Search site
Find podcasts, news, articles, webinars, and contributors in one search.
Health IT News
Browse by topic
Most-read stories in the last 7 days
1,000 stories
Jul 20, 2024·CNBC
A software update by cybersecurity firm CrowdStrike caused widespread IT outages across various sectors, including banking, healthcare, and air travel. Global disruptions ensued as both businesses and consumers faced significant service interruptions. The issue stemmed from a problem in CrowdStrike's Falcon product, leading to devices running Windows operating systems to crash with the "blue screen of death." The company is currently working to roll back the problematic update. Microsoft clarified that their prior cloud service outage was unrelated. While CrowdStrike announced that a fix was in progress, experts noted that the recovery process might require significant manual intervention.
Jul 20, 2024·publication
A recent CrowdStrike update caused a widespread IT outage affecting Microsoft Windows 10 and later systems, while Mac and Linux hosts remained unaffected. The issue stemmed from the CrowdStrike Falcon content update and was not due to malicious cyber activity. CrowdStrike has identified and deployed a fix for the problem. However, threat actors are exploiting the situation for phishing and other malicious activities. Organizations are urged by CISA to heighten their cybersecurity measures, remain vigilant, and ensure employees follow guidance from legitimate sources only. CISA and international cybersecurity centers continue to monitor and support remediation efforts.
Jul 20, 2024·The Wall Street Journal
CrowdStrike, a well-known cybersecurity software company, recently experienced a significant global IT outage. This disruption impacted numerous organizations relying on its services to safeguard their data and systems. The company has been working to resolve the issues and restore full functionality to its affected products. The incident underscores the critical nature of cybersecurity and the vulnerabilities even top security firms might face.
Jul 20, 2024·Wired
A global IT disruption occurred when a flawed CrowdStrike update caused Windows computers to enter an uncontrollable reboot cycle. This issue, starting with a Microsoft Azure outage followed by CrowdStrike's defective kernel driver release, impacted critical sectors such as air travel, healthcare, and emergency services. Despite CrowdStrike CEO George Kurtz's assurance that the issue was quickly isolated and resolved, the recovery process requires manual intervention on millions of affected machines worldwide. The event underscores the fragility of interconnected digital infrastructures and raises concerns about the sustainability of automatic software updates in cybersecurity.
Jul 20, 2024·wired
A faulty software update from cybersecurity firm CrowdStrike led to widespread disruptions for airports globally, affecting thousands of flights and passengers. The aviation industry, which relies heavily on intricate, automated systems for efficient operations, saw major U.S. airlines like Delta, American, and United ground flights and revert to manual processes. Consequently, over 4,000 flights were canceled and 35,500 delayed. The disruption underscored the vulnerability of the aviation ecosystem to IT failures and highlighted potential long-term effects as airlines scramble to reposition crews and aircraft.
A wide-scale IT incident was triggered when CrowdStrike's recent update to its Falcon antivirus software caused a global system crash, critically impacting health care systems. Hospitals and doctors found themselves without essential diagnostic tools and systems, leading to the cancellation of nonurgent surgeries and procedures worldwide. Emergency services in the US and digital operations in hospitals across multiple countries, including the UK, Germany, and Israel, faced significant disruptions. The outage highlighted the heavy reliance on digital systems in modern health care and underscored the need for diversified and resilient software infrastructure to prevent such catastrophic incidents in the future.
Following a significant software malfunction by security firm CrowdStrike, cybercriminals are exploiting the situation by launching fraudulent websites and scams under the guise of “CrowdStrike Support.” The faulty update to CrowdStrike's Falcon monitoring platform impacted Windows computers worldwide, prompting attackers to create domains and websites aimed at deceiving affected users and IT staff. CrowdStrike has issued warnings about these scams, urging customers to only engage with official support channels and remain vigilant against phishing attempts and false recovery tools being offered by scammers.
A recent Cloudflare outage caused widespread disruptions, forcing many businesses to revert to cash transactions or temporarily close. This incident highlighted the vulnerability of cashless systems, particularly in Australia, where the government promotes cashless transactions. Disruptions were also noted across various sectors in India and the US, impacting services like minor league baseball games, public pools, and movie theaters. Starbucks faced significant issues, compounding the problem with a promotional event. The outages reignited discussions about the security and resilience of cloud-based infrastructures, with some experts warning about the fragility of the current systems. Despite these challenges, certain cashless businesses reported benefits such as reduced transaction times and cost savings, while others were not affected by the outage at all.
Jul 19, 2024·CNN
A global computer outage on Friday, impacting airports, banks, and other businesses, was partly attributed to a software update from US cybersecurity firm CrowdStrike. The issue stemmed from a defect in a single content update of CrowdStrike's Falcon software on Microsoft Windows operating systems. The company's engineers addressed the problem by advising customers to reboot their computers. The outage, not caused by a cyberattack, led to a 10% drop in CrowdStrike's stock in premarket trading. CrowdStrike, known for its cybersecurity services to many businesses and governmental agencies, has also been notable for investigating significant cyber incidents, including Russian interference in the 2016 US election.
Jul 19, 2024·WSJ
This article discusses the prevalence of data breaches in the health technology sector, emphasizing how many incidents are linked to fundamental cybersecurity lapses. It identifies common vulnerabilities such as unpatched software, weak passwords, and inadequate access controls. The piece underscores the critical need for health tech companies to adopt basic cybersecurity measures to protect sensitive patient data from malicious actors.
Jul 19, 2024·publication
Cisco has issued security updates addressing vulnerabilities in several of its products, including network switches, security appliances, and collaboration tools. The patches focus on mitigating risks such as privilege escalation, denial of service, and remote code execution. Users and administrators are advised to apply these updates promptly to protect systems from potential exploitation. Further details and specific instructions on the updates are available on Cisco's official website.
Jul 19, 2024·The Record
The UK government has announced its intention to introduce a Cyber Security and Resilience Bill aimed at updating the country's cybersecurity regulations. This new legislation will include mandatory reporting requirements for companies hit by ransomware, in response to increasing ransomware incidents. While originally ambitious plans proposed by the Home Office would have required all ransomware victims to report and seek authorization before making extortion payments, the current bill restricts new rules to regulated entities and possibly managed service providers, leaving out broader private sector requirements. The bill aims to enhance the protection for digital services and supply chains, particularly critical public services, and includes measures to improve incident reporting standards and empower regulators to ensure cyber safety. The Department for Science, Innovation and Technology is spearheading the effort, though the introduction date to parliament remains unspecified.
Jul 19, 2024·arstechnica
Cisco announced a critical vulnerability in its Smart Software Manager On-Prem devices, allowing unauthenticated remote attackers to change any user's password, including administrators'. The vulnerability, identified as CVE-2024-20419 and rated with the highest severity score of 10, stems from improper password change process implementation. Exploiting it via crafted HTTP requests grants the attacker web UI or API access with the compromised user’s privileges. No immediate workarounds are available, but a security update has been released that addresses the issue. Cisco reports no current evidence of active exploitation.
Jul 18, 2024·healthexec
Following the February security breach at Change Healthcare, which compromised millions of medical records, a bipartisan group of Senators has introduced the Healthcare Cybersecurity Act (S. 4697). Sponsored by Senators Jacky Rosen (D-NV), Todd Young (R-IN), and Angus King (I-ME), the proposed legislation directs the U.S. Department of Health and Human Services (HHS) and the Cybersecurity and Infrastructure Security Agency (CISA) to collaborate on improving healthcare cybersecurity. It aims to enhance resources, develop defensive strategies, and establish a special liaison within CISA to ensure effective coordination with HHS. The bill has gained support from multiple academic and healthcare provider groups, emphasizing the need for strengthened cybersecurity to protect sensitive patient data and maintain healthcare operations.
Jul 18, 2024·healthcaredive.com
UnitedHealth has revised its projections for the costs associated with the massive cyberattack on its payments processor, Change, estimating impacts at $2.3 billion to $2.45 billion for the year, an increase of roughly $1 billion. The ransomware attack in February halted reimbursement processes and compromised the data of an estimated one-third of Americans, resulting in a $22 million ransom payment that ultimately failed to secure patient data. UnitedHealth’s second-quarter profit dropped to $4.2 billion from $5.5 billion due to these expenses, even as revenue grew by almost 7% to $98.9 billion. The company continues to face elevated medical costs partly due to temporarily increased provider coding during the crisis. UnitedHealth is also managing operational challenges and regulatory scrutiny, including investigations by the Department of Justice and potential litigation from the Federal Trade Commission regarding its business practices.
Jul 18, 2024·Healthcare IT News
Senator Mark Warner's policy paper, "Cybersecurity is Patient Safety," addresses the substantial risks and inefficiencies in healthcare cybersecurity. It emphasizes the need for a dedicated healthcare cybersecurity leader within the federal government to enhance coordination between the Department of Health and Human Services (HHS) and the Cybersecurity and Infrastructure Security Agency (CISA). Warner calls for legislative measures such as updating HIPAA regulations, implementing cyber hygiene practices, and incentivizing cybersecurity improvements through rebates and workforce development programs. The report outlines critical responses to cyberattacks, including federal disaster relief and programs to support rural healthcare cybersecurity efforts. Warner invites feedback from stakeholders to build a balanced, collaborative approach to address the escalating cybersecurity threats in the healthcare sector.
Jul 17, 2024·Tampa Bay Times
The Florida Department of Health experienced a significant data breach by the hacker group RansomHub, resulting in the release of over 20,000 files containing sensitive personal information, including HIV test results, immunization records, and doctors' notes, on the dark web. The breach exposed individuals' full names, social security numbers, and other private data, predominantly from Broward County. State officials confirmed the breach after several days and emphasized the ongoing challenge of cyberattacks on healthcare providers. The compromised data includes detailed medical records as well as internal department files. Notifications to affected individuals will follow a thorough review of the extent of the breach.
Jul 17, 2024·Healthcare IT Today
Patients are increasingly concerned about the security of their personal data, with a recent survey showing that 95% worry about data breaches and a significant distrust in Big Tech handling their health data. Healthcare data breaches are notably costly, averaging $10.9 million in 2023, primarily due to phishing and compromised credentials. These breaches jeopardize patient care, privacy, and institutional reputation. Providers can enhance data security by adopting advanced patient payment technologies that incorporate PCI compliance, payment tokenization, and validated point-to-point encryption, thereby mitigating the risks associated with data breaches.
Jul 17, 2024·Forbes
Apple has launched a new ad campaign urging iPhone users to stop using Google Chrome, emphasizing privacy concerns. This move comes as Google aims to increase Chrome's presence on iPhones, potentially impacting their financial arrangement where Google Search is the default on Apple's Safari browser. Amidst looming monopoly investigations, Apple's ad leverages privacy fears by highlighting Chrome's ongoing use of tracking cookies and undisclosed data collection. This strategic push underlines a broader battle for user retention and browser market share between Safari and Chrome, particularly as AI-driven search capabilities evolve.
Jul 16, 2024·SecurityWeek
A massive data breach at AT&T exposed call and text interaction records for nearly all its wireless customers between May 2022 and January 2023. The breach is linked to recent attacks on Snowflake customers, where data was illegally downloaded from AT&T's workspace on a third-party cloud platform. The stolen data includes telephone numbers, call durations, and cell site identification but lacks personal identifiers like Social Security numbers. AT&T asserts the breach has not materially impacted its operations and believes the data has not been publicly released. At least one suspect has been apprehended in connection to the breach.