Search site
Find podcasts, news, articles, webinars, and contributors in one search.
Health IT News
Browse by topic
Most-read stories in the last 7 days
1,000 stories
Sep 16, 2024·BleepingComputer
FBI has issued a warning against false claims on social media regarding hacked voter data, asserting that there is no evidence to support such allegations. The agency stressed the importance of relying on credible sources for information about election security and urged the public to avoid spreading unverified claims that could undermine trust in the electoral process. In response to ongoing cybersecurity threats, the FBI is working closely with state and local officials to enhance protective measures for election systems while advocating for accurate information to uphold the integrity of democracy.
Sep 15, 2024·Cybersecurity Dive
Cyber insurance is evolving in response to increasing cybersecurity threats and a competitive market landscape. Insurers are adjusting their policies to account for the rising costs associated with cyber incidents, leading to higher premiums and stricter requirements for policyholders. As companies seek coverage, they are faced with challenges related to accurately assessing their cyber risk and navigating the complex underwriting process, which is becoming more rigorous in light of recent high-profile attacks. The article highlights the need for businesses to adopt robust cybersecurity measures to secure favorable insurance terms.
Sep 15, 2024·Healthcare IT Today
In the latest episode of the CIO Podcast, Mike Mainiero discusses the recent CrowdStrike outage, exploring its implications for healthcare organizations and cybersecurity strategies. He emphasizes the importance of incident response planning and the need for robust security measures to protect sensitive patient data in the face of evolving threats. The conversation highlights the lessons learned from this outage and how healthcare IT leaders can better prepare for similar challenges in the future.
Sep 15, 2024·Lehigh Valley News
Lehigh Valley Health Network has reached a $60 million settlement regarding a data breach that compromised the personal information of over 3,000 patients. The breach, which occurred in 2018, involved unauthorized access to patient data stored by a third-party vendor. Affected individuals are advised to enroll in credit monitoring services and remain vigilant for signs of identity theft, as the settlement includes provisions for compensation related to the breach. The settlement underscores the importance of data security in healthcare settings.
A recent cybersecurity breach involving the MOVEit file transfer software has impacted the Wisconsin Department of Health Services, compromising sensitive data for over 100,000 individuals, including Medicare members. The incident has raised concerns about data protection protocols, leading the state to notify affected individuals and review its cybersecurity measures. The breach highlights the growing risks associated with third-party software vulnerabilities in healthcare data management.
Sep 13, 2024·SecurityWeek
Palo Alto Networks has released updates to address multiple vulnerabilities in its products, impacting features such as firewalls and cloud services. The patches cover over 40 security flaws, with several rated critical in severity, highlighting the importance of timely software updates to mitigate potential exploitation risks for users and organizations relying on these technologies. The company advises users to apply the updates promptly to enhance their security posture.
Sep 13, 2024·CyberNews
A recent cybersecurity incident involving MNA Healthcare has led to the exposure of sensitive patient data, affecting thousands of individuals. The breach, attributed to a third-party vendor, has raised significant concerns regarding data security practices within healthcare organizations. MNA Healthcare has begun notifying impacted patients and is working with cybersecurity experts to mitigate the damage and prevent further breaches. This incident highlights ongoing vulnerabilities in healthcare data protection and the need for stringent safeguards against cyber threats.
A Pennsylvania healthcare provider has agreed to pay $6.5 million to settle claims related to a ransomware attack that compromised the sensitive data of approximately 3.2 million patients. The settlement follows allegations that the provider failed to implement adequate security measures to protect patient information, resulting in unauthorized access and data breaches. The funds from the settlement will be used to enhance cybersecurity measures and provide compensation to affected individuals.
Sep 12, 2024·SecurityWeek
Intel has notified customers about over a dozen vulnerabilities affecting its processors, including serious security flaws that could allow unauthorized access to sensitive data. The company is advising users to apply updates and patches to mitigate risks. Among the highlighted vulnerabilities are issues related to privilege escalation and information disclosure, which could impact a range of devices from servers to personal computers. Intel emphasizes the importance of prompt action to ensure system security and stability.
Sep 12, 2024·Information Security Buzz
The article discusses the growing cybersecurity risks faced by healthcare organizations as they increasingly rely on third-party suppliers for technology solutions. It underscores the importance of robust supplier management practices to mitigate vulnerabilities that could compromise patient data and healthcare operations. The piece highlights that many healthcare providers lack sufficient cybersecurity measures when engaging with suppliers, making them potential targets for cyberattacks. It advocates for a proactive approach to strengthen cybersecurity frameworks and enhance the overall security posture of the healthcare sector.
Sep 12, 2024·LinkedIn
In the article, Dr. Leber emphasizes the critical role of the human element in cybersecurity, highlighting that technological defenses alone are insufficient to combat cyber threats. He advocates for a comprehensive approach that includes training and awareness programs to empower employees, alongside technological measures. By focusing on the human factors in cybersecurity, organizations can better mitigate risks and enhance their overall security posture.
Sep 12, 2024·CPAPracticeAdvisor.com
In response to escalating cyber threats, CFOs are increasingly prioritizing data security and privacy within their organizations. The article highlights a shift in focus towards financial planning and analysis (FP&A) alongside the integration of generative AI technologies. This strategic pivot aims to enhance risk management and safeguard sensitive financial information, reflecting the growing recognition of cybersecurity as a critical component of financial and operational strategy.
Sep 12, 2024·The Record
A data breach in Wisconsin has resulted in the exposure of sensitive information belonging to approximately one million Medicare beneficiaries. The incident involved the unauthorized access of personal details by a third-party vendor, raising concerns about patient privacy and the security of health information systems. Authorities are working with affected individuals to mitigate risks and provide guidance on protecting their data.
Sep 12, 2024·BankInfoSecurity
CrowdStrike has reported that it has not encountered any customer lawsuits stemming from a recent service outage that impacted its operations. The cybersecurity firm suffered a technical disruption that affected customer access, but the company has emphasized its commitment to addressing the issue and maintaining customer support. Despite the outage, CrowdStrike indicated that it has not received any legal claims related to the incident, and it continues to work on enhancing its service reliability.
The article discusses the critical role of the human element in cybersecurity, emphasizing that technological measures alone are insufficient to defend against threats. The author argues for leveraging psychological and organizational factors to enhance security protocols and foster a culture of awareness among employees. By prioritizing training, communication, and behavioral strategies, organizations can better combat cyber risks and protect sensitive information.
Sep 11, 2024·JD Supra
The U.S. Department of Health and Human Services’ Office for Civil Rights (OCR) has reiterated the importance of complying with the Physical Security provisions of the Health Insurance Portability and Accountability Act (HIPAA). The reminder emphasizes the need for healthcare organizations to implement adequate physical safeguards to protect electronic medical records and related equipment from risks such as unauthorized access, damage, and interference. OCR encourages regular audits and risk assessments to identify vulnerabilities and ensure compliance with HIPAA regulations.
Sep 11, 2024·CSO Online
The article discusses the evolving responsibilities of Chief Information Security Officers (CISOs) in response to increasing cybersecurity threats and organizational demands. It highlights a shift towards a more strategic focus, where CISOs are now expected to engage more with executive leadership and align security initiatives with business objectives. The piece also explores the potential emergence of new roles, such as Chief Risk Officers or Chief Cybersecurity Officers, to address the broader scope of risk management and governance in organizations.
Sep 11, 2024·Krebs on Security
A critical vulnerability in Windows systems has left numerous computers unpatched due to a bug in the Microsoft Windows Update service. This issue disrupted the installation of updates for various versions of Windows, potentially exposing users to security risks. Microsoft has acknowledged the problem and is working on a resolution, urging affected users to check their systems for updates manually to ensure they are protected.
Sep 10, 2024·SecurityWeek
The article emphasizes the importance of cybersecurity maturity as a critical focus for Chief Information Security Officers (CISOs). It discusses the necessity for organizations to proactively assess and enhance their cybersecurity practices, ensuring comprehensive risk management and resilience against increasingly sophisticated threats. The piece outlines key strategies for achieving maturity, including the development of a structured framework, continuous training for staff, and regular assessments of security protocols. Overall, it advocates for a strategic approach to cybersecurity that integrates risk management throughout the organization.
The article examines the security and privacy risks associated with generative AI applications, highlighting the lack of regulatory frameworks and standardized guidelines governing their use. It discusses potential vulnerabilities these technologies may introduce, such as unauthorized data access and the dissemination of misinformation. The piece calls for increased vigilance from developers and users to ensure robust security measures are implemented and emphasizes the need for regulatory oversight to protect sensitive information and mitigate risks.