Search site
Find podcasts, news, articles, webinars, and contributors in one search.
Health IT News
Browse by topic
Most-read stories in the last 7 days
4,419 stories
May 1, 2024·Cybersecurity Dive
Microsoft is grappling with the consequences of long-ignored security warnings, facing significant reputational damage after a series of breaches linked to nation-state actors. The software giant, known for its dominance in the cloud and enterprise markets, has suffered from two major security incidents affecting its core platforms and exposing sensitive data from top executives, corporate customers, and federal agencies. Despite Microsoft's stature and vast security customer base, critics argue that the company's focus on market dominance and revenue-generating security investments has led to inadequate attention to fundamental security practices. The recent breaches and government directives highlight the urgent need for Microsoft to revamp its security approach, moving towards zero-trust initiatives and more substantial infrastructure investments to fend off future attacks and reestablish trust amongst its vast user base.
May 1, 2024·BankInfoSecurity
In testimony before Congress, UnitedHealth Group CEO Andrew Witty described the decision to pay a ransom following a cyberattack on Change Healthcare as one of his toughest choices. The attack, perpetrated by cybercriminals exploiting a Citrix portal without multifactor authentication, led to significant disruption and a complex recovery involving major tech firms. The absence of multifactor authentication was pinpointed as a crucial vulnerability. Despite paying the ransom, the company faced questions about possibly paying multiple ransoms and its efforts to protect sensitive health information. This incident has sparked broader discussions on cybersecurity in the healthcare industry, with experts urging the adoption of phishing-resistant multifactor authentication to prevent similar attacks.
May 1, 2024·BleepingComputer
UnitedHealth has disclosed that its subsidiary, Change Healthcare, was victim to a BlackCat ransomware attack after attackers used stolen credentials to access the company's Citrix remote access service, which lacked multi-factor authentication. The breach, occurring in late February 2024, led to significant operational disruptions, affecting vital services such as payment processing and insurance claims, with financial damages estimated at $872 million. UnitedHealth later admitted to paying a ransom in an effort to protect compromised data, despite the details of the attack not being fully disclosed. The organization has undertaken extensive remediation efforts, including system upgrades and network rebuilds, aimed at restoring affected services and enhancing security measures. Additionally, an update mentions that stolen Change Healthcare employee Citrix credentials were detected on February 8 by Hudson Rock's threat intelligence platform, though it's unclear if these credentials were directly linked to the ransomware attack.
May 1, 2024·MIT News
The U.S. Securities and Exchange Commission (SEC) now mandates public companies to disclose the cybersecurity expertise present within their boards of directors, aiming to enhance oversight and management of cyber risks. This regulatory change underscores the growing importance of cyber resilience amid increasing data breaches and emphasizes the role of board members in ensuring organizations are prepared for cyberattacks. Keri Pearlson's research highlights the shift from a protection-oriented cybersecurity approach to one focused on resilience, proposing the adoption of a Board Level Balanced Scorecard for Cyber Resilience (BSCR) to facilitate strategic discussions on cyber risk management. This scorecard helps quantify and address risks across technology, financial, organizational, and supply chain dimensions, aiming to foster a more resilient business approach to cyber threats. Pearlson also advocates for executive education to bolster non-technical leaders' understanding of cybersecurity, emphasizing the need for boards to foster cyber resilience rather than solely focusing on preventive measures.
Apr 30, 2024·LinkedIn
David Carmouche of Walmart Health expresses deep disappointment over the announcement to close Walmart health centers and virtual care services. The initiative aimed to improve access, convenience, and affordability in healthcare but is now winding down operations, impacting many employees who were central to this mission. Despite the setback, Walmart Health remains committed to supporting the transition of patient care to new providers. The company's leaders, acknowledging the contributions and dedication of their teams, expressed deep gratitude and a continued belief in the potential for large retailers to make significant impacts in healthcare. While the project did not end as hoped, the achievements and strong relationships formed along the way were highlighted as points of pride and celebration.
Apr 30, 2024·paulkeckley.com
The Federal Trade Commission (FTC) has passed a new rule that prohibits employers from using non-compete agreements with workers, except for a narrower application to top executives. This FTC final rule is part of a broader scrutiny of non-competes which research shows tend to impede market competition, suppress worker earnings, and hinder business innovation. Predictably, the rule has generated significant backlash, particularly from healthcare organizations, leading to lawsuits and contention about the FTC’s authority. With staggered enforcement dates for existing and new agreements, the rule reflects an intent to increase labor market fluidity and decrease healthcare costs, aligning with empirical research promoting economic efficiency and competition. However, its immediate future is clouded by legal challenges and dissenting views from within various industry sectors, especially healthcare, as debates about its broader implications continue to unfold.
Apr 30, 2024·PYMNTS
OpenAI is reportedly on the brink of releasing GPT-5, a significant advancement in its series of generative pre-trained transformers, enhancing capabilities in personalized communication, error reduction, and multimedia content handling. Experts anticipate that this model will not only improve AI's language processing abilities but also its application across various fields including commerce, law, and more, by providing more sophisticated interaction and automation capabilities. Concerns, however, loom regarding privacy, the handling of sensitive data, and the potential for increased misinformation if appropriate safeguards aren't established.
Apr 30, 2024·The Register
Researchers at the University of Illinois Urbana-Champaign have discovered that OpenAI's GPT-4 large language model can autonomously exploit real-world security vulnerabilities when provided with CVE advisories. The model successfully exploited 87% of tested one-day vulnerabilities, significantly outperforming other models and open-source vulnerability scanners. Despite the impressive performance, the success rate drastically reduces when access to CVE descriptions is restricted. The study highlights the potential for future models to facilitate even more effective exploits, stressing the need for proactive security measures rather than relying on security through obscurity.
Apr 30, 2024·Molly White Newsletter
In Molly White's newsletter "AI isn't useless. But is it worth it?", she explores her complex views on artificial intelligence, likening her skepticism of AI to her criticisms of blockchain technology. White discusses the limited practicality of AI tools, which, while useful in specific scenarios such as simple coding tasks and proofreading, often fail to meet the grandiose claims of AI companies. She stresses the significant ethical, environmental, and social costs of developing these technologies. Despite finding personal utility in some applications of AI, she questions whether the broader impacts and the hype surrounding AI justify its use, especially in light of its potential to replace human labor and generate misleading information. Ultimately, White remains critical of the overhyped promises and the dangerous externalities of rapidly advancing AI technology.
Apr 30, 2024·healthexec.com
Cerebral, a virtual mental health platform, has agreed to a $7.1 million settlement with the Federal Trade Commission (FTC) for mishandling sensitive patient data and sharing it with advertisers. The settlement includes utilizing $5.1 million of the fine for partial refunds to users who struggled to cancel services due to deceptive practices. Founder Kyle Robertson is facing potential personal charges, as he was deeply involved in the platform's problematic policies. The FTC's complaint highlighted the platform's failure to safeguard patient privacy, exposing sensitive health information to third-party advertisers and employing questionable patient engagement tactics. As part of the resolution, Cerebral is banned from using health information for advertising and must overhaul its privacy and data security protocols. This action follows a rare self-reporting to regulators by Cerebral in 2022 amidst leadership changes, with the company expressing a commitment to moving forward with enhanced security measures while still offering its services within new regulatory guidelines.
Apr 30, 2024·Apple Newsroom
Apple has launched the Apple Vision Pro, introducing a revolutionary platform for health app developers through visionOS. This new technology provides an “infinite canvas” for creating spatial experiences that seamlessly integrate digital content with the physical environment, transforming healthcare delivery in settings ranging from clinics to home care. Developers now have the ability to craft applications that were previously unfeasible, focusing on critical areas such as clinical education, surgical planning, medical imaging, and behavioral health. The suite of apps designed for the Vision Pro—including surgical planning tools like Stryker’s myMako and educational platforms such as CyranoHealth—demonstrates the extensive possibilities for enhancing patient care and professional training. Apple's advancements signify a shift towards more interactive and immersive healthcare technologies that promise to improve outcomes and operational efficiency across the medical field.
Apr 30, 2024·Fierce Healthcare
Optum, a subsidiary of UnitedHealth Group, has executed sweeping layoffs and shuttered its Optum Virtual Care telehealth service, as confirmed by the company. Amid these layoffs, naviHealth CEO Harrison Frist will be stepping down, to be replaced by Heather Jarrett, though Frist will remain in an advisory role temporarily. The layoffs span across various Optum divisions, including a sizable reduction at Landmark Health. This organizational shake-up occurs in a context of broader industry pressures such as a class action lawsuit addressing claim denials and legislative scrutiny over large-scale acquisitions and cyberattack repercussions, highlighting significant challenges within Optum’s operation and management.
Apr 30, 2024·healthcare-in-europe.com
Generative AI is significantly enhancing healthcare beyond basic applications, as highlighted by Dr. Shez Partovi of Philips. This technology enables the translation of complex medical notes into simpler language, improving patient understanding and engagement with their own health records. Furthermore, it promises to streamline physician review of patient histories by quickly synthesizing relevant information, thus allowing more time for patient care. Additionally, generative AI aims to optimize hospital workflows through precise, AI-generated overviews of logistical information, aiding in effective management and planning. Despite these advancements, the necessity of keeping human experts in the loop remains crucial to ensure accuracy and mitigate risks associated with AI-generated errors.
Apr 30, 2024·Becker's Hospital Review
The Federal Trade Commission's (FTC) recent decision to ban noncompete agreements poses significant changes for the nation's largest Electronic Health Records (EHR) vendor, Epic Systems. This rule, under scrutiny in court, has been challenged by former employees and health systems affected by Epic's comprehensive noncompete clauses. These clauses have historically restricted career advancement for individuals in healthcare and technology sectors and limited health systems' ability to hire ex-Epic talent, involving around 4,500 competitors and customers, including nine health systems. While Epic announced it is evaluating the implications of the FTC's ban and stresses the importance of protecting high-tech intellectual property, the decision could potentially end their restrictive noncompete agreements, altering the landscape of employment and competition within the health technology domain.
Apr 30, 2024·Axios
Microsoft CEO Satya Nadella emphasized the company's intensified focus on cybersecurity during a recent earnings call, highlighting a strategic shift to prioritize security due to growing concerns after several high-profile cyberattacks on its products. This comes in response to both a U.S. Cyber Safety Review Board report criticizing Microsoft's vulnerability to a Chinese espionage effort and internal adjustments following a Russian email hack. Despite these challenges, Microsoft reported a robust fiscal quarter, with significant revenue growth driven by its cloud business and AI developments, maintaining its position as a leading cloud vendor for the federal government.
Apr 30, 2024·Daily Kos
Nonprofit hospitals, traditionally focused on serving lower-income populations, are increasingly adopting concierge physician practices that charge significant membership fees for enhanced access and personalized care. This trend, exemplified by major hospitals like Northwestern Medicine and Penn Medicine, involves fees that can surpass $4,000 annually, on top of regular healthcare costs. While this model can reduce doctor workload and potentially improve care for wealthier patients, it raises concerns about exacerbating primary care shortages and increasing healthcare inequities, as it limits access to those who can afford the high fees, therefore possibly redirecting resources away from general patient care. Critics argue that this approach not only strains the availability of primary care for the average population but also prioritizes higher-income individuals, hence contradicting the foundational mission of nonprofit hospitals.
Apr 30, 2024·The Record
Seven years after a significant cyberattack disabled access to major US websites using a distributed-denial-of-service (DDoS) attack via the Mirai botnet, the UK has legislated to counter similar threats by becoming the first country to ban default guessable usernames and passwords on IoT devices. The Product Security and Telecommunications Infrastructure Act 2022 sets new minimum security standards for IoT device manufacturers, requiring them to inform consumers about the duration of security updates and forbidding weak default passwords to reduce the risk of cyberattacks. This legislation, enforced by the Office for Product Safety and Standards, also subjects non-compliant manufacturers to fines or recalls, highlighting a proactive approach to enhancing cybersecurity in an increasingly connected world.
Apr 30, 2024·BankInfoSecurity
Attorney Lynn Sessions of BakerHostetler revealed that approximately half of their healthcare sector clients end up paying ransom in ransomware attacks, despite initial reluctance. Speaking with Information Security Media Group, Sessions highlighted that the unique operational requirements of the healthcare sector, including the need to maintain patient care 24/7, make it particularly vulnerable to such attacks. The firm's 10th annual Data Security Incident Response Report, which analyzes over 1,150 security incidents across various sectors, indicates a trend of double-extortion techniques being used against healthcare organizations. Sessions advised against paying for data suppression alone, noting the complications that can arise even after paying ransoms, such as data still being leaked. She emphasized that paying a ransom does not exempt an entity from HIPAA breach reporting obligations or from potential lawsuits, underlining the complex decision-making process involved in responding to ransomware attacks and the importance of preparedness and comprehensive security measures.
Apr 29, 2024·SC Magazine
The recent cyberattack on Change Healthcare, which is part of UnitedHealth Group, has highlighted significant vulnerabilities in the healthcare sector's approach to cybersecurity. The attack led to the compromise of patient data and resulted in a predicted loss of $1.6 billion for UnitedHealth, though this is not expected to significantly affect their overall financial projections for the year. Despite the financial buffer of larger companies like UnitedHealth, smaller healthcare providers have suffered extensively, facing severe operational and financial challenges similar to those experienced during the COVID-19 pandemic. This incident underscores the critical need for healthcare organizations to conduct thorough business impact analyses and establish robust cybersecurity measures, highlighting the inadequacy of current strategies largely reliant on cyber insurance and the absence of preventive planning.
Apr 29, 2024·DHInsights
The article delves into the repercussions of a cyberattack on Change Healthcare, detailing the ensuing financial crisis for healthcare providers. Dr. Christine Meyer's experience of plummeting bank balances and the dire need to make payroll encapsulates the broader impact on healthcare facilities, which are facing substantial daily losses. Meyer's exploration of a Home Equity Line of Credit (HELOC) loan highlights the desperate measures some are taking to sustain operations. The article criticizes United Healthcare and its subsidiary Optum for their inadequate and criticized financial assistance response, as well as highlights broader concerns about cybersecurity and the potential misuse of data within the healthcare sector. It also touches on the broader implications of such cyberattacks on national security and the healthcare system, considering healthcare's significant share in the U.S. economy. The article concludes by noting the lasting impact of the cyberattack on providers and the continued struggle for recovery, underscoring the far-reaching consequences of this incident on national health care continuity and financial stability.