Search site
Find podcasts, news, articles, webinars, and contributors in one search.
Health IT News
Browse by topic
Most-read stories in the last 7 days
1,000 stories
Oct 14, 2024·Barron's
The Internet Archive has experienced a significant cyberattack attributed to a pro-Palestinian hacker group named "SN_BLACKMETA," resulting in the defacement of the website and the compromise of user data, including usernames, emails, and passwords for approximately 31 million accounts. Brewster Kahle, the organization's founder, confirmed that the Internet Archive has been under a series of distributed denial-of-service (DDoS) attacks since Tuesday and is actively working to restore services while ensuring that the core data remains intact. The hackers' motivations are politically charged, criticizing U.S. support for certain geopolitical actions.
Oct 13, 2024·CyberScoop
OpenAI's recent quarterly threat report reveals that the company has disrupted over 20 foreign influence networks in the past year, aimed at manipulating political sentiments worldwide, including in the U.S. These networks have attempted to misuse OpenAI's generative AI technologies, such as ChatGPT, to create misleading content and execute cyberattacks. Notably, actors linked to Iran and China have utilized these tools for mass content generation and phishing attacks, while a group tied to the Islamic Revolutionary Guard Corps (IRGC) has also been implicated. Despite these threats, OpenAI officials indicate that these malicious efforts have not significantly advanced malware development or audience manipulation techniques.
Oct 13, 2024·National Law Review
Effective October 2, 2024, New York will enforce new cybersecurity requirements for licensed general hospitals to enhance their protection against cyber threats. Hospitals are mandated to establish comprehensive cybersecurity programs, including risk assessments and incident response plans, and to appoint a chief information security officer to oversee compliance. Immediate reporting of any cybersecurity incidents to the New York State Department of Health is also required. While these regulations apply only to general hospitals, they aim to supplement existing federal HIPAA Security Rule requirements, with potential extensions to other healthcare facilities considered in the future.
Oct 13, 2024·Cybersecurity Dive
A recent PwC report highlights a significant disconnect between security executives and C-suite leaders regarding corporate cyber resilience strategies. While over two-thirds of technology leaders identify cybersecurity as a top risk, only 48% of business leaders share this view. The findings show that less than half of executives see their Chief Information Security Officers (CISOs) involved in strategic planning and board discussions, indicating communication challenges regarding operational vulnerabilities. Additionally, discrepancies in perceptions of regulatory compliance underscore a misalignment in priorities, with tech leaders focusing on cloud security and data protection, whereas business leaders are more concerned with modernization.
Oct 10, 2024·Dark Reading
Chief Information Security Officers (CISOs) are seeing a slight rise in compensation, with average annual salaries now reaching $403,000, an increase of 6.4% over the last year. However, this pay growth does not align with the expanding responsibilities CISOs face, especially due to new SEC regulations that mandate timely breach assessments. Many feel under-resourced, which complicates their ability to manage threats effectively while navigating budget constraints. Demand for CISOs surged during the pandemic, but interest in job changes has significantly decreased, with only 11% contemplating a move in 2024 due to economic pressures. State government CISOs encounter additional challenges like limited budgets and a high turnover rate, with almost half of states hiring new CISOs recently.
The healthcare sector is grappling with a worsening cybersecurity crisis marked by a rise in ransomware attacks, with 66% of organizations affected in the last year, according to Sophos. The implications of these attacks include service disruptions, financial costs, and threats to patient data security, which can ultimately impact patient care. In response, Senators Ron Wyden and Mark Warner have introduced legislation intended to strengthen accountability and resources for healthcare cybersecurity, particularly targeting rural and underserved hospitals. This vulnerability is further amplified by outdated technologies, dependence on third-party services, and a historical tendency of organizations to pay ransoms to restore operations.
Oct 10, 2024·Krebs on Security
A 19-year-old honors student from Connecticut has been linked to a $243 million cryptocurrency theft, which led to a violent carjacking of his parents a week later. During the attack on August 25, 2024, the couple was rear-ended while driving a Lamborghini and subsequently assaulted by six suspects from Florida who believed they could extort cryptocurrency from them. The assailants, who were arrested shortly after the incident, reportedly targeted the couple under the impression that their son had access to significant digital assets. The theft, executed on August 19, involved advanced social engineering tactics, leading to severe financial and personal repercussions for the family.
Oct 9, 2024·The Hacker News
Microsoft has raised concerns about the growing use of legitimate file hosting services like SharePoint, OneDrive, and Dropbox in cyber attack strategies, particularly in business email compromise (BEC) schemes. This technique, referred to as living-off-trusted-sites (LOTS), enables threat actors to mask malicious activities within trusted network traffic, complicating efforts to detect and trace these attacks. Recent observations indicate an uptick in phishing campaigns leveraging restricted access files shared through these platforms, often initiated by compromising trusted vendor users. Targeted individuals receive phishing emails with links requiring one-time password authentication, leading them to pages aimed at stealing credentials and two-factor authentication tokens.
Oct 9, 2024·CSO Online
CISOs are recognizing the need for effective risk storytelling to engage stakeholders and drive action in cybersecurity. Given the complexity of cybersecurity risks, traditional technical presentations are inadequate; instead, CISOs must frame risks in business-related terms, such as brand or regulatory implications. By incorporating relevant news stories and quantifying potential financial impacts, they can craft compelling narratives that highlight the necessity of robust security programs. However, challenges like inconsistent data on cyber threats complicate risk assessment, underscoring the need for a standardized risk management process. Building credibility with executives involves focusing on material risks that connect to business objectives rather than technical jargon.
Oct 9, 2024·HealthLeaders
The Change Healthcare ransomware attack earlier this year disrupted operations at Moffitt Cancer Center by rendering critical systems inoperable, affecting claims processing and patient payments. Vice President Lynn Ansley highlighted the urgent need for accurate information to assess the situation and emphasized maintaining payroll for their staff of 9,500 while seeking alternative cash flow solutions. During the three-week outage, the team adapted by using an alternate clearinghouse and relied on manual data entry for claims, necessitating a re-familiarization with outdated systems.
Oct 8, 2024·The Record
The U.S. Department of Health and Human Services has alerted the healthcare industry about Trinity ransomware, a new strain detected in May 2024 that has already affected multiple victims, including healthcare providers in the U.S. and the U.K. Trinity ransomware encrypts files with a “trinitylock” extension and poses significant data theft risks, as illustrated by one gastroenterology provider's loss of 330 GB of data. The ransomware exploits system vulnerabilities and spreads laterally within networks, with victims facing an urgent demand for payment in cryptocurrency to prevent data leaks. Experts have noted similarities between Trinity and previous ransomware strains, indicating possible links among the attackers.
Oct 8, 2024·Cyberscoop
UnitedHealth Group's recovery from a significant ransomware attack on its Change Healthcare subsidiary is ongoing, requiring a complete overhaul of its computer systems, according to Chief Information Security Officer Steven Martin. Speaking at the Mandiant Worldwide Information Security Exchange, Martin revealed that only the cables were retained from the previous infrastructure, as the company replaced all routers, switches, and computing systems to enhance security. The attack, linked to the ALPHV group and occurring in February, resulted in profound disruptions for healthcare providers and ransom payments estimated at $22 million. After months of intensive effort and collaboration with Mandiant's incident response team, the restoration process is nearing completion, with Martin describing the recovery as a long-term commitment akin to running a marathon.
Oct 7, 2024·Apple News
A teenage hacker gained fame in the underground hacking community for his high-profile attacks on various organizations, showcasing his technical skills. However, his notoriety attracted unwanted attention from rival hackers, leading to increased scrutiny and hostility against him. This shift in dynamics underlines the precarious nature of the hacker world, where former allies can quickly turn into adversaries. His experience serves as a cautionary tale about the risks of fame in this competitive environment, illustrating the balance between opportunity and threat in the digital underworld.
Oct 7, 2024·TechRadar
C-suite executives are increasingly seen as a key vulnerability in organizational cybersecurity due to their access to sensitive data and frequent use of personal devices for work purposes. A GetApp survey indicated that 72% of U.S. senior executives experienced cyberattacks in the past 18 months, with notable increases in various types of fraud, including a 29% rise in scams and piracy and a 26% rise in impersonation scams. The use of deepfake technology in 27% of these incidents has further exacerbated risks, leading to significant financial losses. Cybersecurity experts advocate for enhanced training and awareness for top executives, highlighting the need for proactive measures to safeguard organizational leadership against these targeted threats.
Oct 7, 2024·AP News
IronNet, a software company that was valued at more than $3 billion in 2021, made headlines when it announced it was shutting down last September. Founded by a former director of the National Security Agency and stacked with elite members of the U.S. intelligence establishment, InfoNet burned out quickly, failing to meet its promise to revolutionize the way organizations combat cyberattacks, and facing scrutiny over its leadership decisions and operational integrity. Allegations of inflated projections and a lack of transparency plagued the firm, leading to a loss of confidence among investors and partners. IronNet’s struggle to establish itself in the competitive cybersecurity landscape and its inability to land key contracts, despite the backing of prominent figures, ultimately culminated in its financial collapse and subsequent shutdown.
Oct 7, 2024·Federal News Network
The Department of Health and Human Services has established the Administration for Strategic Preparedness and Response (ASPR) to coordinate cybersecurity efforts in the healthcare sector. With the increasing incidence of cyberattacks, including ransomware, ASPR has formed a dedicated cybersecurity division to enhance incident response in collaboration with agencies like the FBI. The division aims to address the operational disruptions caused by cyber incidents while supporting recovery efforts through initiatives such as the Medical Reserve Corps. ASPR is also working to incorporate cybersecurity into funding opportunities through the Hospital Preparedness Program and is conducting a sector risk assessment to tackle third-party risks from major providers.
Oct 7, 2024·The Record
A senior White House official has urged insurance companies to stop offering policies that incentivize ransomware payments, citing their harmful effect on global cybersecurity. Anne Neuberger, U.S. deputy national security adviser for cyber and emerging technologies, made the comments after the International Counter Ransomware Initiative summit, emphasizing that such insurance practices undermine efforts to combat cybercrime. While discussions have occurred with the insurance industry, no formal agreements have been established. Neuberger recommended that insurers require businesses to implement strong cybersecurity measures as a condition of coverage. The UK's National Cyber Security Centre has previously collaborated with its insurance sector, producing guidance against extortion payments that has gained support from international industry bodies.
A ransomware attack on University Medical Center Health System in Lubbock, Texas, has prompted the diversion of ambulances and a temporary halt to patient admissions due to significant IT outages. As the only level 1 trauma center within a 400-mile radius, UMC's closure of emergency services raises concerns about access to critical care. While some clinics remain operational under limited capabilities, patients face delays and are advised to bring physical copies of their medical records due to staff's inability to access electronic files. The attack has also disrupted radiology services and communication systems, and the hospital is working with experts to restore functionality while keeping affected patients informed. This incident follows a prior data breach earlier this year.
Oct 3, 2024·LinkedIn
Dennis E. Leber, Ph.D., addresses the challenges posed by human behavior in cybersecurity, emphasizing that individuals often lack the mindset required for recognizing and mitigating threats. Many employees operate under the optimism bias, underestimating the risk of cyberattacks and viewing their data as not valuable, which leads to negligence in adhering to security protocols. Leber recommends that organizations view cybersecurity as a fundamental business priority rather than a technical concern, advocating for its integration across all levels of the company to strengthen security measures and enhance overall business objectives, as illustrated by DDN's proactive approach under Bob Zukis.
Oct 3, 2024·Healthcare IT News
Cybersecurity has become a critical concern in the healthcare sector, where frontline workers are essential to protecting against cyberattacks. Despite many organizations believing they have strong security measures, they often lack preparedness for evolving threats, particularly as artificial intelligence advances. Dr. Eric Liederman, CEO of CyberSolutionsMD, underscores the need for effective, role-specific training rather than a one-size-fits-all approach, while Anahi Santiago, CISO at ChristianaCare, emphasizes the importance of understanding the audience and fostering a culture that encourages reporting security issues. By addressing the unique needs of various staff members, healthcare organizations can improve their overall cybersecurity posture.