The FBI and CISA confirmed that attackers obtained significant records, including metadata, allowing access to communications of everyday Americans and some government officials, although no classified information appears to be compromised. Neuberger cautioned that threat actors might still access these networks, highlighting ongoing vulnerabilities and the necessity for U.S. companies to improve their cybersecurity measures.
Dec 4, 2024·Washington Post
The rise of artificial intelligence in conjunction with extensive data breaches has heightened risks to consumer privacy, as hackers exploit readily available personal information for sophisticated phishing attacks. These criminals are utilizing AI to analyze compromised data, including sensitive health records and Social Security numbers, to create convincing communications that mimic trusted sources. This trend threatens not only individual privacy but also the stability of financial and corporate systems, making it challenging for consumers to distinguish between legitimate and fraudulent communications. The potential for significant financial losses and data breaches underscores the urgent need for enhanced security measures in the digital landscape.
Dec 4, 2024·CBS News
Minnesota has implemented a new law requiring public agencies and their contractors to report cybersecurity incidents, effective immediately. The legislation, which applies to various levels of government and educational institutions, aims to enhance the state's cybersecurity framework by analyzing reported data to identify trends that can inform preventive measures against cyberattacks. Officials from the Minnesota Bureau of Criminal Apprehension and Minnesota IT Services will oversee this analysis, with a focus on aiding schools that often lack adequate resources to handle such threats. The law, signed by Governor Tim Walz in May, seeks to foster collaboration between government entities and educational institutions and includes provisions for ongoing support and guidance during the reporting process.
Dec 3, 2024·GlobeNewswire
Fairfax, VA-based Inova has become the first healthcare organization in the U.S. to receive the Responsible Use of Health Data (RUHD) Certification from The Joint Commission, a step aimed at guiding health systems in managing the secondary use of patient data responsibly. The certification process required Inova to implement rigorous measures, such as de-identifying health data, establishing security protocols, and ensuring transparency in data usage. This achievement was recognized in a discussion at the Inova Center for Personalized Health, attended by policymakers, emphasizing the importance of patient data privacy amidst evolving healthcare challenges. Inova's leadership highlighted that this certification enhances patient trust and reinforces ethical data stewardship.
Dec 3, 2024·Dark Reading
Organizations are increasingly seeking virtual chief information security officers (vCISOs) to bolster their cybersecurity frameworks in response to rising threats and incidents. Collaborating with managed security service providers (MSSPs), many companies find vCISOs essential for creating proactive security plans, while venture capitalists and cyber insurers often advocate for their expertise during due diligence and to promote best practices. The growing demand reflects a shortage of skilled cybersecurity executives, making vCISOs an appealing option for companies looking to implement a consistent and strategic management approach without the costs associated with a full-time hire. Organizations typically engage vCISOs to comply with regulations, align with industry standards, or establish comprehensive security programs.
Dec 3, 2024·Apple News
The discussion surrounding the establishment of a dedicated military cyber force highlights the growing importance of cybersecurity in modern warfare. Supporters believe that such a unit could improve national security by providing specialized responses to cyber threats, protecting critical infrastructure, and advancing offensive capabilities. In contrast, opponents caution that creating a separate cyber force might lead to operational fragmentation and inefficiencies, heightening the risk of cyber conflicts. Ethical and legal concerns also emerge, as questions about rules of engagement and accountability in cyber operations become critical. The debate ultimately centers on finding a balance between enhancing defense capabilities and maintaining coherent cybersecurity strategies within military establishments.
Dec 3, 2024·KTTC
The Veterans Health Administration (VHA) has reported a cybersecurity breach that may have compromised the protected health information of over 2,000 veterans, related to files managed by contracted vendor DBP, Inc. Although medical records within the VA's electronic health system were not affected, sensitive documents, including full names and social security numbers, were found to be vulnerable. In response, the VHA has investigated the incident, shut down the affected server, and implemented new security measures. Affected veterans will receive a Privacy Notification Letter detailing the potential exposure of their data and outlining the steps being taken to address the breach.
Dec 2, 2024·Forbes
A recent cyber attack linked to the Russian state-sponsored group RomCom has exploited two critical zero-day vulnerabilities in Mozilla Firefox and Windows operating systems, allowing attackers to install a backdoor without user interaction. Security researchers from ESET have reported that the attack leverages a use-after-free vulnerability in Firefox, paired with a privilege escalation flaw in Windows, enabling command execution and additional malware downloads. The attack typically initiates through a fraudulent website that directs victims to the malicious exploit server, threatening users primarily in Europe and North America, while RomCom continues to focus on espionage alongside its cybercrime activities.
Dec 2, 2024·The Guardian
Alder Hey Children's Hospital in Liverpool is investigating a possible data breach after the INC ransomware group claimed to have stolen sensitive patient information and financial documents, sharing alleged screenshots on the dark web. The hospital is currently validating the claims, which may include names, addresses, and medical reports. In response, Alder Hey is collaborating with the National Crime Agency to secure its IT systems and has confirmed that patient services remain unaffected. The incident highlights the growing trend of ransomware attacks targeting healthcare organizations, a sector increasingly seen as vulnerable.
Dec 1, 2024·The Record
The Wirral University Teaching Hospital NHS Foundation Trust in northwest England has declared a "major incident" following a cyberattack that poses a significant risk to public health. The Trust has canceled all outpatient appointments and advised patients to seek emergency care only, as staff face major operational disruptions due to inaccessible electronic systems. This incident highlights an ongoing issue with cyberattacks on the NHS, following a similar ransomware attack earlier in 2024 that resulted in extensive cancellations across London hospitals. The Trust has expressed regret over the situation and plans to contact affected patients to reschedule their appointments.
Dec 1, 2024·Cybersecurity Dive
CrowdStrike managed to retain a strong customer base despite a major global IT outage on July 19, 2024, which stemmed from a problematic software update to its Falcon platform. During a recent earnings call, CEO George Kurtz noted a gross retention rate exceeding 97% for the third quarter of fiscal 2025, highlighting customer loyalty amidst the crisis. The outage led to $33.9 million in expenses and a net loss of $16.8 million for the quarter, yet the company also reported a 29% year-over-year revenue increase, totaling $1 billion. CFO Burt Podbere acknowledged the financial repercussions but expressed hope for recovery through internal changes. In response to the incident, CrowdStrike launched "customer commitment packages" to enhance relationships with clients, although some churn was observed in its managed security services sector.
Dec 1, 2024·CSO Online
The role of Chief Information Security Officers (CISOs) is increasingly associated with stress-related substance abuse due to burnout and isolation, as highlighted by Olivia Rose, a former corporate CISO. She recounted her struggles with overwhelming responsibilities that impacted her personal life and led to increased alcohol use. After moving to a consulting role as a virtual CISO, Rose achieved a healthier work-life balance and quit drinking. Surveys indicate a troubling prevalence of stress in the cybersecurity field, with 91% of CISOs experiencing moderate to severe stress, and 17% resorting to alcohol or medications for coping. Experts call for open discussions about mental health and addiction in cybersecurity to improve the wellbeing of professionals in this high-pressure environment.
Nov 26, 2024·SecurityWeek
Russian cyberspies carried out a Wi-Fi hacking operation by targeting a building near a U.S. government facility, allowing them to access the facility's systems without direct intrusion. This tactic reveals a strategic use of physical proximity to exploit digital vulnerabilities, enabling attackers to potentially intercept sensitive data and communications. Experts are stressing the need for enhanced cybersecurity protocols, such as VPNs and encrypted communications, and urge organizations to bolster physical security to prevent unauthorized access to adjacent buildings that could facilitate similar attacks, highlighting a crucial consideration for safeguarding national security amidst evolving cyber threats.
Nov 26, 2024·Infosecurity Magazine
In the third quarter of 2024, ransomware groups, particularly RansomHub and LockBit 3.0, accounted for 40% of all cyber-attacks, as detailed in a report by Corvus Insurance. The report reveals a steady threat level from ransomware, with the number of victims listed on leak sites increasing slightly from 1,248 to 1,257. RansomHub has emerged as a key player, significantly increasing its victim count, while LockBit 3.0 has seen a marked reduction in activity due to law enforcement efforts. Overall, the study identifies a total of 59 active ransomware groups, indicating a complex and competitive landscape in the cyber threat environment.
Nov 25, 2024·Infosecurity Magazine
Ransomware gangs are strategically targeting organizations during weekends and holidays, as a report from Semperis indicates that 86% of companies experiencing these attacks were hit when their cybersecurity operations centers (SOCs) were understaffed. Despite 96% of organizations maintaining a 24/7 SOC, many reduce staffing by up to 50% during off-hours due to financial constraints and the assumption that risks are lower when fewer employees are online. The report highlights that this vulnerability allows attackers to navigate networks with less resistance and encrypt sensitive data, with significant incidents reported in the finance, manufacturing, and utilities sectors.
Nov 25, 2024·CyberNews
Public Wi-Fi networks, often found in public spaces like cafes and airports, provide convenient internet access but come with significant security risks. Cybercriminals can exploit these connections to intercept sensitive information, making it essential for users to understand the associated dangers. To enhance security, the best practice is to avoid public Wi-Fi when possible; if necessary, users should confirm the legitimacy of the network, avoid sensitive transactions, update their software regularly, disable file sharing, and ensure they are using HTTPS websites. Lastly, forgetting the network after use can further safeguard against unauthorized access.
Nov 25, 2024·Healthcare IT News
CommonSpirit Health has formed a clinical collaboration with the University of Utah Health to improve access to medical care along the Wasatch Front, focusing on enhancing population health and care delivery. This partnership will facilitate closer cooperation between U of U Health providers and CommonSpirit hospitals, particularly benefiting vulnerable populations. The collaboration also aims to bolster cybersecurity resilience in light of recent challenges faced by CommonSpirit, including a ransomware attack that affected multiple facilities. With the acquisition of five hospitals in Utah earlier this year, CommonSpirit aims to strengthen its regional presence and leverage U of U Health's academic resources for better comprehensive care delivery.
Nov 24, 2024·Help Senate 2023-10-17
U.S. Senators Bill Cassidy, Mark Warner, John Cornyn, and Maggie Hassan have introduced the Health Care Cybersecurity and Resiliency Act of 2024, aimed at improving cybersecurity in the healthcare sector to safeguard patient health data. This bipartisan legislation, prompted by increasing cyberattack threats, proposes grants for healthcare organizations to enhance their defenses and provides cybersecurity training, particularly for rural clinics. It also seeks to improve coordination between the Department of Health and Human Services and the Cybersecurity and Infrastructure Security Agency and suggests updates to HIPAA regulations to ensure the adoption of advanced cybersecurity practices.