Search site
Find podcasts, news, articles, webinars, and contributors in one search.
Health IT News
Browse by topic
Most-read stories in the last 7 days
4,419 stories
Aug 16, 2024·SecurityWeek
Security experts are urging Windows administrators to immediately patch a critical remote code execution vulnerability in the Windows TCP/IP stack (CVE-2024-38063), which can be exploited without user interaction. Microsoft has issued a high-severity bulletin, assigning this vulnerability a CVSS score of 9.8/10, and highlighted the ease with which attackers could craft exploits. The flaw, discovered by Chinese researcher Xiao Wei, could allow an attacker to send specially crafted IPv6 packets to a target machine, enabling remote code execution. As part of its recent Patch Tuesday release, Microsoft addressed this and six other actively exploited zero-days, underscoring the need for prompt action to mitigate these significant security risks.
Aug 16, 2024·CIO
As generative AI hype begins to wane, IT leaders are advised to recalibrate their strategies by focusing on specialized AI models and setting more realistic goals. The need to integrate a variety of AI forms, rather than solely relying on generative AI, is becoming increasingly apparent. This shift will enable organizations to harness the full potential of AI technologies more effectively.
Aug 16, 2024·CIO.com
CIOs are increasingly incorporating sustainability criteria into their evaluation of potential vendors and IT investments. This shift reflects a broader commitment to sustainability within their organizations. By vetting partners and solutions for green initiatives, CIOs aim to align their technology infrastructure with environmental goals, ensuring that IT practices contribute to broader ecological and corporate social responsibility objectives.
Aug 15, 2024·The HIPAA Journal
The enforcement of the HIPAA Security Rule is primarily overseen by HHS’ Office for Civil Rights (OCR), although other federal agencies, State Attorneys General, and organizations’ own HIPAA Privacy Officers often play more proactive roles in enforcement actions. OCR investigates a minimal number of breach notifications, typically less than 1%, leading to few enforcement actions. Violations requiring attention by other agencies, like the Department of Justice or HHS’ Office of Inspector General, often involve criminal actions or potential federal program exclusions. State Attorneys General may also impose civil monetary penalties for data breaches. While HIPAA Privacy Officers enforce compliance within organizations, the potential for future indirect enforcement by CMS through federal health program conditions signifies a need for stringent voluntary compliance to avoid penalties and exclusions.
Aug 15, 2024·The Detroit News
State Representative Donni Steele has called for increased penalties for ransomware attacks targeting Michigan hospitals after a cyber attack impacted McLaren's IT and telephone systems. Currently, hacking penalties in Michigan max out at five years in prison, while ransomware possession carries up to three years. Steele argues these punishments are insufficient given the disruptions to critical medical services, such as those experienced by McLaren and Ascension Healthcare in recent months. Both healthcare systems faced significant operational issues due to cyber attacks, with Ascension confirming potential exposure of patient data. Steele is advocating for stronger legislative measures and enhanced law enforcement collaboration to combat these cyber threats effectively.
Aug 15, 2024·The Wall Street Journal
Microsoft has stated that Delta Air Lines' slow recovery from a recent network outage was likely due to outdated technology. The airline experienced significant delays and cancellations, which Microsoft attributes to their reliance on legacy systems that are less resilient to disruptions. This highlights the growing need for companies to modernize their IT infrastructure to improve reliability and response times.
Aug 15, 2024·publication
Post-cybersecurity incident, organizations must undertake detailed post-mortem evaluations to understand the attack's specifics, identify vulnerabilities, and improve future incident responses. This analysis includes reviewing attack vectors, timelines, and the effectiveness of the responses. It is essential to share the findings and learnings within the organization and with the wider cybersecurity community to enhance collective knowledge and defenses. Feedback loops should be established to continuously improve security measures. The goal is to build a culture of continuous learning and collaboration without attributing blame, ensuring timely and constructive reviews post-incident to adapt to evolving cyber threats effectively.
Aug 15, 2024·The Register
LockBit 3.0 continues to be the leading ransomware gang according to Palo Alto Networks' Unit 42, despite law enforcement actions six months ago. Analyzing the first half of 2024, Unit 42 observed 1,762 posts on ransomware gangs' leak sites, a slight increase from 2023. The six most active groups accounted for over half of the infections, with LockBit 3.0 leading at 325 victims. The Play gang moved to second place with 155 victims, and the newcomer 8base ranked third with 119 victims. Other notable gangs included Akira, BlackBasta, and Medusa. Law enforcement disruptions have temporarily hindered certain groups like ALPHV/BlackCat and CLOP, but the criminal ecosystem quickly adapts, with new groups and rebrands emerging, leading to a resilient and evolving ransomware threat landscape.
Aug 15, 2024·PharmaLive
The Federal Trade Commission (FTC) has updated its Health Breach Notification Rule (HBNR), effective July 29, 2024, to address the evolving landscape of health data privacy. The revised rule now explicitly includes health apps and connected devices, such as wearables, under its purview and defines a breach to include unauthorized disclosures of personal health information to third-party platforms like Facebook and Google. Key changes involve new definitions of “PHR identifiable health information,” expanded requirements for breach notifications, and specific timeframes for informing both consumers and the FTC in case of data security breaches. The rule emphasizes the importance of protecting personal health data amid increasing data collection and usage for marketing purposes.
Aug 15, 2024·The Verge
CrowdStrike's president, Michael Sentonas, accepted the "Most Epic Fail" award at the Def Con hacking conference for a software update that led to a global IT outage. The Pwnie Awards highlight both achievements and failures in the security community. Sentonas acknowledged the award while emphasizing its significance as a lesson for the company. The faulty update caused Windows machines to fail globally, impacting entities such as airlines and prompting Microsoft to reconsider its policies on kernel access. CrowdStrike attributed the issue to a test software bug and committed to improving their testing processes and implementing staged updates to prevent recurrence.
Aug 15, 2024·CBS News
In the past year, prominent institutions including hospitals, tech companies, and major Las Vegas resorts suffered from ransomware attacks, where critical data is encrypted by hackers and held for ransom. The September attack on MGM Resorts cost over $100 million, highlighting the growing threat posed by the cybercrime group "Scattered Spider," a collective of young hackers from the U.S., U.K., and Canada. They have allied with Russia’s notorious BlackCat hackers, combining social engineering and sophisticated malware attacks. The rise of these cybercriminals, often younger than 25, challenges security with their adept manipulation of Western cultural norms and online spaces, driving a surge in ransomware incidents.
Aug 15, 2024·Tripwire
The extradition of Maksim Silnikau to the United States marks a significant step in a decade-long investigation into one of the world's most prolific Russian-speaking cybercriminal gangs. Known by handles such as "J P Morgan," Silnikau is accused of leading a group that developed and distributed various ransomware strains, including Reveton, which evolved into a sophisticated ransomware-as-a-service model. The investigation, led by the UK's National Crime Agency alongside the FBI and US Secret Service, initially identified "J P Morgan" in 2011 during the first Reveton ransomware attacks. Silnikau's arrest in Spain by international law enforcement highlights the extensive efforts to track and detain cybercriminals who have extorted tens of millions of dollars globally. He now faces charges in the US alongside other alleged associates.
Aug 15, 2024·Journal of the American Medical Association
The provided text does not contain any substantive content from an article within a Health Technology blog. It appears to be a generic HTML structure without any information or narrative to summarize. Please provide text with specific details or content from an article for proper summarization.
Aug 15, 2024·HealthLeaders
The emphasis on patient experience has heightened its value in the healthcare revenue cycle, adapting to a patient-consumer market where individuals bear more care costs. Patient portals have expedited processes and increased patient engagement in their care, aiding tasks like billing, scheduling, and payment plans. Allegheny Health Network utilized a financial engagement platform for integrated billing, while Lake Washington Physical Therapy saw a 47% reduction in accounts receivable with electronic billing. The pandemic-driven need for telehealth expanded digital services, with Ann & Robert H. Lurie Children’s Hospital boosting portal usage significantly through targeted initiatives. Digital tools, like at Springfield Clinic, streamline front-end tasks and reduce administrative burdens, aiming to enhance patient interactions through technology.
Aug 15, 2024·nist.gov
The U.S. Department of Commerce’s National Institute of Standards and Technology (NIST) has finalized a principal set of encryption algorithms designed to withstand future cyberattacks from quantum computers. These new standards emerge from NIST's post-quantum cryptography (PQC) standardization project and are ready for immediate deployment. As quantum computing advances, it poses significant threats to current encryption methods, potentially compromising security and privacy within a decade. The finalized standards include detailed instructions for implementation and focus on safeguarding general encryption and digital signatures. NIST continues to evaluate additional algorithms for future backup standards to ensure comprehensive protection against quantum threats.
Aug 15, 2024·Tenable Blog
Tenable Research discovered critical security vulnerabilities in Microsoft's Azure Health Bot Service that allowed access to cross-tenant resources due to server-side request forgery (SSRF) flaws. The Azure Health Bot Service enables healthcare providers to deploy AI-powered virtual assistants to streamline administrative workflows and interact with sensitive patient data. Tenable found that by exploiting the “Data Connections” feature, they could bypass filters and access internal metadata and customer resources. Microsoft promptly addressed these issues by implementing fixes across all affected regions, ensuring no customer action was necessary. A similar vulnerability was also found in endpoints validating FHIR data connections, but it did not allow cross-tenant access. Both issues have now been resolved, emphasizing the need for robust web and cloud security in AI services.
Aug 15, 2024·Wall Street Journal
Hospitals are increasingly adopting home-based healthcare services, shifting some treatments traditionally administered in hospital settings to patients' residences. This approach aims to alleviate hospital congestion, lower healthcare costs, and offer more personalized care. Advances in telemedicine and remote monitoring technology support this transition, allowing medical professionals to oversee patient recovery and administer treatments remotely. Key challenges include ensuring consistent quality of care, managing logistics, and overcoming regulatory and insurance hurdles.
Aug 15, 2024·Fierce Healthcare
Mayo Clinic is collaborating with SandboxAQ, a startup spun out of Alphabet, to research an AI-enhanced medical device for cardiac diagnostics. The device, known as CardiAQ, utilizes quantum sensing and advanced AI algorithms to enable non-invasive, rapid, and accurate cardiac assessments. The initiative aims to improve clinical diagnosis for conditions like heart attacks, potentially reducing hospital admissions and medical costs. The study involves around 150 patients and is set to run at Mayo Clinic through 2024 and 2025. If successful, the technology could revolutionize cardiac care by providing real-time, bedside diagnostic capabilities.
Aug 15, 2024·SecurityAffairs
On August 10, 2024, McLaren Health Care, a nonprofit health care organization in Michigan, was hit by an INC Ransom ransomware attack, disrupting their IT and phone systems. An investigation was launched following the attack, with patients urged to keep appointments unless otherwise informed, and to bring medical documentation to visits due to lost access to patient databases. This incident follows a significant data breach they disclosed in November 2023, exposing personal information of over 2.1 million individuals. McLaren is enhancing its security protocols and offering 12 months of identity protection services to affected individuals.
Aug 15, 2024·cisa.gov
CISA and the FBI have updated their joint Cybersecurity Advisory regarding BlackSuit (Royal) ransomware, providing detailed insights into recent and past tactics, techniques, and procedures (TTPs), as well as indicators of compromise (IOCs). Investigations revealed that BlackSuit ransomware has impacted various critical infrastructure sectors including commercial facilities, healthcare, government, and manufacturing. Network defenders are advised to review this update and implement the recommended mitigations. Additionally, CISA urges software manufacturers to improve security outcomes for customers by adopting secure by design practices, for which comprehensive guidelines are available on CISA’s website.