Search site
Find podcasts, news, articles, webinars, and contributors in one search.
Health IT News
Browse by topic
Most-read stories in the last 7 days
4,419 stories
Jun 6, 2024·MedCity News
The article discusses the rising cybersecurity threats in the healthcare sector, highlighting major incidents like the cyberattack on Optum’s Change Healthcare unit, which impacted 85 million patient records, and the attack on Ascension, which caused significant operational disruptions. These breaches are not only costly, with the healthcare industry facing the highest average breach costs for over a decade, but they also compel healthcare providers to prioritize cybersecurity. Executives from various health systems, including MD Anderson Cancer Center, Yale New Haven Health, CommonSpirit Health, Allegheny Health Network, and UPMC, emphasize the increasing sophistication of cyber threats and the need for enhanced cybersecurity measures. They argue for more investment in cybersecurity, better management of third-party risks, extensive staff training on cyber hygiene, and potential government assistance to bolster defenses against cyberattacks.
Jun 5, 2024·MobiHealthNews
A Yale study published in *Clinical Imaging* examined how ChatGPT models GPT-3.5 and GPT-4 simplified 750 radiology reports based on the prompt, "I am a ___ patient. Simplify this radiology report," with various racial identifiers filled in. The results showed significant differences in the reading grade level of the outputs depending on the race specified. For example, GPT-3.5 produced higher-grade reading levels for White and Asian categories compared to Black, African American, and American Indian categories. Researchers found these differences alarming and stressed the need for vigilance against bias in AI-generated medical information. This aligns with broader industry efforts to ensure responsible AI development, including the formation of the Frontier Model Forum by major tech companies and the growing use of ChatGPT in healthcare by companies like Moderna. Despite its potential, experts, including those from Microsoft, warn about the complexities of addressing AI bias in healthcare applications.
Jun 5, 2024·Psychology Today
In the article "The Digital Self: The AI Apocalypse We're Not Talking About," John Nosta highlights a less-discussed but significant impact of AI on human self-perception. As AI systems surpass human performance in various cognitive tasks, they expose the limits and flaws of our biological intelligence—challenging our long-held belief in our intellectual superiority. This shift provokes an existential crisis, not of annihilation, but of diminishing human ego and value. Instead of succumbing to insecurity, Nosta suggests embracing AI as a tool for augmenting human potential and redefining our value beyond intellectual dominance. The real apocalypse, he argues, is one of anthropocentric arrogance, not existential destruction.
Jun 5, 2024·publication
In response to a recent hyperbolic article from Business Insider criticizing Oracle's efforts in modernizing the Department of Veterans Affairs' electronic health record (EHR) system, Ken Glueck of Oracle argues that the piece disregarded major advancements and improvements made under Oracle’s leadership. He points out that the outdated VistA system, which had vulnerable and fragmented data, is being replaced with a secure, interoperable EHR platform used successfully by over 3,800 Department of Defense locations. Glueck highlights various inaccuracies and omissions in the Business Insider article, emphasizing Oracle's commitment to transforming healthcare IT infrastructure using advanced cloud and AI technologies, resulting in enhanced patient care and efficiency.
Jun 5, 2024·Healthcare Brew
Dollar General has ended its partnership with mobile care provider DocGo, discontinuing a pilot program that offered mobile health clinics at three stores in Tennessee. The move is part of a broader trend among retailers—including Walmart and Walgreens—who are withdrawing from primary care operations due to the challenges of low reimbursements, high operating costs, and workforce shortages. Dollar General plans to continue offering health and wellness products in its stores but will no longer pursue its initial goal of becoming a "health destination." This shift follows similar strategic changes by competitors, reflecting the broader difficulty of achieving profitability in the primary care space.
Jun 5, 2024·TechRadar
OpenAI's ChatGPT experienced a major service outage impacting the web version, mobile app, and new Mac app on June 4, 2024. The outage began around 2:30am ET and lasted over five hours, affecting millions of users who rely on the AI for various tasks. OpenAI acknowledged the issue and implemented a fix, which is being monitored to ensure stability. While the exact cause remains unclear, the situation recalls previous service disruptions. Users are gradually regaining access, though some still report issues.
Jun 5, 2024·thehackernews
Microsoft has highlighted the urgent need to secure internet-exposed operational technology (OT) devices following a rise in cyber attacks since late 2023. Such attacks can manipulate critical parameters in industrial processes, potentially causing malfunctions and outages. OT systems' vulnerabilities are often due to weak passwords and outdated software, making them easy targets. Recent advisories from Rockwell Automation and the U.S. Cybersecurity and Infrastructure Security Agency (CISA) stress the heightened risk amidst geopolitical tensions, with pro-Russia hacktivists targeting control systems in North America and Europe. To mitigate these risks, organizations are urged to enhance their OT security hygiene, reduce attack surfaces, and implement zero trust practices. Additionally, Claroty has reported on Fuxnet, a new malware used to attack Russian infrastructure, highlighting the evolving threat landscape for OT systems.
Ticketmaster recently reported a data breach affecting over 500 million users, attributing the issue to security weaknesses in Snowflake’s cloud database environment. Snowflake denies responsibility, suggesting that the breach resulted from credential stuffing attacks rather than vulnerabilities in their system. Third-party cybersecurity firms CrowdStrike and Mandiant supported Snowflake’s preliminary findings, indicating that the breach likely involved single-factor authentication and credentials obtained from previous malware incidents. While a compromised demo account was found, it did not contain or provide access to sensitive data, and it was not protected by multi-factor authentication.
Jun 5, 2024·Forbes
In response to recent zero-day vulnerabilities and security threats, Google has mandated urgent updates for its Chrome browser. All users, including federal employees, are required to apply updates by June 6 to protect against critical exploits, such as memory issues and vulnerabilities in the Chromium Visuals and V8 Engine. U.S. government agencies have already updated their systems, with additional deadlines looming for other known exploits. Furthermore, users are cautioned against the potential risks of cookie theft through malicious plugins and the importance of verifying the authenticity of installed extensions. Despite concerns over ad blockers affected by the transition from Manifest V2 to V3, the security updates remain essential. If a system no longer supports Chrome updates, discontinuation of use is advised to avoid exploitation.
Jun 4, 2024·ONC 20th Anniversary Commemoration
The Office of the National Coordinator for Health Information Technology (ONC) was created in 2004 by an executive order from President George W. Bush to develop a nationwide interoperable health IT infrastructure. In 2005, ONC awarded multimillion-dollar contracts to foster public-private collaboration and accelerate health IT adoption. The Federal Health IT Strategic Plan 2008-2012 aimed to transform the healthcare system by guiding federal agencies and stakeholders’ efforts. The 2009 HITECH Act bolstered health IT adoption, reduced costs, and empowered patients, while also legally establishing ONC. From 2010 onward, ONC launched various programs, certifications, and frameworks to support health IT implementation and interoperability, including the S&I Framework and the voluntary ONC Health IT Certification Program. By 2011, a new strategic plan guided health IT adoption, and the 2014 Edition Final Rule introduced enhanced certification criteria. In 2014, ONC outlined a 10-year vision for interoperable health IT infrastructure, and by 2015, it released roadmaps to guide nationwide and federal IT initiatives, emphasizing standards and reducing information blocking. The 2016 21st Century Cures Act focused on interoperability and patient access to health information,
Jun 4, 2024·Hudson Rock
This research uncovers a significant data breach involving cloud storage provider Snowflake. A threat actor behind this breach revealed that they used stolen credentials to access a Snowflake employee's ServiceNow account, bypassing security measures and generating session tokens to exfiltrate a large amount of data. The breach, which impacted approximately 400 companies including customers of Ticketmaster and Santander Bank, has led to data being sold on cybercrime forums. Documents provided by the threat actor confirmed the extent of their access. The actor attempted to blackmail Snowflake for $20 million, but the company was unresponsive. Snowflake is investigating the breach, which was part of a broader pattern of identity-based cyberattacks. Hudson Rock continues to monitor and report on the developments of this case.
Jun 4, 2024·aha.org
The Department of Health and Human Services (HHS) announced that hospitals and health systems impacted by the February 22 Change Healthcare cyberattack can require UnitedHealth Group to notify patients if their data was compromised. HHS’ Office for Civil Rights Director Melanie Fontes Rainer emphasized the importance of prioritizing HIPAA breach notifications. The American Hospital Association (AHA) expressed satisfaction with the decision, noting it aligns with their earlier request and helps avoid confusion and additional costs for hospitals. According to updated FAQs, if Change Healthcare handles the breach notifications as per HIPAA and HITECH standards, the affected entities will have no further notification obligations. UHG CEO Andrew Witty had previously agreed to this approach during May hearings with Senate and House committees.
Jun 4, 2024·Forbes
Healthcare delivery organizations (HDOs) are increasingly vulnerable to cybersecurity threats, with a 40% rise in reported breaches noted early this year, causing significant financial loss and impacting care delivery. High-profile ransomware attacks have crippled organizations like the University of Vermont Medical Center and Scripps, incurring million-dollar losses. Studies indicate that such cyber incidents jeopardize patient safety by delaying procedures and increasing mortality rates. To combat this, HDOs must strengthen their cybersecurity foundation through three main strategies: formalizing cybersecurity governance within a standing committee, establishing an integrated cyber and enterprise risk program, and measuring the effectiveness of their cybersecurity initiatives. These steps emphasize board-level accountability and require comprehensive oversight to ensure cybersecurity risks are effectively managed across all aspects of their operations.
Jun 4, 2024·The Atlantic
The article discusses the increasing tendency of patients, particularly those who have experienced multiple miscarriages, to conduct their own research online and gather information from various sources before consulting their doctors. This self-gathered information, often compiled from Google, WebMD, support groups, and personal networks, can result in a substantial amount of data that patients bring to their medical appointments. The article underscores the need for healthcare providers to adapt by finding ways to effectively integrate patient-led research into the clinical decision-making process, fostering a collaborative atmosphere where patients and doctors work together for the best outcomes.
Jun 4, 2024·Public Citizen
Technological advancements in artificial intelligence (AI) have significantly increased lobbying activity in recent years, affecting a broad range of industries beyond just technology. Public Citizen's analysis of five years of House lobbying disclosure data (2019-2023) shows a sharp rise in AI-related lobbying, with more than 3,400 lobbyists engaging in AI issues in 2023 alone—an increase of 120% from the previous year. Lobbying efforts have not been limited to technology firms but have also involved industries such as financial services, healthcare, and defense. The White House was the most targeted entity, attracting more than 1,100 lobbyists in 2023, reflecting heightened interest following the Biden administration's executive order on AI. Although 85% of the lobbyists represented corporate interests, discussions also included various non-corporate stakeholders, illustrating extensive efforts to shape AI regulations across federal agencies.
Jun 4, 2024·Healthcare IT News
UCSF Health, in collaboration with the UCSF Division of Clinical Informatics and Digital Transformation, has received a $5 million donation from Ken and Kathy Hao to develop the Impact Monitoring Platform for AI in Clinical Care (IMPACC). This platform aims to continuously evaluate the efficacy and safety of AI tools used in clinical settings, ensuring they meet intended outcomes and addressing potential risks such as increased health disparities. Led by Julia Adler-Milstein and Dr. Sara Murray, the initiative will initially test IMPACC on current AI tools to provide real-time performance insights. This project addresses the critical need for ongoing AI monitoring protocols in healthcare, offering a scalable solution for assessing the real-world impact of these technologies.
Jun 4, 2024·Axios
Senators Eric Schmitt (R-Mo.) and Ron Wyden (D-Ore.) have voiced serious concerns regarding the Pentagon's planned investment in upgrading Microsoft products, arguing that the Department of Defense should consider a multi-vendor approach to enhance competition, reduce costs, and improve cybersecurity outcomes. Their letter to Pentagon CIO John Sherman questions the reliance on Microsoft, especially in the wake of recent cyberattacks linked to nation-states. The plan, which involves upgrading to Microsoft's E5 license as part of a zero-trust strategy, is under scrutiny for possibly perpetuating a "failed strategy." The senators seek detailed responses from the Pentagon and readiness for upcoming legislative reviews. House Speaker Mike Johnson (R-La.) has received unexpected mentorship from former Speaker John Boehner, a figure from a previous era of Republican leadership, to navigate the complexities of passing critical aid packages for Israel and Ukraine despite opposition from the party's far-right faction. This rare alliance highlights a bridge between current hard-right GOP members and the more traditional, pre-Trump Republican leadership. Hunter Biden is set to begin trial on Monday for three felony gun charges, carrying a potential maximum sentence of 25 years in prison. This case, one of two trials Biden faces this year, is
Jun 3, 2024·SC Magazine
Senate Finance Committee Chair Ron Wyden has called on the Federal Trade Commission and Securities and Exchange Commission to investigate UnitedHealth Group's cybersecurity shortcomings, following a significant ransomware attack on Change Healthcare. The attack has been linked to UnitedHealth Group's hiring of Steven Martin as chief information security officer, a position he assumed without full-time cybersecurity experience. Wyden emphasized that UnitedHealth Group's CEO and board of directors should be accountable for this decision and the company's inadequate cyber defenses, as opposed to solely blaming Martin. Fastly has identified vulnerabilities in three WordPress plugins that could expose nearly 6 million sites to unauthenticated cross-site scripting (XXS) attacks, enabling threat actors to inject malicious scripts. Everbridge, a U.S. enterprise risk intelligence and crisis management software provider, confirmed a security breach of its corporate systems caused by an attack exploiting information from an earlier phishing campaign targeting its employees. A cyberattack in October 2023 affected more than 600,000 internet routers across several Midwest states by distributing malicious firmware, leading to significant disruptions for an unnamed U.S. telecommunications firm.
Jun 3, 2024·therecord.media
Senator Gary Peters (D-MI) has proposed draft legislation to establish a new interagency committee for streamlining and coordinating federal cybersecurity regulations. The aim is to reduce the regulatory burden on industries by making compliance easier. If passed, the Office of the National Cyber Director (ONCD) would lead this committee, with representatives from relevant regulatory agencies. The committee would identify and address inconsistencies and redundancies in current regulations, potentially implementing aligned changes within a year. While some fear the bill’s attempt to centralize authority in ONCD might face challenges from various congressional committees, industry advocates and experts underscore its necessity.
The National Institute of Standards and Technology (NIST) has contracted an external vendor to address the backlog of software and hardware vulnerabilities in the National Vulnerability Database (NVD). This backlog emerged after NIST announced cutbacks in February 2023, causing delays in the enrichment and processing of new vulnerabilities. NIST, working with the Cybersecurity and Infrastructure Agency (CISA), aims to resume previous processing rates within a few months and clear the backlog by the end of the fiscal year. NIST's funding decreased by 12% this year, affecting its capacity. To improve the NVD program sustainably, NIST is updating technology and processes and emphasizes the need for automation in vulnerability management. CISA has initiated the “Vulnrichment” effort to enhance the information available on vulnerabilities. Experts and former officials stress that restoring NVD functionality is crucial for maintaining cybersecurity defenses.