Search site
Find podcasts, news, articles, webinars, and contributors in one search.
Health IT News
Browse by topic
Most-read stories in the last 7 days
1,000 stories
Sep 24, 2024·SC Magazine
Although Zero Trust has been recognized as a critical strategy for cyber resilience, misconceptions still exist that could hinder adoption. According to the article, Zero Trust complements existing security protocols by adding layers of verification and control. It fosters a more resilient security posture but does not replace conventional defenses, underscoring the importance of a multi-faceted approach to cybersecurity. By addressing these myths, organizations can better understand and implement Zero Trust principles, enhancing their overall security strategy.
Sep 24, 2024·Microsoft
Microsoft's Secure Future Initiative (SFI) has made notable advancements in cybersecurity as of September 2024, focusing on combating cyber threats and promoting a safer digital landscape. The initiative includes enhanced security measures and partnerships with various stakeholders to foster transparency in cybersecurity practices. A key highlight is the expansion of threat intelligence capabilities through artificial intelligence and machine learning, enabling real-time detection and response to threats. SFI also emphasizes collaboration with governments, non-profits, and tech companies to establish best practices and develop innovative solutions against cybercrime. Looking forward, Microsoft plans to continue investing in research and user education to further strengthen digital security.
Sep 24, 2024·BizTech
Economic challenges in recent years have prompted many companies to stretch out IT refresh cycles. However, doing so can limit their ability to fully leverage technology. The article advocates for a proactive IT modernization strategy, urging organizations to update their systems regularly to avoid the pitfalls of legacy technology, which can hinder operational effectiveness and introduce security vulnerabilities. By embracing timely upgrades, companies can optimize resources, improve customer satisfaction, and enhance their resilience against cyber threats.
Sep 24, 2024·Healthcare Dive
A recent panel discussion by Google Cloud focused on the growing cyber risks facing the healthcare supply chain, emphasizing the sector's vulnerability due to interconnected systems and sensitive data. Experts highlighted the need for robust cybersecurity measures, including regular risk assessments and advanced security technologies, as well as the importance of collaboration among stakeholders to enhance overall security. The panel also called for updated regulatory frameworks to ensure adherence to best practices across the healthcare supply chain. The conversation concluded with a clear message: healthcare organizations must prioritize cybersecurity as a fundamental aspect of their operations to protect patient data in an evolving threat landscape.
Sep 23, 2024·CyberScoop
At the MWISE conference, cybersecurity experts emphasized the increasing threat of ransomware attacks and the need for organizations to adopt proactive defense strategies. Allan Liska from Mandiant highlighted the importance of understanding the financial motivations behind these attacks and encouraged organizations to strengthen their security measures to deter attackers. Brett Callow from Emsisoft stressed the necessity of collaboration among organizations to share threat intelligence and improve overall cybersecurity, particularly as ransomware groups increasingly target critical infrastructure. The discussion also addressed evolving attack methods, such as double extortion, complicating the decision-making processes for affected organizations.
Sep 23, 2024·CIODive
As generative AI becomes more interwoven in the fabric of IT strategy, organizations face both opportunities and challenges. Flexential warns that while the technology can improve cybersecurity practices by enhancing threat detection and response, it also presents risks, such as facilitating sophisticated cyberattacks like phishing. The potential misuse of generative AI underscores the urgent need for employee training to identify fraudulent communications and necessitates a reassessment of current security protocols to ensure AI systems are secure and not vulnerable to exploitation. Ultimately, a proactive approach, including regular evaluations and best practices, is essential for protecting sensitive data in this evolving landscape.
Sep 23, 2024·Cybersecurity Dive
The role of the CISO is evolving beyond technical expertise to encompass strong leadership, communication, and adaptability, said Kevin Mandia at the recent Mandiant Worldwide Information Security Exchange conference. He stressed the importance of confidence in decision-making during security incidents and the need to build trust with non-technical stakeholders to enhance organizational security. Mandia also emphasized continuous learning and team development to keep pace with emerging threats, advocating for a holistic approach to cybersecurity that fosters resilience and effective collaboration within organizations.
Sep 20, 2024·Forbes
Cybersecurity is now recognized as a vital element of business strategy rather than just a technical concern, as organizations confront increasing risks from cyber threats. The article highlights the necessity of instilling a culture of cybersecurity awareness throughout all levels of an organization, with an emphasis on employee training and leadership involvement. This proactive approach not only helps mitigate risks but also protects sensitive information, given the significant financial and reputational consequences of cyber incidents. Organizations are urged to view cybersecurity investments as critical for long-term success, leading to the allocation of necessary resources towards advanced security measures. Ultimately, a holistic perspective on cybersecurity that aligns with business objectives is advocated.
Sep 20, 2024·CSO Online
In the rush to build and deploy AI apps, organizations can overlook essential security hardening practices during implementation, according to a report from Orca Security, which can increase their vulnerability to cyber threats. This oversight results in significant risks, including data breaches and the exploitation of AI vulnerabilities, as new attack vectors emerge. Experts emphasize the importance of adequately training staff on the security implications of AI, as a lack of awareness can worsen potential risks. Ultimately, balancing the drive for innovation with comprehensive security strategies is essential for organizations to safeguard their sensitive data and systems.
Sep 20, 2024·Healthcare Information Security
Experts emphasize the urgent need for healthcare organizations to implement robust recovery plans in response to the rising threat of ransomware attacks. These plans should prioritize patient safety and data integrity and encompass both technical recovery measures and clinical considerations to swiftly restore services. Clear communication with staff and patients is crucial during such incidents to manage expectations and reduce anxiety. Regular training and simulations for staff are recommended to ensure preparedness. Furthermore, organizations must identify and prioritize critical systems during recovery to minimize service disruptions and maintain continuity of care, as a well-defined strategy can significantly shorten recovery times and lessen the overall impact of attacks.
Sep 19, 2024·Cyberscoop
The FBI has dismantled a cyber operation associated with the Chinese botnet Flax Typhoon, which targeted U.S. critical infrastructure and government entities. Collaborating with international law enforcement, the FBI disrupted the botnet's activities and addressed the vulnerabilities it exploited. This operation underscores the importance of global cooperation in cybersecurity, as the threat from cybercriminals often transcends borders. The initiative not only mitigates risks associated with Flax Typhoon but also highlights the ongoing need for vigilance in safeguarding critical systems from cyber threats.
Sep 19, 2024·Healthcare Dive
Janet Rathod has been appointed as the Chief Information Security Officer at Johns Hopkins Medicine, charged with enhancing the organization’s cybersecurity strategy amidst rising threats in the healthcare sector. Her extensive background spans healthcare, technology, finance, and government, positioning her to address the complexities of protecting patient data. Rathod plans to cultivate a culture of security awareness through comprehensive training for staff and aims to improve collaboration across departments to create a cohesive defense against cyber threats. Her leadership comes at a pivotal moment as the healthcare industry seeks to strengthen its defenses against increasing cyberattacks.
Sep 18, 2024·CIO
Along with the advances it promises in the way of patient care, data management, and operational efficiency, digital transformation also comes with risks. Therefore, healthcare leaders must emphasize proactive risk management, including a comprehensive cybersecurity strategy and regular employee training, to protect patient data and comply with healthcare regulations. By integrating these elements into its modernization efforts, MemorialCare aims to improve patient outcomes while fostering trust and accountability within the healthcare system.
Sep 18, 2024·The Record
Lehigh Valley Health Network (LVHN) has settled a data breach case from 2020 that affected about 3,000 patients' personal information, including names and Social Security numbers. The breach was linked to unauthorized access through a third-party vendor, prompting LVHN to pay $1.5 million to those impacted and to implement enhanced cybersecurity measures. The health network has committed to investing in advanced technologies and regular audits to improve data protection and regain community trust following the incident.
Sep 18, 2024·Wall Street Journal
A cyberattack on Change Healthcare has resulted in significant delays for medical providers in receiving payments for claims, creating cash flow issues and exacerbating financial strain. The breach disrupted operations for numerous healthcare organizations that rely on Change Healthcare's services, with many providers reporting unpaid claims and seeking alternative funding to sustain their practices. While Change Healthcare is working to restore systems and enhance security measures, the prolonged recovery has left many healthcare professionals uncertain and concerned about the future of their financial stability. This incident underscores the critical need for improved cybersecurity in the healthcare sector.
A significant data breach affecting nearly one million patients has occurred within the UK's National Health Service (NHS) following a ransomware attack by the group "Clop." The hackers accessed and leaked sensitive personal information, raising concerns about patient privacy and security. NHS officials are currently evaluating the breach's impact and working with cybersecurity experts to mitigate damage and enhance security measures sector-wide. In light of this incident, NHS leaders are urging healthcare organizations to adopt stronger cybersecurity protocols, while affected patients are advised to monitor their personal information for any suspicious activity.
Sep 17, 2024·CSO
Patch management may seem like a mundane task, and yet, it plays a crucial role in safeguarding organizations against cyber threats. It highlights the challenges companies face in maintaining effective patch management strategies due to the complexity of modern IT environments, the myriad of devices, and the demands placed on IT teams. By advocating for a more streamlined approach and emphasizing the importance of security awareness and resource allocation, the article calls for organizations to prioritize patch management to reduce vulnerabilities and ensure regulatory compliance.
Sep 17, 2024·The Record
DNA, a leading genetic testing company, is investing millions to improve its cybersecurity following a significant data breach that exposed sensitive customer information. The company has announced a comprehensive plan that includes enhancing encryption technologies, implementing advanced monitoring, and conducting regular security audits. To support affected users, DNA is providing services such as credit monitoring and identity theft protection. The breach has raised wider concerns about data security in the genetic testing industry, underscoring the need for robust protection as more consumers seek genetic insights.
Sep 17, 2024·Becker's Hospital Review
With organizations becoming increasingly reliant on digital platforms for community engagement, a recent Zoom bombing incident at a hospital underscores significant vulnerabilities in online communications. During a virtual health event, hackers infiltrated the meeting, projecting offensive political propaganda instead of facilitating discussion. The hospital's administration condemned the attack and initiated enhanced cybersecurity measures to secure future virtual sessions. This occurrence highlights the need for improved online safety protocols as healthcare organizations navigate the challenges of engaging with their communities through digital channels.
Sep 16, 2024·Johns Hopkins University
Janet Rathod has been appointed as the Chief Information Security Officer at Johns Hopkins University, bringing over 20 years of information security experience, including her previous role at the University of California, Berkeley. Rathod will oversee the university's cybersecurity strategy, aiming to protect sensitive data and enhance security awareness across campus. Her focus includes fostering collaborative relationships with the university community to proactively address cybersecurity challenges, particularly as higher education institutions face increasing cyber threats.