Search site
Find podcasts, news, articles, webinars, and contributors in one search.
Health IT News
Browse by topic
Most-read stories in the last 7 days
1,000 stories
Nov 12, 2024·CSO
Cybersecurity associations are essential for supporting Chief Information Security Officers (CISOs) by offering professional development resources, networking opportunities, and industry certifications. Notable organizations like ISC2, ISACA, ISSA, and the Cloud Security Alliance (CSA) play significant roles in the cybersecurity community. ISC2, for instance, has about 664,000 members and provides prestigious certifications such as the CISSP. ISACA, with around 180,000 members, focuses on IT governance, while ISSA promotes networking among its 7,500 members. The CSA addresses cloud security concerns with over 126,000 volunteers globally, fostering collaboration and education in tackling cloud vulnerabilities.
Nov 11, 2024·CSO Online
A significant number of organizations face difficulties in identifying the sources of their data security incidents, with one-third unaware of the causes behind breaches in the past year. According to the Foundry/CSO Security Priorities Study 2024, only 67% of security leaders can identify breach causes, complicated further by lengthy detection times and the sophistication of modern attacks. Additionally, financial constraints and a shortage of skilled professionals hinder effective investigations. The reliance on outsourced security operations and the absence of robust monitoring systems contribute to challenges in understanding and responding to incidents, often resulting in inadequate follow-up and root cause analysis.
Nov 11, 2024·BleepingComputer
Cisco has released a security update to address a serious vulnerability, CVE-2024-20418, affecting its Ultra-Reliable Wireless Backhaul (URWB) access points, which are critical for industrial wireless automation. The flaw, located in the web-based management interface of Cisco's Unified Industrial Wireless Software, allows unauthenticated attackers to execute commands with root privileges through command injection attacks without user interaction. This vulnerability affects specific models, including the Catalyst IW9165D, IW9165E, and IW9167E access points, only when running vulnerable software in URWB mode. While there is no evidence of active exploitation or publicly available exploit code, administrators are advised to check their devices for risk using the "show mpls-config" command.
Nov 11, 2024·Albuquerque Journal
A recent data breach at Presbyterian Healthcare Services may have compromised the personal information of patients, including names and addresses. The law firm representing the healthcare provider is investigating the breach's extent and its potential impact on individuals. In response, Presbyterian Healthcare Services is collaborating with the firm to assess the situation and notify affected patients on how to protect themselves from identity theft or fraud. This incident underscores ongoing concerns about healthcare data security and highlights the need for stronger cybersecurity measures within the industry. Updates from the organization regarding the investigation are anticipated.
Nov 11, 2024·CIODive
In response to a notable outage caused by a flawed CrowdStrike security update in July, technology leaders are reassessing their IT operational resilience. A survey by Cockroach Labs and Wakefield Research revealed that over 90% of 1,000 senior cloud architects and engineers recognized operational weaknesses that could lead to costly interruptions, with nearly half admitting to inadequate measures for improvement. The incident, which disrupted millions of Windows systems and impacted major airlines and banks, underscored the necessity for robust cybersecurity and operational strategies, as companies reported an average of 86 outages a year, with significant recovery times and resultant productivity losses.
Nov 11, 2024·Healthcare IT News
Ransomware attacks and cyber threats are increasingly affecting healthcare services in the U.S., with an average of two data breaches occurring daily, according to Greg Garcia of the Health Sector Coordinating Council Cybersecurity Working Group. A recent ransomware incident at Memorial Hospital in Bainbridge, Georgia, disrupted its electronic health records system, forcing a temporary shift to paper processes. Meanwhile, Summit Pathology in Colorado reported a significant data breach impacting over 1.8 million individuals, with sensitive patient information being compromised.
Nov 7, 2024·SecurityWeek
CrowdStrike has announced plans to acquire Adaptive Shield for approximately $300 million, aiming to enhance its cybersecurity offerings focused on cloud application security. Adaptive Shield specializes in securing SaaS applications, and its integration into CrowdStrike's platform is expected to improve visibility and control over cloud security configurations. This acquisition responds to the increasing demand for comprehensive security solutions as organizations adopt cloud technologies and face growing cyber threats. By incorporating Adaptive Shield’s capabilities, CrowdStrike intends to strengthen its position in the evolving cybersecurity landscape and better protect sensitive data and applications for its clients.
North Korean hackers are employing a sophisticated phishing campaign targeting macOS users with counterfeit cryptocurrency-related PDF documents. These PDFs are designed to install malware, compromising systems and stealing sensitive data. The campaign reflects the evolving nature of cyber threats as it capitalizes on trends in digital currency to lure victims through seemingly legitimate offers. Cybersecurity experts urge macOS users, particularly those involved with cryptocurrency, to remain vigilant and adopt enhanced security measures in light of these emerging threats, which indicate a worrying shift from traditional Windows targets to macOS.
Nov 7, 2024·BleepingComputer
Google has announced that multi-factor authentication (MFA) will be mandatory for all Google Cloud accounts by the end of 2025, targeting enhanced security for businesses and IT teams. The rollout will occur in three phases, starting with reminders for users without MFA this month, followed by notifications for those using only passwords in early 2025. Ultimately, all Google Cloud users, including federated users, will need to implement MFA, underscoring its importance for account protection.
Nov 6, 2024·Newsday
A data breach at Long Island Plastic Surgical Group has compromised the personal information of 161,707 patients, with unauthorized access occurring between January 4 and 8. The incident, disclosed on October 4, prompted an investigation by external cybersecurity experts, which revealed that sensitive data including Social Security numbers and medical information were accessed. The practice has reported the breach to the Department of Health and Human Services and is working to enhance its security measures. Ransomware groups Radar and AlphV have claimed responsibility, highlighting the ongoing vulnerability of healthcare providers to cyberattacks.
Nov 6, 2024·SecurityWeek
Mystic Valley Elder Services has reported a data breach affecting approximately 87,000 individuals due to unauthorized access to its computer systems. The organization, which supports the elderly in Massachusetts, discovered the breach during a routine security assessment and has since taken steps to secure its systems, engage cybersecurity experts, and collaborate with law enforcement. Affected individuals have been notified and provided with resources, including credit monitoring services, to protect their personal information. The incident underscores the increasing risks of cyberattacks on healthcare and social service organizations and raises concerns about the security of sensitive data for vulnerable populations.
Nov 6, 2024·Healthcare IT News
Cherilyn Pascoe, Director of the National Cybersecurity Center of Excellence at NIST, underscored the critical need for trust and collaboration in cybersecurity during her keynote at the HIMSS24 Healthcare Cybersecurity Forum. She discussed NIST's longstanding role in developing security standards, including the advanced encryption standard, and emphasized the importance of incorporating trust in technology for societal benefit. Pascoe highlighted NIST's recent update of the Cybersecurity Framework to Version 2.0, developed with input from various sectors, and noted the collaboration with 34 healthcare organizations to improve cybersecurity practices. She also outlined specific projects focused on securing telehealth ecosystems and genomic data cybersecurity.
Nov 5, 2024·TechCrunch
A new group of financially motivated hackers known as "advanced persistent teenagers" is emerging as a significant cybersecurity threat, with known entities like Lapsus$ and Scattered Spider leading the charge. These young cybercriminals have employed sophisticated social engineering tactics to infiltrate major organizations, including hotels and tech companies, by impersonating help desk staff and using credible email lures to extract sensitive information. Cybersecurity experts, including Darren Gruber from MongoDB and Heather Gantt-Evans from Marqeta, emphasize the need for organizations to recognize and understand the tactics of these youth-driven cyber threats, which exploit vulnerabilities in human behavior rather than relying solely on advanced technology.
Nov 5, 2024·Healthcare Digital
TikTok, one of the world's most popular social media platforms, is being sued for failing to stop harmful content from being published. The lawsuit in France highlights ongoing concerns about the potential risks associated with social media platforms, particularly in relation to the mental health of young users. As the platform navigates these legal challenges and health misinformation, it reflects a larger conversation about the responsibility of tech companies in safeguarding their audience.
Nov 5, 2024·LinkedIn
Rural hospitals face increasing threats from ransomware attacks, which jeopardize their operations and patient care. Healthcare technology executive Joey Meneses emphasizes the urgent need for these facilities to enhance their cybersecurity measures, noting that their limited resources make them vulnerable to cybercriminals. Ransomware incidents can lead to operational disruptions and erode community trust, making cybersecurity a critical priority rather than just a technical concern. Meneses advocates for a proactive strategy that includes investing in security technologies, regular assessments, and staff training to foster a culture of cybersecurity awareness. This approach is essential to protect the health and well-being of patients in these at-risk areas.
Nov 5, 2024·GovTech
Healthcare organizations are increasingly targeted by cyber attacks, with a dramatic 128 percent rise in ransomware incidents in 2023. The recent breach of Change Healthcare, affecting around 100 million people, highlights the sector's vulnerability due to interconnected systems and the critical nature of patient data. Experts call for stronger cybersecurity standards beyond the current HIPAA guidelines, pointing towards frameworks like those from the National Institute of Standards and Technology and HITRUST. With potential updates to HIPAA and New York state introducing stricter cybersecurity measures for hospitals, identity and access management, including phishing-resistant multifactor authentication, is identified as a critical area for improvement.
Nov 5, 2024·Cybersecurity Dive
A recent study by IANS and Artico Search highlights a troubling trend among Chief Information Security Officers (CISOs), who, despite earning salaries between $400,000 and $1 million annually, report low job satisfaction, with 75% contemplating a career change in 2023. The research indicates that, while CISOs hold C-suite titles, they often lack meaningful support from organizational leadership, which may result in them being blamed for cybersecurity failures. As accountability pressures increase, this disconnect contributes to burnout and diminished motivation, potentially undermining corporate security effectiveness and stability. The report underscores the necessity for better engagement between CISOs and executive teams to foster a more robust security culture.
Nov 4, 2024·Cyberscoop
The FBI has issued a warning about two fake videos falsely attributed to the agency, one of which claims to have arrested groups linked to the Democratic Party for alleged ballot fraud. The bureau confirmed that these videos are not authentic and provide misleading information concerning election security. The first video misrepresents quotes from journalist Eliot Higgins, who denied any connection to the claims and labeled the content as Russian disinformation. The second video reportedly discusses Doug Emhoff, husband of Vice President Kamala Harris, and suggests the FBI would ignore alleged connections he has with a significant government issue, although it has not been reviewed for authenticity.
Nov 4, 2024·LinkedIn
The mantra, "people, process, and technology" has long been a guiding principle in business and technology. However, cybersecurity expert Dennis Leber believes it's time to rethink that, he wrote in a recent piece. Not only did he suggest changing the wording, but also adding cybersecurity into the organizational process, which can help companies ensure a proactive approach to risk management. Finally, technology should be leveraged to support these people-driven processes, with tools that facilitate communication, efficiency, and security. By adopting this revised hierarchy of prioritization, organizations can create an environment that not only fosters employee engagement but also strengthens overall governance and resilience against cyber threats.
Nov 4, 2024·Federal News Network
The Department of Health and Human Services (HHS) is enhancing its cybersecurity measures to address the growing threat of cyber attacks on healthcare organizations, evidenced by a 128% rise in ransomware incidents in 2023. HHS is implementing a four-pronged strategy to strengthen cyber incident response, which includes setting voluntary performance goals, providing resources to promote these standards, and creating a centralized cybersecurity support hub. Deputy director Brian Mazanec noted that progress has already been made with the publication of healthcare-specific cybersecurity goals and emphasized the agency's commitment to improving collaboration with government and private sector partners.