Search site
Find podcasts, news, articles, webinars, and contributors in one search.
Health IT News
Browse by topic
Most-read stories in the last 7 days
1,000 stories
Jul 24, 2024·healthtechmagazine.net
Faced with increasing cybersecurity threats, healthcare IT leaders are adopting zero trust, a framework that mandates authentication, authorization, and continuous validation of all users accessing applications and data. Zero trust assumes that breaches have already occurred, thus preventing internal attacks. A 2023 survey by Okta showed that 61% of organizations had a zero-trust strategy, a significant increase from two years prior. Implementing zero trust in healthcare involves inventorying systems and devices, conducting risk assessments, and applying principles such as least-privileged access, network segmentation, and continuous behavior monitoring. Despite its complexity, zero trust can protect patient data without burdening clinicians, ensuring operational efficacy while mitigating security risks.
Jul 24, 2024·Infosecurity Magazine
The article addresses the increasing responsibilities of corporate boards in handling cybersecurity risks in light of new SEC reporting rules. Despite pushback and misconceptions about the necessity and feasibility of board-level cybersecurity expertise, real-world data and research indicate that the lack of such expertise hampers effective risk management. Misalignments in prioritization and resource allocation exacerbate vulnerabilities exploited by cybercriminals. Additionally, the urgent need for standardized incident response playbooks and improved communication strategies is highlighted. The article also discusses relevant federal regulations and initiatives, emphasizing the importance of board-level prioritization and direct engagement between boards and cybersecurity teams for better risk management and organizational resilience.
Jul 22, 2024·LinkedIN
On July 19, a major CrowdStrike Falcon update caused unexpected global disruptions due to a compatibility issue with Microsoft Windows, leading to widespread operational issues across various sectors. The outage highlighted the critical need for rigorous software testing, clear communication during crises, and robust contingency planning for IT departments. CrowdStrike responded swiftly by issuing a patch and mobilizing support teams, while also reviewing internal processes to prevent future incidents. This event underscores the interconnected nature of modern digital infrastructure and the importance of preparedness and collaboration in the cybersecurity landscape.
Jul 22, 2024·bleepingcomputer
The recent CrowdStrike update crash affected millions of Windows systems, leading to significant business disruptions globally. Cybercriminals have exploited this chaos by launching phishing campaigns and distributing malware under the guise of CrowdStrike updates, putting companies at further risk. In response, CrowdStrike advises customers to communicate exclusively via official channels for support. Observations by cybersecurity organizations highlight increased phishing attempts and data wiper deployments targeting these vulnerabilities. While CrowdStrike has identified and resolved the bug, the fallout included widespread operational disruptions in various sectors, and guidance has been provided for affected companies to recover their systems.
Jul 22, 2024·The Hill
Rep. Ritchie Torres (D-N.Y.) plans to introduce legislation to formalize the Cyber Safety Review Board (CSRB) following a significant IT failure at cybersecurity firm Crowdstrike. The proposed bill aims to create a structured review process for major cybersecurity incidents to improve responses and mitigate future risks. This move follows disruptions caused by the Crowdstrike meltdown, highlighting the need for enhanced oversight and a coordinated approach to handling such crises.
Jul 22, 2024·Reuters
A software update by CrowdStrike, a major cybersecurity firm, triggered a global technology outage affecting industries such as healthcare, airlines, shipping, and finance. The disruption lasted several hours and grounded flights, delayed medical services, and disrupted financial transactions, raising questions about the resilience and concentration of cybersecurity infrastructure. CrowdStrike's shares dropped significantly while its competitors saw gains. The incident emphasized the vulnerability of interconnected global systems, prompting calls for better contingency planning and multiple redundancies in IT networks.
Jul 22, 2024·Wall Street Journal
A recent article from The Wall Street Journal discusses a global tech outage that highlights the risks associated with rapid IT updates. The incident underscores the tension between the need for speed in deploying new technology and ensuring the safety and stability of IT systems. The outage serves as a reminder for businesses to carefully balance innovation with comprehensive testing and checks to prevent widespread disruptions.
Jul 22, 2024·Tom's Hardware
Southwest Airlines managed to avoid major disruptions during a global outage caused by a faulty CrowdStrike update because it still relies on Windows 3.1 and Windows 95 operating systems. Other major US airlines faced significant troubles as their newer systems were hit by the Blue Screen of Death (BSoD) due to the update. While Southwest's use of outdated systems has often been criticized, it shielded the airline from chaos, though some issues still impacted airports. The incident raises questions about future system upgrades, as newer yet vulnerable systems present ongoing risks.
Jul 22, 2024·The HIPAA Journal
A faulty software update from CrowdStrike has significantly disrupted U.S. healthcare organizations, causing hospitals to cancel appointments and delay services by rendering Windows devices inoperable. The bug in their Falcon threat detection platform led to system crashes and incapacitated devices with the blue screen of death, affecting around 8.5 million Windows devices globally. Despite the availability of a fix, the resolution process requires manual intervention, imposing a heavy burden on IT teams. The disruption impacted major health systems and other critical services, including flight operations and emergency communications. Additionally, cybercriminals are exploiting the situation by creating fake CrowdStrike-related domains to perpetrate scams, further complicating recovery efforts.
Jul 22, 2024·Becker's Hospital Review
A flawed software update released by CrowdStrike on July 18 disrupted IT systems globally, significantly impacting 8.5 million Microsoft Windows devices, including those in healthcare. Health systems such as Kaiser Permanente, Banner Health, and Mass General Brigham faced unprecedented challenges, leading to postponed surgeries and closed outpatient facilities. The cyber disruption affected major EHR systems like Epic and Meditech, with Providence's 52-hospital system experiencing severe operational breakdowns. CrowdStrike reported that hackers exploited the situation, adding additional malware threats. Microsoft, along with Google Cloud and AWS, is collaborating to ameliorate the situation, while the healthcare community continues to recover, leveraging the incident as a crucial learning experience for future IT resilience.
Jul 22, 2024·The Hacker News
CrowdStrike, reeling from a flawed update that caused IT disruptions worldwide, has alerted that threat actors are exploiting this chaos by distributing Remcos RAT malware to its customers in Latin America. Attackers are using a ZIP file labeled “crowdstrike-hotfix.zip,” which contains a malware loader that installs the Remcos RAT. The archive file includes Spanish instructions, suggesting the campaign targets Latin American users. Malicious actors have also set up fake CrowdStrike domains, offering services for cryptocurrency payments. CrowdStrike advises customers to verify communications with official representatives and follow provided technical guidance.
Jul 22, 2024·LinkedIn
The integration of AI and large language models (LLMs) in healthcare is transforming patient care and operational efficiency but also brings significant cybersecurity challenges. Healthcare systems are increasingly targeted by ransomware attacks, as evidenced by the high-profile hack of UnitedHealth Group's Change Healthcare. AI systems, due to their complex and opaque structures, may be even more vulnerable to breaches than traditional IT systems. Compromised AI can lead to inaccurate diagnoses, inappropriate treatments, and fraudulent claims, with substantial financial consequences and risks to patient safety. Healthcare leaders must adopt robust cybersecurity practices, continuously evaluate AI models, demand transparency from developers, and push for regulatory frameworks and industry-wide standards to secure AI systems. Collaborative efforts among stakeholders are crucial to harness AI's potential while safeguarding healthcare integrity.
Jul 22, 2024·arstechnica
CrowdStrike has released a patch that addresses a series of vulnerabilities requiring users to reboot their systems multiple times. The fix process can become more complex depending on the specific issues encountered, highlighting the intricate nature of cybersecurity maintenance. Details on the step-by-step remediation, affected systems, and user experience during the patching process were discussed to provide a comprehensive overview of the updates necessary for securing the environments where CrowdStrike is deployed.
Shawn Henry, Chief Security Officer at CrowdStrike, acknowledged a serious failure on their part last Friday, which has significantly impacted their customers and partners. With a career spanning almost 40 years, including 24 years at the FBI, Henry's aim has always been to "protect good people from bad things." After transitioning to CrowdStrike in 2012, the company successfully fought against cyber threats for over a decade. Despite this recent failure, which he describes as a profound gut punch, CrowdStrike is working round the clock to restore customer systems and regain the lost trust. Henry assures stakeholders that the team is committed to emerging stronger and better from this challenging experience.
Jul 22, 2024·publication
CrowdStrike has addressed an issue affecting Windows hosts caused by a defect in a recent Falcon content update. While Mac and Linux systems were not impacted, the defect triggered blue screen errors and other disruptions on Windows host systems. A fix has been deployed, reverting to a stable version of the problematic file, and CrowdStrike has ensured that their Falcon platform systems are not compromised. Customers are advised to stay updated through official CrowdStrike channels and verify communications to avoid exploitation by adversaries. Detailed remediation steps and resources are available on the CrowdStrike support portal.
Jul 20, 2024·wired.com
In response to a major Crowdstrike outage, Jeff D., Vice President & CTO at Parkland Health, shared key lessons on LinkedIn. He highlighted the fallibility of even top-tier tech companies, the dual nature of protective tools, and the drastic impact of tech absences. He emphasized the need for automated vendor fixes, thorough preparation for major events, and robust downtime procedures spearheaded by business process owners, not IT. The event underscores the importance of vigilance, preparedness, and effective crisis management in maintaining business continuity in technology-dependent environments.
Jul 20, 2024·LinkedIn
William Walders highlights the critical need for organizations to prepare for disruptions not only from direct IT issues but also from third-party services. Reflecting on the recent CrowdStrike outage, he emphasizes the inevitability of operational disruptions from various sources like natural disasters and cyber incidents. Walders advocates for robust business continuity plans, strong internal and external relationships, and flexible IT infrastructure to ensure effective recovery. He also underscores the importance of digital adoption and leveraging BYOD capabilities for seamless work continuity, stressing that preparation and communication are essential for navigating such challenges successfully.
Jul 20, 2024·The Cyber Security Hub™
A recent global IT outage caused by a bug in CrowdStrike's "Falcon Sensor" antivirus software has affected numerous sectors including airlines, hospitals, and banks. The issue led to Windows systems crashing and displaying a blue screen, disrupting services and operations worldwide. CrowdStrike CEO George Kurtz clarified that the incident was due to a software defect and not a cyberattack. The company has identified the issue, deployed a fix, and issued a manual workaround for affected clients. Despite these efforts, recovery is ongoing, with many organizations and emergency services significantly impacted.
Jul 20, 2024·Statement on Falcon content update for Windows Hosts
CrowdStrike acknowledged a defect in a specific content update affecting Windows hosts, which caused crashes identified by a blue screen error related to the Falcon Sensor. The issue does not affect Mac or Linux hosts and has been isolated and resolved with a fix now deployed. Unaffected Windows systems require no action, while impacted systems must follow workaround steps to delete the problematic channel file. Customers are advised to stay updated via the support portal and ensure communication with CrowdStrike through official channels. The Falcon platform systems and services remain operational and unaffected by this issue.
Jul 20, 2024·The Cyber Security Hub
CrowdStrike identified a specific file, “C-00000291*.sys”, in a recent update as the cause of a global IT outage. Users can address this issue by booting Windows into Safe Mode or the Windows Recovery Environment, navigating to the C:WindowsSystem32driversCrowdStrike directory, deleting the problematic file, and then rebooting the host normally. This solution allows users to retain the Falcon Sensor update while resolving the outage. Further details and workaround steps are available on the CrowdStrike blog.