Search site
Find podcasts, news, articles, webinars, and contributors in one search.
Health IT News
Browse by topic
Most-read stories in the last 7 days
4,419 stories
Jul 8, 2024·Lexology
On June 28, 2024, the U.S. Supreme Court overruled the Chevron doctrine in Loper Bright Enterprises v. Raimondo, which had allowed courts to defer to agency interpretations of ambiguous statutes for nearly 40 years. This change, along with the Court's subsequent ruling on July 1 regarding the timing of the statute of limitations under the Administrative Procedure Act in Corner Post, Inc. v. Board of Governors of the Federal Reserve System, signals a significant shift in administrative law. The withdrawal of Chevron deference means that courts will now independently interpret statutory law without automatically deferring to agency expertise. This will likely result in increased litigation as regulated industries challenge agency actions, impacting sectors such as healthcare, environment, real estate, and more. The implications are profound, as the regulated community may now leverage these rulings to contest a broader spectrum of federal regulations, necessitating closer scrutiny of statutory language by agencies and Congress alike.
Jul 5, 2024·cfodive.com
The recent U.S. Supreme Court decision to overturn the Chevron doctrine, which previously allowed courts to defer to federal agency interpretations of ambiguous statutes, could significantly impact regulatory actions by agencies like the Federal Trade Commission (FTC) and the Securities and Exchange Commission (SEC) concerning cybersecurity. This shift challenges the authority of these agencies, which have used older statutes to address modern cybersecurity issues in the absence of explicit congressional mandates. The ruling may particularly affect the FTC's initiative to establish extensive data privacy and security rules. Concurrently, the SEC's mandate requiring companies to report significant cybersecurity incidents has faced criticism and opposition from some congressional Republicans, highlighting ongoing debates over the appropriate scope and reach of federal cybersecurity regulation.
Jul 5, 2024·aha.org
The American Hospital Association (AHA) has provided feedback to the Cybersecurity and Infrastructure Security Agency (CISA) regarding its proposed Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) rule. While acknowledging the importance of incident reporting to understand and mitigate cyber threats, the AHA raises concerns about the redundancy, complexity, and timing of these requirements, which could burden hospitals during critical times. They advise CISA to harmonize its reporting rules with existing regulations, ensure data anonymity, and simplify the reporting process. Additionally, the AHA emphasizes the need for clearer definitions, more inclusive criteria for all health care-related entities, and a reduction of the operational burden on hospitals, suggesting that penalties on victim organizations be reconsidered in favor of collaborative approaches.
Jul 5, 2024·Mass General Brigham
Daniel Restrepo, MD, a physician at Massachusetts General Hospital, conducted two studies comparing the diagnostic reasoning abilities of large language models (LLMs) to human physicians. Published in *JAMA Internal Medicine* and the *Journal of Hospital Medicine*, the research explored whether AI could reduce clinical reasoning errors that often lead to misdiagnoses. The first study compared an LLM and a human doctor in diagnosing a real medical case, revealing that the AI was slower to integrate new data points but arrived at the correct diagnosis. The second study assessed GPT-4 against resident and attending physicians, noting the AI's comparable reasoning abilities but also its tendency toward verbosity and higher instances of incorrect reasoning. The findings suggest LLMs could potentially augment, but not replace, human clinicians, highlighting the need for further study and careful implementation to address biases and data safety.
Jul 5, 2024·theconversation.com
The rapid advancement of the digital afterlife industry is bringing the possibility of interacting with virtual reconstructions of deceased loved ones through AI, VR, and other technologies. Companies in this niche market, such as HereAfter and MyWishes, are developing digital personas based on the data left behind by individuals, raising significant emotional and ethical questions. These technologies offer both comfort and potential psychological harm, blurring the lines between reality and simulation. Issues around consent, privacy, and the potential for misuse call for updated legal frameworks and ethical guidelines, including informed consent and data security measures, to ensure these digital interactions honor the deceased while supporting the emotional health of the living.
Jul 5, 2024·Wall Street Journal
The article from The Wall Street Journal discusses how scammers are increasingly using artificial intelligence (AI) to outsmart both consumers and financial institutions. Techniques include mimicking voices for fraud calls and creating realistic phishing emails. The advanced AI tactics present significant challenges for cybersecurity, requiring new approaches to protect sensitive information.
Jul 5, 2024·cyberscoop
Researchers at cybersecurity firm Qualys have identified a critical vulnerability in the widely used OpenSSH secure communications protocol, named "regreSSHion". This flaw, affecting nearly 14 million instances, could allow attackers to gain full access to systems and bypass firewalls, though it is challenging to exploit under typical conditions. The vulnerability, CVE-2024-6387, was re-introduced in 2020 after being fixed nearly a decade ago. While experts caution against overhyping the severity, they emphasize the importance of zero trust and mitigating risks. The bug primarily impacts older, 32-bit Linux systems and highlights the need for continued efforts toward using memory-safe languages to secure open-source ecosystems.
Jul 5, 2024·HealthExec
Geisinger Health System experienced a significant data breach affecting over 1.2 million patient records, involving unauthorized access by a terminated employee of Nuance Communications, a Microsoft subsidiary. The breach, discovered after the employee's dismissal in November 2023, prompted a delayed notification to patients due to a federal investigation. Stolen data includes personal information but not care details or social security numbers. Geisinger is offering identity protection services and is cooperating with authorities as the former employee faces federal charges. Geisinger emphasizes the importance of patient privacy and continues to address the incident.
Jul 5, 2024·Fierce Healthcare
Healthcare technology startup Fabric has acquired Walmart's telehealth business, MeMD, as Walmart closes its primary care clinics. This acquisition significantly expands Fabric's reach in the employer market, enhancing its virtual care platform and incorporating MeMD's network of 30,000 employers and 5 million employees. Fabric will leverage its advanced AI and automation technologies to improve operational efficiency and patient experience across both virtual and in-person care settings. The deal also includes MeMD's clinicians, enriching Fabric's clinical capacity and adding virtual behavioral health services. Financial details were not disclosed, but the acquisition aligns with Fabric's strategy to integrate and enhance its telehealth services amidst shifts in the virtual care market.
The evolving needs of the workplace are driving companies to reimagine the traditional internet browser for enterprise use. Originally designed for consumers, existing browsers require complex and costly measures to ensure security and functionality for business applications. To address these challenges, tech giants like Google and emerging startups such as Island and Here are developing enterprise-specific browsers with built-in security controls and improved app integration. These new tools aim to enhance productivity while reducing the need for additional security layers, with projections indicating widespread adoption by 2030. Companies like Pfizer have started integrating these solutions, citing benefits like cost savings and improved data control.
Jul 3, 2024·ITPro
Healthcare organizations worldwide are experiencing a significant increase in cyber attacks, leading to service disruptions and longer patient waiting times. A report by KnowBe4 highlighted that in the first three quarters of 2023, the healthcare sector faced an average of 1,613 attacks per week, approximately four times the global average. The financial impact of these breaches is considerable, with IBM noting an average cost of nearly $11 million per breach, making healthcare the most expensive sector for cyber attacks. The human cost is also notable, as evidenced by the cancellation of thousands of procedures in NHS England following an attack on Synnovis. In the United States, half of all reported cyber intrusions in 2024 targeted North American institutions, with healthcare being the third-most targeted sector. Despite the frequency and severity of these attacks, many healthcare organizations remain underprepared; 27% do not have dedicated ransomware defense programs. The high value of medical data makes the sector particularly attractive to hackers, underlining the urgent need for improved cybersecurity measures.
Jul 3, 2024·The Record
Jen Easterly, director of the U.S. Cybersecurity and Infrastructure Security Agency (CISA), expressed skepticism about the feasibility of a U.S. ban on ransomware payments during her appearance at the Oxford Cyber Forum. Despite efforts to reduce ransomware attacks, Easterly noted the difficulty in gauging success due to the lack of a baseline. She highlighted the new Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) as a tool to better understand the cyberattack ecosystem. Easterly also endorsed CISA’s pre-ransomware notification initiative and emphasized the need for a Secure-by-Design approach to effectively combat ransomware. Comparisons were made to similar regulatory efforts in the UK and Europe.
Jul 3, 2024·inews
The UK Home Office was cautioned about a significant risk of ransomware attacks months prior to a major cyber-attack on the NHS by Kremlin-protected hackers, according to a report by the Joint Committee on National Security Strategy (JCNSS). Despite these warnings, the NHS's outdated IT infrastructure and insufficient security measures made it particularly vulnerable. The attack, linked to a Russian hacker group known as Qilin, resulted in canceled medical procedures and the public release of sensitive patient data. The Home Office's prioritization of other issues over cybersecurity was criticized, and a transfer of responsibility to the Cabinet Office was suggested. The attack indicated an escalation in Russia’s cyber warfare tactics, prompting calls for the UK to bolster its cybersecurity defenses and international cooperation to combat such threats. The government has committed to further investments and collaborations to improve resilience, amidst ongoing investigations into the incident.
Jul 3, 2024·bankinfosecurity
The article discusses the efforts by major healthcare industry groups, including the College of Healthcare Information Management Executives (CHIME) and the American Medical Association (AMA), to urge the U.S. Department of Health and Human Services' Office for Civil Rights (HHS OCR) to provide clear guidance on breach notification responsibilities following a massive data breach at Change Healthcare. This breach impacted millions of patients and disrupted services for healthcare providers. While Change Healthcare has offered to handle the breach notifications, industry groups seek assurances that the regulatory burden will fall on Change Healthcare rather than the affected healthcare providers. Despite HHS OCR’s guidance allowing such delegation, covered entities remain ultimately responsible for ensuring notifications are made, prompting ongoing requests for further clarification.
Jul 3, 2024·SecurityWeek
Microsoft has expanded its notification pool regarding the Midnight Blizzard hack, a cyber-attack attributed to the Russian government. The company is alerting more customers about stolen emails involving their accounts, facilitated by a secure portal for reviewing compromised data. Earlier reports from Microsoft identified Midnight Blizzard, also known as Nobelium or Cozy Bear, as being engaged in an ongoing attack, leveraging stolen emails for further cyber intrusions. Social media posts from affected customers highlight the widening impact of the breach. These revelations come as part of Microsoft's commitment to transparency and proactive customer assistance.
Jul 3, 2024·publication
The article outlines significant political and judicial developments affecting the U.S. healthcare landscape. The first focal event is a highly-viewed presidential debate between President Biden and former President Trump, drawing significant public and media discourse but notably low engagement from the younger demographic, which shows a growing disillusionment with the political system. The second major point discusses critically important decisions by the Supreme Court, including rulings on federal agencies' power, emergency room abortions, the Purdue Pharma opioid settlement, and abortion medication access. These rulings significantly impact healthcare regulation and indicate a potential shift in power from federal to state governance. Additionally, the article stresses the importance of engaging young adults in healthcare reform and underscores the need for dynamic strategic planning within healthcare organizations, as incrementalism may no longer suffice in a rapidly evolving landscape.
Jul 3, 2024·HealthTech Magazine
Large Language Models (LLMs) have rapidly found valuable applications in healthcare, from improving patient communication and documentation to analyzing unstructured data for clinical insights. The integration of LLMs with Electronic Health Records (EHR) systems enhances their utility but also introduces challenges in maintaining accuracy and addressing biases. Developers and healthcare providers must implement safeguards to ensure ethical usage and minimize risks like data privacy breaches and incorrect LLM outputs. Ongoing evaluations and user feedback are essential to fully realize the potential of LLMs while mitigating their limitations.
Jul 1, 2024·Becker's Hospital Review
UC Davis Health, in partnership with Best Buy Health’s Current Health platform, is implementing a remote patient monitoring program to enhance chronic disease management, particularly hypertension. Despite advancements, effective blood pressure control remains challenging for many patients. The program will utilize blood pressure cuffs and scales to transmit real-time data to UC Davis Health's electronic medical records, improving patient and physician collaboration. Best Buy Health was chosen for their comprehensive and accessible monitoring solutions, as well as their robust logistical and technical support, allowing clinical teams to concentrate on patient care.
Jul 1, 2024·Healthcare Finance News
Walgreens plans to close up to 25% of its underperforming retail stores as the current pharmacy model becomes unsustainable, according to CEO Tim Wentworth. With the shift in customer demographics and preferences, only 75% of U.S. stores contribute to segment Adjusted Operating Income (AOI), necessitating store closures over the next three years. Walgreens also faces reimbursement pressure from pharmacy-benefit managers and lower script market growth compared to pre-pandemic levels. To cut costs, Walgreens will reduce its stake in VillageMD and close unprofitable clinics, aiming to better align with long-term profitability strategies.
Jul 1, 2024·Fierce Healthcare
Lurie Children's Hospital of Chicago faced a significant cybersecurity breach in January, leading to unauthorized access to the personal information of nearly 800,000 individuals. The hospital's electronic systems were temporarily taken offline to mitigate the threat, causing disruptions in patient services. By late May, all patient-facing systems were reactivated, though MyChart functions are still being updated. The hospital did not pay a ransom and has offered affected individuals complimentary access to information protection services. An ongoing investigation, in collaboration with law enforcement, aims to enhance future cybersecurity measures.