Search site
Find podcasts, news, articles, webinars, and contributors in one search.
Health IT News
Browse by topic
Most-read stories in the last 7 days
1,000 stories
Oct 22, 2024·Apple News
A recent cybersecurity warning highlights the increasing threat from around 1,000 elite hackers using artificial intelligence (AI) to enhance their attack methods. These hackers are employing advanced AI tools to automate and refine their cyberattacks, complicating defense strategies for organizations. Experts are concerned that AI enhances the sophistication of phishing tactics, vulnerability scanning, and malware adaptation, necessitating a reevaluation of security protocols. Cybersecurity firms and government agencies recommend that organizations implement AI-driven security solutions and prioritize employee training to improve threat detection and response capabilities.
Oct 22, 2024·SecurityWeek
Cisco has confirmed a security breach following a hacker's attempt to sell stolen data from the company. The incident was discovered when the hacker publicly advertised the compromised information, prompting Cisco's security team to investigate the situation and assess the potential exposure of sensitive data. In response, Cisco reaffirmed its commitment to security, emphasizing its efforts to understand the breach, implement preventive measures, and safeguard customer information. The incident has raised concerns within the cybersecurity community about the persistent threats posed by cybercriminals, underscoring the necessity for strong cybersecurity practices. Updates on the investigation are anticipated as Cisco works to address the issue.
Oct 22, 2024·LinkedIn
Dee Young, Chief Information Security Officer at UNC Health Care, highlights the significant devastation caused by Hurricane Helene in Western North Carolina, affecting over 500 miles and leaving communities in recovery mode. She stresses the importance of continued support and awareness, even as media coverage diminishes, and commends the resilience of local residents actively aiding one another. Young recommends a 60-minute report that provides further insights into the storm's effects and shares resources for individual contributions to recovery efforts, including those from the Red Cross. Her message calls for collective action and engagement to assist in the long-term rebuilding process.
Oct 21, 2024·Healthcare Finance News
UnitedHealth Group's third-quarter earnings report indicates a notable financial impact from the February ransomware attack on Change Healthcare, with $0.3 billion affecting earnings from operations of $8.7 billion. Adjusted earnings amounted to $9 billion, despite disruptions related to the cybersecurity incident. Following the report, the company's stock fell over 9%, reflecting investor apprehension about ongoing challenges. UnitedHealth Group maintained its adjusted net earnings outlook for the year, while the medical cost ratio increased from 82.3% to 85.2%, attributed to various factors including hospital coding practices and Medicaid rate adjustments, as noted by CFO John Rex.
Oct 21, 2024·CNBC
U.S. officials express heightened concern over rising ransomware attacks, predicting 2024 may be particularly severe. Ann Neuberger, deputy national security adviser, has pointed out that cyber insurance policies that cover ransom payments contribute to the issue, advocating for stricter cybersecurity prerequisites to reduce such reimbursements. Businesses grapple with the challenging decision of whether to pay ransoms, influenced by the urgency to resume operations and potential legal consequences, as seen in the Lehigh Valley Health Network case, where refusal to pay led to a significant data breach affecting over 134,000 patients.
Oct 20, 2024·BleepingComputer
The BianLian ransomware group has targeted Boston Children's Health Physicians (BCHP) in a cyberattack, threatening to release stolen data unless a ransom is paid. The breach, which began with an attack on BCHP's IT vendor on September 6, 2024, led to unauthorized access to sensitive information of patients and employees. An investigation confirmed that while substantial data, including personal and medical details, has been compromised, BCHP's electronic medical records were secure. Affected individuals will be notified by October 25, 2024, particularly those with exposed Social Security numbers and driver's licenses.
Oct 20, 2024·CSO
Main Line Health (MLH) has launched a comprehensive cybersecurity initiative to bolster its defenses against evolving threats in the healthcare sector. Led by CISO Aaron Weismann, the initiative emphasizes the integration of personnel, processes, and technology to combat various cyber threats such as social engineering and malware. MLH has partnered with vendors to enhance its IT infrastructure and adopted the HITRUST Framework for risk management, while also investing in employee training to improve awareness of cybersecurity risks. A notable aspect of the program is the implementation of chaos engineering, which tests system resilience by intentionally introducing vulnerabilities.
Oct 20, 2024·LinkedIn
October marks Security Awareness Month, emphasizing the need for organizations to improve their security practices. Jigar Shah, Global Head of IT, Identity, Access and Application for Tenet Health, highlights that human factors are involved in over 80% of data breaches, yet over 90% of employees still engage in risky behaviors post-training, questioning the effectiveness of traditional security programs. He argues that these programs often fail because they don't address human psychology or promote genuine behavioral change, instead focusing on compliance. Shah advocates for a new approach that incorporates elements like gaming into training to foster employee engagement and accountability while emphasizing a culture of security. He also calls for better measurement of program effectiveness to link employee behavior with business outcomes.
Oct 20, 2024·Wall Street Journal
A recent rise in AI-driven scams targeting Gmail users has prompted security experts to issue warnings about sophisticated phishing attempts, affecting the platform's 2.5 billion users. Hackers are employing tactics such as impersonating Google support in phone calls and using fake Google Forms to create a veneer of legitimacy. Victims have reported manipulative calls that instill fear, convincing them to divulge sensitive information. In light of this escalating threat, Google has joined the Global Anti-Scam Alliance and launched the Global Signal Exchange to enhance intelligence sharing on scams and fraud prevention.
Oct 20, 2024·Cybersecurity Dive
The large majority of CISOs believe the role is becoming untenable, according to a report from Trellix and Vanson Bourne, which found that more than 4 in 5 believe it should be split into two separate positions, The findings suggest a pressing need for organizations to rethink their security leadership structure in light of rising regulatory demands and the complexity of cybersecurity threats. The differentiation of roles could provide a clearer focus on technical security measures and regulatory compliance, ultimately benefiting both corporate governance and cybersecurity practices.
Oct 17, 2024·Cyber Magazine
Healthcare organizations are increasingly vulnerable to cyber threats, with a recent report indicating that 92% of U.S. healthcare entities faced cyberattacks in the past year, primarily through damaging supply chain intrusions. These attacks frequently disrupt essential services and supplies, impacting patient care directly; 82% of affected organizations reported significant interruptions, and 28% noted an increase in patient fatalities linked to such breaches. The findings underscore the need for healthcare entities to enhance their cybersecurity measures, particularly concerning third-party vendor management, to mitigate the risks associated with these supply chain vulnerabilities.
Oct 17, 2024·HCInnovation Group
A recent report by Proofpoint, Inc. and the Ponemon Institute shows a significant increase in patient care disruptions due to cyberattacks in healthcare, with a 77 percent rise compared to last year. The survey notes that 92 percent of health systems experienced at least one cyberattack, impacting patient outcomes negatively; specifically, 56 percent reported delays affecting care, and 28 percent indicated rising mortality rates. Notably, supply chain attacks were found to be particularly harmful. Despite some increase in IT budgets, challenges in cybersecurity effectiveness persist, according to Larry Ponemon, chairman of the Ponemon Institute.
Oct 16, 2024·The Verge
The Internet Archive has resumed limited operations in a read-only format after a cyberattack on October 9 that led to a data breach and a DDoS attack, resulting in the theft of a user authentication database for 31 million accounts. While users can currently access 916 billion archived web pages through the Wayback Machine, the ability to archive new pages is temporarily suspended. The organization is focused on restoring services and enhancing security measures while acknowledging that ongoing maintenance could cause further disruptions. A hacker group claimed responsibility for the breach, which was confirmed by the data breach notification service Have I Been Pwned, detailing the stolen sensitive information.
Oct 16, 2024·PCMag
National Public Data, a Florida-based company, has filed for Chapter 11 bankruptcy after a massive data breach exposed 272 million Social Security numbers and 600 million phone numbers, prompting numerous lawsuits and investigations from over 20 states and the Federal Trade Commission. The breach's financial fallout has severely impacted the company, which reported only $865,149 in profit last year against $1.2 million in revenue. The bankruptcy is intended to facilitate reorganization as the company faces significant legal challenges, and a Florida court has temporarily paused the first class-action lawsuit against its parent company, Jerico Pictures.
Oct 16, 2024·TechRadar
Gryphon Healthcare has reported a data breach affecting nearly 400,000 patients, resulting from a supply-chain cyberattack on a partner company. The breach allowed unauthorized access to sensitive personal and health information, including Social Security numbers and medical records. Although the specific partner involved has not been disclosed, Gryphon indicated that no evidence currently suggests the data has been misused. This incident highlights the growing trend of cybercriminals targeting healthcare organizations, which face significant risks including financial loss and reputational damage.
Oct 16, 2024·CyberScoop
A recent Censys report has identified more than 14,000 internet-connected medical devices and healthcare databases that are exposed to vulnerabilities, with nearly 50% located in the U.S. The decentralized nature of the U.S. healthcare system is a significant contributor to this issue, in contrast to the UK's centralized system, which has about 200 such devices. The healthcare sector has increasingly become a target for cyberattacks, prompting the Biden administration to prioritize cybersecurity measures, particularly regarding ransomware threats. Efforts include advocating for stricter cybersecurity mandates for medical device manufacturers to enforce secure design principles; however, many healthcare organizations, especially smaller ones, remain ill-prepared to handle these evolving cyber threats.
Oct 15, 2024·LinkedIn
The concept of “default aggression” in cybersecurity advocates for a proactive and decisive approach to address evolving threats, akin to the tactics used by Navy SEALs. Recent training experiences, such as those at AZ Tactical Adventures, showcased the importance of teamwork, clear communication, and continuous improvement in executing defense strategies effectively. The insights gained highlight that understanding individual roles, respecting team contributions, and fostering open dialogue are crucial for enhancing organizational effectiveness. By embracing this mindset, writes Dennis Leber, CISO at Honest Medical Group, individuals and organizations can better prepare for and respond to challenges in both military and civilian contexts.
Oct 15, 2024·The Record
Axis Health System, a nonprofit managing multiple healthcare facilities in Colorado, has been struck by a cyberattack that has disrupted its patient portal and prompted an investigation into the attack's nature and extent. While the timeline of the breach is unclear, Axis Health has initiated its incident response protocol and will inform affected individuals if patient data is compromised. The Rhysida ransomware gang has claimed responsibility, demanding over $1.5 million for data access, highlighting the ongoing threats to healthcare organizations. Concurrently, a report from Censys found over 14,000 healthcare devices potentially exposed to the internet, raising concerns about sensitive medical data vulnerability.
Oct 14, 2024·TechTarget
A recent Ponemon Institute report, sponsored by Proofpoint, reveals significant impacts of cyberattacks on patient care in healthcare organizations. Surveying 648 IT and security professionals, it found that over 90% experienced cyberattacks in the past year, with 69% reporting negative effects on patient care, including delays and higher mortality rates. Supply chain attacks were characterized as particularly harmful, affecting 82% of organizations surveyed, while the perceived vulnerability to ransomware has decreased slightly. Additionally, data loss incidents are common, with over 90% of organizations encountering multiple breaches of confidential data.
Oct 14, 2024·SiliconANGLE
In an interview at Fal.Con 2024, CrowdStrike CEO George Kurtz discussed the significant role of artificial intelligence (AI) in transforming cybersecurity, moving beyond malware detection to predictive measures for complex threats in cloud and network systems. He stressed the necessity of collaboration among major industry players, such as Microsoft, Nvidia, and Amazon Web Services, to effectively tackle security challenges and build trust with clients. Kurtz pointed to recent incidents as opportunities for these partnerships to enhance overall security. He also highlighted how CrowdStrike's early adoption of AI technologies, particularly in generative AI, has improved detection and response times while utilizing cloud technology for better data collection and resource efficiency.