Search site
Find podcasts, news, articles, webinars, and contributors in one search.
Health IT News
Browse by topic
Most-read stories in the last 7 days
1,000 stories
Sep 10, 2024·IT Brew
Instances of QR code phishing are increasing, though still relatively limited, as cybercriminals exploit the growing use of QR codes for various transactions. While the technology offers convenience, it also presents security vulnerabilities, making users susceptible to scams that lead to personal information theft. Experts emphasize the importance of vigilance, encouraging individuals to verify the authenticity of QR codes before scanning and to be cautious of links that could compromise their data security.
Sep 9, 2024·Cybersecurity Dive
The Cybersecurity and Infrastructure Security Agency (CISA) has launched a new Cyber Incident Reporting System that aims to streamline and enhance the reporting of significant cyber incidents. This portal is designed to facilitate communication between critical infrastructure entities and the federal government, allowing for faster response and better coordination in incident management. The initiative reflects CISA's commitment to improving cybersecurity collaboration and transparency amid increasing cyber threats.
Sep 9, 2024·Axios
President Biden has established a three-headed cybersecurity team to enhance the nation’s defenses against cyber threats. This team includes the new National Cyber Director, the Deputy National Security Advisor for Cyber and Emerging Technology, and the Cybersecurity and Infrastructure Security Agency leadership. Together, they are tasked with coordinating federal cybersecurity efforts, improving collaboration among agencies, and responding to the increasing frequency and sophistication of cyberattacks on critical infrastructure and governmental systems.
Sep 9, 2024·Raconteur
The article discusses the evolving partnership between Chief Financial Officers (CFOs) and Chief Information Security Officers (CISOs) in organizations, highlighting the growing recognition of cybersecurity as a critical aspect of financial planning and risk management. It emphasizes the need for CFOs to understand cybersecurity investments and their potential return, while CISOs must articulate the financial implications of security risks. This collaborative relationship is essential for navigating the complexities of modern business challenges and ensuring the long-term resilience of the organization.
Sep 9, 2024·Healthcare Finance News
The Centers for Medicare and Medicaid Services (CMS) announced that a cyber breach has potentially exposed the personal information of approximately 1 million individuals. The agency informed affected parties that their data may have been accessed without authorization, prompting concerns about privacy and the security measures in place. CMS is providing resources for those impacted, including guidance on monitoring their information for potential misuse.
Sep 6, 2024·TechRadar
As the new academic year begins, educational institutions are increasingly targeted by cybercriminals, prompting concerns over data security and privacy. The rise in remote learning and digital resources has expanded the attack surface for hackers, who exploit vulnerabilities within school networks. Experts emphasize the need for robust cybersecurity measures and staff training to protect sensitive student and institutional data from potential breaches.
Sep 6, 2024·The Register
Planned Parenthood reported a cybersecurity incident impacting the personal information of patients and donors. The organization discovered unauthorized access to its system, which may have exposed sensitive data. In response, Planned Parenthood is implementing enhanced security measures and is working with cybersecurity experts to investigate the breach and notify affected individuals.
Sep 6, 2024·CSO
A recent survey reveals that Chief Information Security Officers (CISOs) anticipate modest budget increases for 2024, with many organizations planning to allocate additional resources to bolster cybersecurity efforts. Despite growing concerns about security threats and the evolving landscape of cyberattacks, the overall budget growth remains conservative. The survey indicates that while priorities include improved security measures and compliance, CISOs face ongoing challenges in securing adequate funding amid competing organizational demands.
Sep 6, 2024·JD Supra
On September 3, 2024, Hospital Sisters Health System (HSHS) filed a notice of data breach after an unauthorized party accessed sensitive patient information, including names, Social Security numbers, and medical records. The breach occurred between August 16 and August 27, 2023. HSHS responded by containing the incident, notifying law enforcement, and investigating the breach with third-party security experts. Letters were sent to affected individuals, informing them of the compromised data. HSHS operates 13 hospitals in Illinois and Wisconsin, employing over 14,500 people.
Sep 6, 2024·Becker's Hospital Review
A recent report from the White House indicates that a limited number of rural hospitals are taking advantage of available free cybersecurity resources. Despite the ongoing challenges posed by cyber threats in the healthcare sector, many rural facilities remain unaware of the assistance options, underscoring a gap in resource utilization that may leave them vulnerable to attacks.
Sep 5, 2024·CSO
A recent survey conducted by the International Association for Privacy Professionals revealed that Chief Information Security Officers (CISOs) anticipate only modest budget increases for 2024, reflecting ongoing economic pressures. While cybersecurity remains a priority, organizations are facing challenges in balancing budget constraints with the need to enhance their security posture. The survey highlights a trend toward reallocating existing resources rather than significant additional funding, indicating a strategic approach to managing cybersecurity investments.
Sep 5, 2024·HSToday
The article discusses the growing threat of cyberattacks in the healthcare sector and emphasizes the need for a strategic response to enhance security measures. It outlines key challenges faced by healthcare organizations, such as outdated systems and limited budgets, and advocates for comprehensive cybersecurity frameworks that include risk assessment, staff training, and collaboration with government entities. The piece highlights the importance of proactive planning and investment in technology to safeguard patient data and ensure the continuity of care amidst evolving cyber risks.
Sep 4, 2024·Healthcare IT News
A joint cybersecurity advisory issued by the Cybersecurity and Infrastructure Security Agency (CISA) and other agencies warns of potential cyberattacks from Iran-based threat actors. The advisory highlights tactics and techniques used in previous incidents, focusing on the healthcare sector's vulnerabilities. It emphasizes the need for organizations to enhance their cybersecurity measures, implement best practices, and ensure robust incident response plans to mitigate risks associated with these threats.
Sep 4, 2024·BankInfoSecurity
The proposed House bill would establish a collaboration between the Cybersecurity and Infrastructure Security Agency (CISA) and the Department of Health and Human Services (HHS) to enhance cybersecurity within the healthcare sector. The initiative aims to improve the protection of health organizations against cyber threats by facilitating information sharing and providing resources to mitigate risks. If passed, this partnership would result in a coordinated approach to cybersecurity, emphasizing the importance of safeguarding sensitive health data.
Sep 4, 2024·Healthcare Info Security
The proposed House Bill A-26176 aims to enhance cybersecurity in the health sector by establishing a partnership between the Cybersecurity and Infrastructure Security Agency (CISA) and the Department of Health and Human Services (HHS). If passed, the legislation would facilitate collaboration on threat analysis, information sharing, and the development of resilience strategies to protect healthcare organizations from cyberattacks. The bill reflects growing concerns over vulnerabilities in the health sector, which has increasingly become a target for cybercriminals.
Sep 3, 2024·CSO Online
The article "3 Key Strategies for Mitigating Non-Human Identity Risks" by CSO Online focuses on addressing the security risks associated with non-human identities, such as service accounts and robotic processes. It emphasizes the importance of adopting three key strategies: inventorying all non-human identities, implementing strong access controls, and continuously monitoring and auditing these identities for suspicious activities. By following these strategies, organizations can better secure their systems and reduce potential vulnerabilities related to non-human entities.
Sep 3, 2024·HealthLeaders
The article "Cybersecurity Maturity a Must-Have on CISOs' Agenda" from HealthLeaders Media emphasizes the critical importance of advancing cybersecurity measures within healthcare organizations. It outlines that Chief Information Security Officers (CISOs) must prioritize improving their cybersecurity maturity to combat increasing cyber threats. The piece discusses strategies such as adopting new technologies, improving incident response plans, and fostering a culture of security awareness among staff. These steps are integral in protecting sensitive patient data and maintaining regulatory compliance amidst a landscape of growing cyber risks.
Sep 3, 2024·BankInfoSecurity
A small rural hospital in Alabama reported a significant data breach in 2023, revealing that hackers accessed sensitive patient information, including Social Security numbers and medical records. The hospital indicated that it is working with cybersecurity experts to investigate the incident and has notified affected individuals. This incident highlights ongoing cybersecurity vulnerabilities faced by rural healthcare institutions, emphasizing the need for improved security measures in the sector.
Sep 2, 2024·Cyberscoop
The increasing digital connectivity in the United States has introduced unprecedented cyber threats to critical infrastructure, posing significant risks to public safety. Federal policymakers are examining how insurance products can bolster cyber risk management, drawing parallels with incentives seen in homeowner and automobile insurance. Standards of care must be established across Operational Technology (OT) sectors to mitigate risks similar to fire or mechanical failures. The emphasis is on implementing mandatory cyber safety engineering standards to ensure resilience in new infrastructure, aided by the $1.2 trillion Infrastructure Investment and Jobs Act. A taxpayer-funded backstop for catastrophic cyber incidents could lead to moral hazard risks, making it crucial to prioritize proactive risk mitigation over risk transfer. Active collaboration among asset owners, engineers, and insurers is essential for effective cyber risk management and continuous improvement. Public policy must focus on avoiding consequences rather than managing post-catastrophe outcomes to protect lives.
Sep 2, 2024·HCInnovationGroup
The Department of Health and Human Services Health Sector Cybersecurity Coordination Center (HC3) has issued an alert regarding Everest, a ransomware-as-a-service group actively targeting the healthcare sector. Active since 2020, Everest recently impacted a U.S. surgical facility and operates as an initial access broker, facilitating ransomware attacks by selling unauthorized access to other gangs. Healthcare organizations are advised to use network monitoring tools to detect Cobalt Strike activations.