Search site
Find podcasts, news, articles, webinars, and contributors in one search.
Health IT News
Browse by topic
Most-read stories in the last 7 days
1,000 stories
Aug 19, 2024·Los Angeles Times
A recent article from the LA Times reports on a massive data breach that could have more severe consequences than initially anticipated. The breach has potentially exposed sensitive information on a large scale, raising concerns about data security and privacy for individuals and businesses alike. Details about the extent of the breach and the specific data compromised are still emerging, with experts urging affected parties to take precautionary measures to protect their information.
Aug 19, 2024·techtarget
Wiz researchers have identified significant security vulnerabilities in AI infrastructure platforms such as Hugging Face, Replicate, and SAP AI Core, which could allow attackers to access sensitive user data. At the Black Hat USA 2024 conference, researchers Hillai Ben-Sasson and Sagi Tzadik demonstrated how they breached these platforms using malicious models and container escape techniques to cross-tenant barriers. They discovered that current containerization methods are inadequate for secure data isolation. While providers have been responsive in addressing reported issues, the researchers stressed the need for better sandboxing and isolation standards. Overall, the rapid adoption of AI often overlooks security, introducing additional risks due to the use of numerous tools and open-source resources without proper security validation.
Aug 19, 2024·The HIPAA Journal
Healthcare providers in Illinois, Florida, and Puerto Rico have confirmed data breaches resulting from cyberattacks. Roseland Community Hospital in Illinois reported unauthorized access to its IT network on June 2, 2024, affecting at least 500 individuals' protected health information. In Puerto Rico, Hospital Auxilio Mutuo experienced a network server breach in September 2023, with ongoing investigations suggesting at least 500 individuals were impacted. PRM Management Company in Florida detected a breach in an email account involving patient data, with unauthorized access between January and June 2024. Each entity is in the process of notifying affected individuals and strengthening cybersecurity measures.
Aug 16, 2024·The Record from Recorded Future News
The White House is developing a new cyber insurance policy proposal aimed at addressing catastrophic cyber incidents, as announced at the Black Hat cybersecurity conference. National Cyber Director Harry Coker revealed that his office, in collaboration with the Department of Treasury’s federal insurance office and the Cybersecurity and Infrastructure Security Agency (CISA), is set to release the proposal by the end of the year. The initiative, part of the broader National Cybersecurity Strategy, seeks to manage risk, stabilize the insurance market against catastrophic cyber threats, and improve national cybersecurity resilience. Current efforts focus on challenges related to actuarial data and understanding stakeholder needs within the insurance industry.
Aug 16, 2024·HealthCare Dive
Court documents reveal that federal and state investigations are underway into Prospect Medical Holdings, a 16-hospital system accused of defrauding the government and failing to protect personal information prior to a ransomware attack last year. The investigations, which involve the U.S. Department of Justice, Connecticut Attorney General, and Connecticut Commissioner of Consumer Protection, are part of a larger legal conflict with Yale New Haven Health over a $435 million hospital sale. The DOJ has issued Civil Investigative Demands linked to potential violations of the False Claims Act, while Connecticut officials are focused on cybersecurity lapses and potentially deceptive hospital funding practices. Prospect denies all allegations.
Aug 16, 2024·Cybersecurity Dive
The article highlights the pitfalls of focusing too much on the identities of cybercriminal groups in enterprise security strategies. Experts, including Andy Piazza from Palo Alto Networks Unit 42 and Jen Easterly from the Cybersecurity and Infrastructure Security Agency, argue that mythologizing threat actors can detract from more effective practices like improving detection, response capabilities, and patch management. They suggest that instead of emphasizing the names and narratives of cyberattacks, defenders should concentrate on practical measures to reduce risk. Crowdsourcing efforts from cybersecurity vendors, such as CrowdStrike's symbolic representations of threat groups, aim to elevate cybersecurity discourse but can inadvertently glamorize the adversaries they seek to neutralize.
Aug 16, 2024·NPR
Hospitals are increasingly reliant on internet-connected devices for patient care, but this dependency makes them targets for cyberattacks. Cybersecurity expert Beau Woods stresses the necessity of cybersecurity funding, as attacks can impede treatment and force patient transfers. Such incidents have surged, with attacks on organizations like Change Healthcare and Ascension causing significant disruptions. To combat this, the Biden administration has announced tech companies will provide free or discounted cybersecurity services to underfunded hospitals. However, experts worry that these temporary measures may not offer a long-term solution, highlighting the ongoing vulnerability of smaller hospitals. Cyberattack simulations underscore the importance of preparedness in ensuring patient safety.
Aug 16, 2024·SecurityWeek
Security experts are urging Windows administrators to immediately patch a critical remote code execution vulnerability in the Windows TCP/IP stack (CVE-2024-38063), which can be exploited without user interaction. Microsoft has issued a high-severity bulletin, assigning this vulnerability a CVSS score of 9.8/10, and highlighted the ease with which attackers could craft exploits. The flaw, discovered by Chinese researcher Xiao Wei, could allow an attacker to send specially crafted IPv6 packets to a target machine, enabling remote code execution. As part of its recent Patch Tuesday release, Microsoft addressed this and six other actively exploited zero-days, underscoring the need for prompt action to mitigate these significant security risks.
Aug 15, 2024·The Detroit News
State Representative Donni Steele has called for increased penalties for ransomware attacks targeting Michigan hospitals after a cyber attack impacted McLaren's IT and telephone systems. Currently, hacking penalties in Michigan max out at five years in prison, while ransomware possession carries up to three years. Steele argues these punishments are insufficient given the disruptions to critical medical services, such as those experienced by McLaren and Ascension Healthcare in recent months. Both healthcare systems faced significant operational issues due to cyber attacks, with Ascension confirming potential exposure of patient data. Steele is advocating for stronger legislative measures and enhanced law enforcement collaboration to combat these cyber threats effectively.
Aug 15, 2024·publication
Post-cybersecurity incident, organizations must undertake detailed post-mortem evaluations to understand the attack's specifics, identify vulnerabilities, and improve future incident responses. This analysis includes reviewing attack vectors, timelines, and the effectiveness of the responses. It is essential to share the findings and learnings within the organization and with the wider cybersecurity community to enhance collective knowledge and defenses. Feedback loops should be established to continuously improve security measures. The goal is to build a culture of continuous learning and collaboration without attributing blame, ensuring timely and constructive reviews post-incident to adapt to evolving cyber threats effectively.
Aug 15, 2024·The Register
LockBit 3.0 continues to be the leading ransomware gang according to Palo Alto Networks' Unit 42, despite law enforcement actions six months ago. Analyzing the first half of 2024, Unit 42 observed 1,762 posts on ransomware gangs' leak sites, a slight increase from 2023. The six most active groups accounted for over half of the infections, with LockBit 3.0 leading at 325 victims. The Play gang moved to second place with 155 victims, and the newcomer 8base ranked third with 119 victims. Other notable gangs included Akira, BlackBasta, and Medusa. Law enforcement disruptions have temporarily hindered certain groups like ALPHV/BlackCat and CLOP, but the criminal ecosystem quickly adapts, with new groups and rebrands emerging, leading to a resilient and evolving ransomware threat landscape.
Aug 15, 2024·The Verge
CrowdStrike's president, Michael Sentonas, accepted the "Most Epic Fail" award at the Def Con hacking conference for a software update that led to a global IT outage. The Pwnie Awards highlight both achievements and failures in the security community. Sentonas acknowledged the award while emphasizing its significance as a lesson for the company. The faulty update caused Windows machines to fail globally, impacting entities such as airlines and prompting Microsoft to reconsider its policies on kernel access. CrowdStrike attributed the issue to a test software bug and committed to improving their testing processes and implementing staged updates to prevent recurrence.
Aug 15, 2024·CBS News
In the past year, prominent institutions including hospitals, tech companies, and major Las Vegas resorts suffered from ransomware attacks, where critical data is encrypted by hackers and held for ransom. The September attack on MGM Resorts cost over $100 million, highlighting the growing threat posed by the cybercrime group "Scattered Spider," a collective of young hackers from the U.S., U.K., and Canada. They have allied with Russia’s notorious BlackCat hackers, combining social engineering and sophisticated malware attacks. The rise of these cybercriminals, often younger than 25, challenges security with their adept manipulation of Western cultural norms and online spaces, driving a surge in ransomware incidents.
Aug 15, 2024·Tripwire
The extradition of Maksim Silnikau to the United States marks a significant step in a decade-long investigation into one of the world's most prolific Russian-speaking cybercriminal gangs. Known by handles such as "J P Morgan," Silnikau is accused of leading a group that developed and distributed various ransomware strains, including Reveton, which evolved into a sophisticated ransomware-as-a-service model. The investigation, led by the UK's National Crime Agency alongside the FBI and US Secret Service, initially identified "J P Morgan" in 2011 during the first Reveton ransomware attacks. Silnikau's arrest in Spain by international law enforcement highlights the extensive efforts to track and detain cybercriminals who have extorted tens of millions of dollars globally. He now faces charges in the US alongside other alleged associates.
Aug 15, 2024·nist.gov
The U.S. Department of Commerce’s National Institute of Standards and Technology (NIST) has finalized a principal set of encryption algorithms designed to withstand future cyberattacks from quantum computers. These new standards emerge from NIST's post-quantum cryptography (PQC) standardization project and are ready for immediate deployment. As quantum computing advances, it poses significant threats to current encryption methods, potentially compromising security and privacy within a decade. The finalized standards include detailed instructions for implementation and focus on safeguarding general encryption and digital signatures. NIST continues to evaluate additional algorithms for future backup standards to ensure comprehensive protection against quantum threats.
Aug 15, 2024·Tenable Blog
Tenable Research discovered critical security vulnerabilities in Microsoft's Azure Health Bot Service that allowed access to cross-tenant resources due to server-side request forgery (SSRF) flaws. The Azure Health Bot Service enables healthcare providers to deploy AI-powered virtual assistants to streamline administrative workflows and interact with sensitive patient data. Tenable found that by exploiting the “Data Connections” feature, they could bypass filters and access internal metadata and customer resources. Microsoft promptly addressed these issues by implementing fixes across all affected regions, ensuring no customer action was necessary. A similar vulnerability was also found in endpoints validating FHIR data connections, but it did not allow cross-tenant access. Both issues have now been resolved, emphasizing the need for robust web and cloud security in AI services.
Aug 15, 2024·SecurityAffairs
On August 10, 2024, McLaren Health Care, a nonprofit health care organization in Michigan, was hit by an INC Ransom ransomware attack, disrupting their IT and phone systems. An investigation was launched following the attack, with patients urged to keep appointments unless otherwise informed, and to bring medical documentation to visits due to lost access to patient databases. This incident follows a significant data breach they disclosed in November 2023, exposing personal information of over 2.1 million individuals. McLaren is enhancing its security protocols and offering 12 months of identity protection services to affected individuals.
Aug 15, 2024·cisa.gov
CISA and the FBI have updated their joint Cybersecurity Advisory regarding BlackSuit (Royal) ransomware, providing detailed insights into recent and past tactics, techniques, and procedures (TTPs), as well as indicators of compromise (IOCs). Investigations revealed that BlackSuit ransomware has impacted various critical infrastructure sectors including commercial facilities, healthcare, government, and manufacturing. Network defenders are advised to review this update and implement the recommended mitigations. Additionally, CISA urges software manufacturers to improve security outcomes for customers by adopting secure by design practices, for which comprehensive guidelines are available on CISA’s website.
Aug 15, 2024·Becker's Hospital Review
Rick Pollack, CEO of the American Hospital Association (AHA), compared cybercrime to a "chronic disease" in his August 8 statement, advocating for enhanced safeguards and federal collaboration to manage its risks. The healthcare industry faces persistent cyberattacks, as seen in the ransomware incidents involving Change Healthcare and OneBlood. In response, the AHA provides cybersecurity alerts, preparedness plans, and tech company support. Pollack emphasized the need for shared responsibility between the healthcare sector and government, calling for greater federal intelligence sharing and disruption of cyber threats. He also urged the Biden administration to align cybersecurity regulations with the Department of Health and Human Services' voluntary approach and to provide more resources and third-party standards for healthcare systems.
Aug 15, 2024·Infosecurity Magazine
The US Cybersecurity and Infrastructure Security Agency (CISA) has launched the "Secure by Design" initiative in 2023, now urging software consumers to adopt a "Secure by Demand" approach. CISA Director Jen Easterly emphasized at Black Hat USA the role of organizations in promoting Secure by Demand by using their purchasing power to prioritize software security. A new Secure by Demand Guide provides questions and resources to help organizations evaluate the cybersecurity practices of software manufacturers. In May, a Secure by Design pledge was introduced, with nearly 200 software manufacturers committing to improved security practices. CISA is actively tracking and promoting the progress of these manufacturers to reduce vulnerabilities and improve security across the technology ecosystem.