Search site
Find podcasts, news, articles, webinars, and contributors in one search.
Health IT News
Browse by topic
Most-read stories in the last 7 days
1,000 stories
Oct 3, 2024·Harvard Business Review
Cybersecurity experts advocate for a shift from a prevention-focused approach to one centered on resilience in response to the inevitability of cyberattacks. Rather than solely trying to keep threats out, organizations are encouraged to prepare for potential breaches by investing in effective incident response and recovery strategies. Key practices adopted by resilient companies include fostering a cybersecurity culture, regularly practicing incident responses, and incorporating "secure by design" principles into their processes. Additionally, establishing robust communication protocols is essential for effective coordination during incidents, which helps mitigate attack impacts and maintain stakeholder trust. The article underscores the challenge faced by defenders, who must secure all potential vulnerabilities while attackers only need to exploit one.
Oct 2, 2024·SecurityWeek
Recent law enforcement operations have successfully disrupted the LockBit ransomware group, resulting in several arrests and the seizure of servers critical to their operations. Known for targeting various sectors including healthcare and finance, LockBit has executed sophisticated attacks that encrypt victims' data until a ransom is paid. The arrests signal a significant blow to the group's capabilities and follow a broader initiative aimed at combating ransomware and cybercrime through international collaboration. Authorities continue to seek additional members of the group, leveraging intelligence gained from the seized infrastructure to further dismantle their network.
UMC Health System has enacted patient diversion protocols following a ransomware attack that compromised its network, resulting in the temporary suspension of certain services and patient rerouting to other facilities. The organization is actively investigating the breach with cybersecurity experts and collaborating with law enforcement to determine the attack's source. UMC emphasizes its commitment to safeguarding patient data and minimizing care disruption during the recovery process. This incident underscores the increasing cybersecurity threats in the healthcare sector, necessitating stronger defenses to protect sensitive patient information.
Oct 1, 2024·SecurityWeek
The Community Clinic of Maui, also known as Malama I Ke Ola Health Center, has reported a data breach affecting over 120,000 individuals due to a ransomware attack by the LockBit group earlier this year. The attack disrupted operations, resulting in a two-week closure, and affected sensitive personal and medical information. Although there is no evidence of data misuse for identity theft, the clinic is providing affected individuals with complimentary credit monitoring services. The incident has been reported to the Maine Attorney General’s Office, and while it is unclear if the stolen data has been published, experts warn of potential future exploitation.
Oct 1, 2024·PYMNTS
Chief Financial Officers (CFOs) are taking on greater responsibilities in cybersecurity, recognizing that safeguarding against cyber threats and data breaches is essential for maintaining financial stability and protecting sensitive information. As organizations undergo digital transformation, CFOs must collaborate with Chief Information Officers (CIOs) and Chief Information Security Officers (CISOs) to integrate cybersecurity into the broader business strategy, emphasizing proactive risk management. With financial data becoming a prime target for cybercriminals, ensuring the security of transactions and sensitive information has become a crucial priority for CFOs to prevent significant financial losses and regulatory issues.
Oct 1, 2024·Newsweek
A recent cyberattack linked to Chinese hackers, identified as part of the "Salt Typhoon" operation attributed to the group APT41, has targeted U.S. internet service providers, highlighting escalating threats to critical infrastructure. The attackers exploited vulnerabilities to gain access to networks, potentially compromising sensitive information and disrupting services. This incident signifies a broader strategy by state-sponsored Chinese actors to bolster cyber capabilities and gather intelligence. In light of the attack, U.S. cybersecurity agencies have issued warnings and are advocating for enhanced security measures among internet service providers. The long-term implications for national security and public safety are still being assessed as investigations proceed.
Oct 1, 2024·paulconnelly.substack.com
analyzed, underscored the importance of integrating cybersecurity and physical security protocols. The collaboration between the two teams not only enhanced situational awareness but also streamlined the response to potential threats, showcasing the effectiveness of a unified security strategy in protecting critical infrastructure, particularly in sensitive environments like healthcare. The article advocates for a holistic approach to security that addresses both cyber and physical risks in a rapidly evolving technological landscape.
Oct 1, 2024·NTD
Verizon has restored service after a major network outage affected over 100,000 customers across the U.S., particularly in cities like Chicago and Seattle. The disruption began around 9:30 a.m. ET, leaving many users with non-functional phones or in "SOS" mode. The Federal Communications Commission (FCC) is investigating the issue following numerous complaints, especially from the Midwest. Verizon acknowledged the problem by noon and confirmed service normalization by 7:18 p.m. ET, recommending users restart their devices. The company has not disclosed the cause of the outage or its potential links to Hurricane Helene, which caused flooding on the East Coast.
Sep 30, 2024·BankInfoSecurity
Ransomware attacks in the healthcare sector have surged to a four-year high, as revealed in a report by Sophos, which found that two-thirds of surveyed healthcare organizations experienced an attack in the past year, up from 60% in 2023. In contrast, ransomware incidents in other sectors have decreased. The report also noted that recovery times are increasing, with 37% of healthcare organizations taking over a month to recover from such attacks. The complexity and severity of these attacks are rising, with 74% resulting in data encryption, and 66% reporting compromised backups, highlighting a growing vulnerability in the healthcare sector.
Sep 30, 2024·Finance Committee
Senators Ron Wyden (D-Ore.) and Mark Warner (D-Va.) have proposed a bill to enhance cybersecurity standards in the American healthcare system, responding to the rise in cyberattacks targeting healthcare organizations. The legislation mandates that healthcare entities implement best practices, conduct routine risk assessments, and report breaches promptly, while also promoting collaboration between federal agencies and healthcare providers to strengthen overall security. By establishing clear guidelines, the bill aims to protect patient data and ensure continuous healthcare services amidst a complex cyber threat landscape.
Sep 30, 2024·The Guardian
An investigation is currently underway regarding the unauthorized access of medical records for vice-presidential nominees Tim Walz and J.D. Vance by several employees at the U.S. Department of Veterans Affairs. The inquiry involves at least a dozen individuals, including a doctor and a contractor, who are suspected of improperly viewing these records, raising concerns about the motivations behind such actions, particularly as both nominees are military veterans. Evidence from the VA inspector's office has been submitted to federal prosecutors, and VA Secretary Denis McDonough has reiterated the importance of adhering to strict privacy regulations regarding veterans' medical information.
Sep 30, 2024·This Week Health
A recent panel discussion with several CISOs served as a critical reminder for healthcare leaders about the necessity of an active role in cybersecurity. It underscores the growing significance of CISOs amid escalating cyber threats and stresses the importance of integrating cybersecurity into organizational strategy. Leaders are encouraged to build a culture of security awareness, develop key skills such as communication and strategic thinking, and support their teams in addressing cybersecurity challenges. The dialogue reinforces that effective cybersecurity leadership combines technical knowledge with strong management and interpersonal skills.
Sep 29, 2024·Fox 2 Detroit
Michigan Medicine has reported a significant data breach affecting approximately 57,000 individuals due to unauthorized access to a third-party vendor's system. Discovered in early September 2023, the breach involved sensitive patient information such as names, birth dates, and medical record numbers, though there is currently no evidence of data misuse. This marks the second breach within a few months, following a July incident that impacted around 3,000 patients, prompting the organization to review its data security measures. Affected individuals are being offered complimentary credit monitoring services, and Michigan Medicine has established a hotline for inquiries while emphasizing its commitment to improving data protection efforts.
Sep 29, 2024·Ars Technica
The National Institute of Standards and Technology (NIST) has proposed changes to password guidelines to simplify password creation and improve security. The new recommendations suggest moving away from complex password requirements and frequent changes, which can lead to poor management practices. Instead, NIST encourages using longer, memorable phrases and changing passwords only when there is evidence of a breach. Additionally, NIST advocates for the use of password managers to help generate and securely store unique passwords, thereby promoting better password hygiene and overall cybersecurity.
Sep 29, 2024·San Diego Union-Tribune
Palomar Medical Group has decided to discontinue its partnership with Graybill Medical Group following a cyber attack that compromised patient data and raised serious security concerns. The ransomware incident, which disrupted Graybill's operations in September, has prompted Palomar to prioritize patient trust and data security. While Graybill works on restoring its systems and improving cybersecurity, Palomar is actively seeking new partnerships to ensure continuity of care for affected patients. This situation highlights the increasing risks posed by cyber attacks within the healthcare sector.
Sep 26, 2024·BankInfoSecurity
CrowdStrike faced a significant global outage that disrupted its services, raising concerns about the reliability of its cybersecurity solutions amidst increasing demand. The incident affected various offerings, including the Falcon platform, leading to client frustrations during a period of heightened cyber threats. In response, CrowdStrike's leadership acknowledged the impact on clients and committed to restoring services and investigating the root causes to prevent future occurrences. This event underscores the vulnerabilities inherent in established cybersecurity firms as organizations increasingly rely on such services for protection.
Sep 26, 2024·eCommunity
Community Health Network has partnered with identity verification company Clear to enhance security and improve patient experiences by streamlining the check-in process using biometric data. This collaboration aims to reduce wait times and minimize the need for physical documentation by employing facial recognition and fingerprint scanning for identity verification, thereby protecting patient information and enhancing safety. Additionally, the initiative reflects Community Health Network's commitment to adopting innovative technologies that create a more patient-centered healthcare environment, ultimately encouraging individuals to seek care efficiently.
Sep 25, 2024·SecurityWeek
CrowdStrike announced has revamped several testing, validation, and update rollout processes to prevent a repeat of the Blue Screen of Death (BSOD) incident that occurred in July. The company is enhancing its testing protocols to improve software reliability, focusing on compatibility across various operating systems. Additionally, CrowdStrike is fostering closer collaboration with clients during the rollout process to address specific needs. To further mitigate issues, the firm is investing in advanced diagnostic tools for ongoing performance monitoring post-deployment, underlining its commitment to service quality in the cybersecurity field.
Sep 25, 2024·Newsweek
Internet security firm Proton found more than 1,800 passwords used by staffers in Congress on the dark web, highlighting the need for enhanced cybersecurity frameworks. The breach of the US Capitol’s digital systems, executed via sophisticated techniques on the dark web, has compromised sensitive information and prompted investigations into the vulnerabilities present within government networks. Lawmakers and cybersecurity experts are advocating for strengthened protocols and increased investment in advanced technologies to safeguard against similar future threats. The event underscores the broader implications for public trust and the resilience of US infrastructure amid rising cyber warfare concerns.
Sep 24, 2024·Cyberscoop
Microsoft is set to launch a new security initiative in 2024 aimed at enhancing cybersecurity for businesses. This initiative will offer a range of advanced security tools designed to integrate with existing Microsoft products, providing features such as real-time threat detection and automated responses. Microsoft emphasizes the need for a proactive approach to cybersecurity and includes a comprehensive training component to improve employee awareness and skills regarding potential threats. Overall, this initiative highlights Microsoft's commitment to equipping organizations with the necessary resources to defend against sophisticated cyberattacks.