Search site
Find podcasts, news, articles, webinars, and contributors in one search.
Health IT News
Browse by topic
Most-read stories in the last 7 days
1,000 stories
Nov 4, 2024·Healthcare IT News
The recent HIMSS Healthcare Cybersecurity Forum brought attention to the urgent cyber threats facing healthcare, particularly from advanced groups like Scattered Spider, and highlighted a concerning gap between increasing cybersecurity budgets and the preparation of many organizations. Despite spending more, many healthcare systems suffer from inadequate defenses, with some lacking essential measures such as multifactor authentication. Greg Garcia, Executive Director, Health Sector Coordinating Council and Erik Decker, CISO at Intermoutain, emphasized that cybersecurity is a collective effort across all employees, suggesting that improved collaboration and potential regulatory changes could strengthen defenses against evolving cyber threats.
Nov 3, 2024·CyberScoop
The Biden administration is approaching the final stages of a second executive order focused on cybersecurity, targeting key areas such as artificial intelligence, secure software, cloud security, identity credentialing, and post-quantum cryptography. This executive order builds on a previous one from the administration's first year and is expected to receive presidential approval in early December, despite concerns about the timeline due to the impending transition of administration. While specific details remain largely undisclosed, the order is anticipated to enhance AI capabilities in federal cybersecurity efforts, enforce security standards for software deployment among contractors, and address vulnerabilities in the software supply chain, particularly in light of recent cyber threats from foreign actors.
Nov 3, 2024·Cybersecurity Dive
UnitedHealth Group has appointed Tim McKnight as its new Chief Information Security Officer following a major ransomware attack that impacted its subsidiary, Change Healthcare, eight months ago. McKnight replaces Steven Martin, who has transitioned to the role of chief restoration officer after a cyberattack compromised the credentials of a Citrix portal, affecting over 100 million individuals. The incident revealed significant vulnerabilities in UnitedHealth's security measures, particularly the lack of multifactor authentication. While the company has not stated that the leadership change is directly linked to the attack, it indicates a possible strategic shift in addressing cybersecurity risks. McKnight brings over 30 years of cybersecurity expertise from his previous roles at SAP, Thomson Reuters, GE, and the FBI.
Nov 3, 2024·CSO Online
As the U.S. election approaches, cybersecurity emerges as a crucial issue likely to influence national security policies, with differing perspectives from Democratic Vice President Kamala Harris and Republican candidate Donald Trump. Expert analysis indicates a bipartisan agreement on the importance of cybersecurity, yet notable distinctions exist regarding the approach to nation-state threats, particularly from Russia, China, North Korea, and Iran. A Trump administration may adopt a more lenient stance toward Russian cyber activities, potentially minimizing accountability measures, whereas a Harris administration is expected to pursue a robust response. Additionally, recent Supreme Court rulings may complicate cybersecurity regulation enforcement, with implications for the efficacy of both candidates' proposed strategies.
Oct 30, 2024·Cyberscoop
Cybersecurity threats are increasingly jeopardizing healthcare in the U.S., as shown by recent attacks on major organizations like Ascension Via Christi St. Joseph and Change Healthcare, which led to disruptions in patient care and significant financial losses. With one in three Americans affected by data breaches in the past year and a sharp rise in hospital cyberattacks, there is an urgent need for a comprehensive strategy to improve cybersecurity in healthcare. Key recommendations include holding IT vendors accountable for their security measures, enhancing collaboration between Congress and the Cybersecurity and Infrastructure Security Agency (CISA) to identify and mitigate vulnerabilities, and improving access to cybersecurity resources, as many providers currently lack adequate contingency plans due to cost barriers.
Oct 30, 2024·SecurityWeek
Apple has released updates to address over 70 vulnerabilities across its products, including iOS and macOS, aimed at enhancing device security and protecting user data. Several critical vulnerabilities could allow unauthorized access or code execution, prompting Apple to recommend that users update their devices promptly. In addition to security enhancements, the updates include performance and stability improvements. Apple emphasizes the importance of regular software maintenance and encourages users to enable automatic updates to stay protected against evolving cyber threats.
Oct 29, 2024·SecurityWeek
As the landscape of cyber threats continues to evolve alongside advancements in AI, organizations need to balance the benefits of AI in improving security measures with the emerging risks associated with its misuse, according to a Security Week article which the most common models and how they can be integrated to enhance detection and response capabilities. This requires a comprehensive strategy that emphasizes vigilance, training, and collaboration in order to safeguard against the sophistication of AI-enabled cyberattacks.
Oct 28, 2024·Ars Technica
Location tracking on smartphones raises significant privacy and security concerns, with users having the ability to manage app permissions on both Android and iOS devices. Users can choose to grant apps access to either precise or approximate location data, or deny access entirely. While essential functionality can require precise location data in apps like navigation, many others do not need such detailed access. Android users can limit intrusive tracking by adjusting settings to delete their advertising ID, while iOS users can manage permissions easily by disabling tracking requests. The article highlights the importance of users evaluating which apps genuinely require location access to protect their privacy.
Oct 28, 2024·Healthcare IT News
The healthcare sector is increasingly targeted by organized cyberattacks, prompting chief information security officers (CISOs) to adapt their strategies to ensure continuous patient care. The rise of ransomware has shifted the CISO's role from simply focusing on data security to an adversarial stance that involves negotiating with attackers. Erik Decker and Darren Lacey, CISOs at Intermountain Health and Johns Hopkins University, respectively, underscore the pressing challenges posed by cyber incidents and the need for improved cybersecurity measures. Their insights will be shared at the HIMSS 2024 Healthcare Cybersecurity Forum, where they will discuss the need for evolving responses to cyber threats without compromising operational integrity and patient safety.
Oct 27, 2024·Apple News
Delta Air Lines has initiated a lawsuit against cybersecurity firm CrowdStrike, claiming that the latter's inadequate system management led to a significant operational crisis in July, resulting in extensive flight delays and cancellations. Delta alleges that the software designed to safeguard its systems failed, causing substantial financial losses and reputational harm. The airline contends that it relied on CrowdStrike's expertise for security, and is seeking compensation for the disruptions. The case raises important considerations about the responsibilities of cybersecurity firms, particularly in critical sectors like aviation, as the industry grapples with evolving cyber threats.
Oct 27, 2024·LinkedIn
The Chief Information Security Officer (CISO) is essential for protecting an organization's digital assets and ensuring a strong cybersecurity framework. As cyber threats evolve, the CISO must establish an execution framework and governance model that align with the organization's strategic goals, enabling the prioritization of cybersecurity initiatives and the management of systemic digital risks. This alignment integrates security measures into business operations, promotes a culture of awareness, and enhances overall resilience. Additionally, the CISO's governance model should focus on risk assessment and incident response to proactively mitigate vulnerabilities. However, challenges such as gaining stakeholder support and adapting to dynamic threats complicate this process.
Oct 27, 2024·Fast Company
Change Healthcare suffered a large ransomware attack by the ALPHV/BlackCat group, resulting in the compromise of personal health information for approximately 100 million individuals. This breach, confirmed by the U.S. Department of Health and Human Services, included sensitive data such as names, addresses, and health records, underscoring the need for enhanced security measures in digital health environments. Following the attack, Change Healthcare initiated a complex notification process for affected individuals, revealing the breach's scale, which impacted nearly one-third of the U.S. population. The Office for Civil Rights is investigating the company's adherence to HIPAA regulations, while any potential financial penalties for UnitedHealth Group may be minimal, despite significant lapses in security disclosed during recent congressional hearings.
Oct 24, 2024·Dark Reading
Nearly half of organizations are vulnerable to data breaches due to the presence of long-lived credentials in their cloud services. These authentication tokens or keys can remain valid for extended periods, increasing the risk of exploitation by attackers. A 2024 report by Datadog highlights that a significant portion of accounts across major cloud platforms like Google Cloud, AWS, and Microsoft Entra have access keys older than one year. With many credentials often unused and at risk of being leaked through source code, the report emphasizes the need for organizations to eliminate long-lived credentials and adopt modern authentication methods that use short-lived credentials to enhance security.
Oct 24, 2024·security-blog
Healthcare organizations have increasingly become targets for ransomware attacks, as detailed in Microsoft's "US healthcare at risk: strengthening resiliency against ransomware attacks" report. The report highlights that ransomware is now one of the leading threats to the healthcare sector, which has seen significant financial repercussions, with organizations losing an average of $900,000 per day to downtime and ransoms averaging $4.4 million. The report emphasizes the critical need for healthcare entities to implement collective defense strategies and enhance access to threat intelligence to protect against these evolving cyber threats, which not only jeopardize financial stability but also pose serious risks to patient care and safety, particularly in resource-limited rural clinics.
Oct 24, 2024·TechRadar
A data breach affecting over five million individuals has been attributed to a misconfigured online database associated with eCaresoft, a software provider for hospital information systems in Mexico. Researchers from Cybernews identified a vulnerable Kibana instance, which exposed personal information such as names, ethnicity, CURP numbers, and other sensitive data but did not include health records or payment details. The incident raises concerns about potential identity theft and highlights broader issues of inadequate database security practices that contribute to data leaks.
Oct 24, 2024·Ars Technica
Location tracking on smartphones is increasingly common, prompting users to take steps to protect their privacy. Both Android and iOS systems offer users the ability to manage app permissions for location access, allowing them to choose between precise, approximate, or no access. While some apps require detailed location data, many do not, underscoring the importance of reviewing app permissions. Android users can limit tracking by deleting their advertising ID through specific settings, while iOS users benefit from more restrictive default settings that prevent unauthorized access to a unique tracking identifier. Users are advised to regularly check and adjust their privacy settings accordingly.
Oct 24, 2024·The Hacker News
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has classified a high-severity vulnerability in Microsoft SharePoint, identified as CVE-2024-38094, as part of its Known Exploited Vulnerabilities catalog following indications of active exploitation. This deserialization vulnerability, which carries a CVSS score of 7.2, permits authenticated attackers with Site Owner permissions to inject arbitrary code into SharePoint Server. Microsoft has addressed this issue in its July 2024 Patch Tuesday updates. The concern is amplified by the existence of proof-of-concept exploits in the public domain, despite no confirmed real-world incidents. CISA requires Federal Civilian Executive Branch agencies to implement the security updates by November 12, 2024.
Oct 23, 2024·Vanderbilt University Medical Center
Vanderbilt University Medical Center (VUMC) employees are encountering a rise in "vhishing," a sophisticated scam that uses AI-generated voice messages to mimic trusted individuals and deceive victims into revealing sensitive information or making financial transactions. This form of voice phishing employs advanced AI techniques, including deep learning algorithms, to create highly convincing impersonations, making it difficult for targets to discern the fraud. The consequences of falling for such scams can be severe, leading to significant financial loss and identity theft. To address these threats, VUMC is working on strategies to educate employees about the risks associated with AI voice scams.
Oct 23, 2024·Health IT Answers
David Finn, Executive Vice President of Governance, Risk, and Compliance at First Health Advisory, underscores the critical need for healthcare organizations to effectively manage cybersecurity risks, particularly as ransomware attacks rise. He emphasizes that assessing risks should involve input from multiple stakeholders, not just IT teams, to gain a comprehensive understanding of how cybersecurity impacts patient care and operations. Finn advocates for a robust incident response plan, regular security training for all staff, and basic cyber hygiene practices, while also promoting collaboration with public and private sectors to enhance threat intelligence sharing.