Search site
Find podcasts, news, articles, webinars, and contributors in one search.
Health IT News
Browse by topic
Most-read stories in the last 7 days
4,419 stories
Apr 29, 2024·HealthTech Magazine
The article explores the increasing issue of cyberattacks within the healthcare sector, emphasizing the necessity for organizations to develop cyber resilience strategies to maintain operations during and after an attack. Cyber resilience, as opposed to solely focusing on prevention, involves preparation for, response to, and recovery from cyber incidents, with a particular emphasis on minimizing downtime for critical healthcare systems and protecting patient information. The article highlights the importance of regular training, such as tabletop exercises and penetration testing, to identify security gaps and prepare for potential ransomware attacks. Furthermore, it discusses the role of backups and incident response plans in recovery efforts, as well as the utility of engaging law enforcement and cyber insurance in the aftermath of an attack. The concept of "zero trust" in managing authentication and access within healthcare IT environments is also mentioned as a foundational security approach. Overall, the piece underscores the critical nature of proactive and responsive cybersecurity measures in protecting against and mitigating the effects of cyber threats in the healthcare industry.
Apr 29, 2024·BankInfoSecurity
A federal judge has advised the dismissal of a lawsuit against the Catholic hospital chain CommonSpirit for a 2022 cyberattack and data breach affecting nearly 624,000 people, marking the second such dismissal related to this breach. Plaintiffs in these cases have struggled to establish standing, failing to demonstrate concrete harm resulting from the breach. This pattern follows a broader trend where health data breach lawsuits often falter on standing issues, despite some recent successes in similar cases against other entities. This situation highlights the challenges plaintiffs face in proving direct harm from data breaches, amid increasing litigation and substantial settlements in other instances of health data breaches.
Apr 29, 2024·Project Disco
The Cyber Safety Review Board (CSRB) issued a critical report on the Microsoft Exchange Online intrusion by a Chinese threat actor in Summer 2023, which compromised email accounts of U.S. federal agencies and officials, attributing the breach to Microsoft's significant security lapses. Highlighting the risk such monoculture poses to national security, the report suggests that while the cybersecurity efforts of the private sector should be encouraged, the federal government must also address its reliance on single vendors which exacerbates vulnerabilities. The article criticizes Microsoft's corporate culture for not prioritizing security and its payment model that puts basic security features behind a premium paywall, underscoring the broader implications for public and private sector cybersecurity. Further, it mentions potential legislative efforts to enforce cybersecurity standards and the government's procurement power as tools to drive improvements in vendor security practices.
Apr 29, 2024·The Record
The Cybersecurity and Infrastructure Security Agency (CISA) has reported positive outcomes from its Ransomware Vulnerability Warning Pilot program, launched in January 2023, aimed at notifying organizations about vulnerabilities in their internet-connected devices potentially exploitable by ransomware attackers. This initiative, a response to cyber incident reporting legislation signed by President Joe Biden in 2022 and executed by the Joint Ransomware Task Force (co-led by CISA and the FBI), has made significant strides by alerting 1,754 organizations last year, leading to remedial actions in nearly half of these cases. The program focuses on a wide range of sectors, with a significant number of notifications sent to government facilities and healthcare organizations, and has been instrumental in reducing risk exposure by targeting vulnerabilities that may not have been recognized or addressed by the organizations otherwise. Through extensive vulnerability scanning, CISA has identified millions of potential risks, narrowing them down to those actively exploited by ransomware groups, thereby increasing operational costs for these criminals and contributing to cybersecurity deterrence efforts.
Apr 29, 2024·John Moore on Linkedn
At the Oracle Health Conference, Eduardo Conrado, President at Ascension, discussed the top four priorities for national systems in which technology can add significant value, in a fireside chat with David Feinberg, MD. Highlighting areas such as workforce management, administrative burdens, and capacity concerns, Conrado emphasized the importance of effective development and change management in implementing technology solutions in healthcare. This conversation aligns with current trends and ongoing discussions in the healthcare sector about enhancing efficiency and service delivery.
Apr 29, 2024·Forbes
This article from Forbes by Robert Pearl, M.D., addresses the pervasive issue of monopolization within the U.S. healthcare sector, illustrating how hospitals and health systems reduce competition by merging, leading to higher prices, lower service quality, and less convenience for patients. It is pointed out how legal loopholes and lobbying perpetuate this issue despite potential regulatory oversight by entities like the FTC and the DOJ. The piece emphasizes that monopolistic conditions in healthcare not only hinder innovation but also increase financial burdens on patients and local governments, which must shift budget priorities to accommodate rising healthcare costs. This detrimental cycle, Pearl argues, undermines overall public health and economic efficiency.
Apr 26, 2024·MIT Sloan Management Review
The article discusses the findings from the MIT Sloan Management Review and BCG's international panel on responsible artificial intelligence (RAI), which indicates that a majority of the experts believe organizations are not adequately expanding their risk management capabilities to safely handle AI-related risks. Highlighting the challenges posed by the rapid advancement of AI technologies and the dynamic nature of associated risks, experts point out that existing risk management frameworks are often outpaced and unable to address new complexities effectively. The article also touches on the role of regulations such as the European Union’s AI Act and offers recommendations for companies to enhance their risk management practices to better meet the demands of evolving AI technologies.
Apr 26, 2024·Newsweek
Newsweek, in partnership with Statista, introduces the first ranking of the "World's Best Digital Health Companies 2024," recognizing 400 firms from 35 countries spanning seven industry segments such as diagnostics, health records, and telehealth. The rankings categorize the digital health firms based on financial performance, impact of their products and services, and online engagement, aiming to guide healthcare stakeholders in selecting the most reliable and effective digital health solutions amidst a rapidly growing market projected to reach $275 billion by 2028.
Apr 26, 2024·HIPAA Journal
The March 2024 Healthcare Data Breach Report highlights a significant increase in healthcare data breaches, with 93 reported incidents involving breaches of 500 or more records, noted as a 50% monthly and a 41% annual increase. This surge was largely attributed to a strategic cyberattack on Ernest Health that involved separate reports for each of the 31 affected hospitals. Although the overall breach numbers were high, the total number of affected individuals continued a downward trend to the lowest since January 2023. The breaches predominantly involved major hacking incidents, including a significant breach at Risa's Dental and Braces, with less frequent occurrences of unauthorized access and theft. This trend underscores the ongoing vulnerabilities in healthcare data security, particularly through network and email compromises.
Apr 26, 2024·TechCrunch
Kaiser Permanente, a major U.S. healthcare organization, is set to notify 13.4 million individuals about a data breach that resulted from sharing patient information with third-party advertisers such as Google, Microsoft, and X (formerly Twitter). The breach involved personal details including names, IP addresses, member activities, and navigation data from Kaiser’s websites and mobile apps. This incident, deemed the largest health-related data breach of 2024, has prompted Kaiser to remove tracking codes from its digital platforms and file notices with the U.S. government and California’s attorney general, as required by HIPAA regulations. Notifications to affected members are scheduled to begin in May.
Apr 26, 2024·Fast Company
Mark Sullivan's article "Why we may be headed for a generative AI winter" in Fast Company discusses concerns around the diminishing returns and unmet expectations surrounding generative AI. Despite initial excitement and some productivity gains in specific sectors like graphic design and legal research, broader productivity impacts and significant performance improvements remain elusive. Companies have invested heavily in AI infrastructures but are experiencing complex challenges and slow ROI realization. Key industry figures, including OpenAI’s executives, have acknowledged the gap between current capabilities and heightened expectations, hinting at a potential cooling period or "AI winter" where the initial enthusiasm for generative AI might significantly wane. Additionally, independent agent-based AI developments are underway but are still far from delivering substantial outcomes.
Apr 26, 2024·AI in Healthcare
A recent survey conducted by Wolters Kluwer Health reveals that over two-thirds of U.S. physicians have grown more trusting of generative AI (GenAI) over the past year, appreciating its potential to save time and improve health care. Approximately 40% of physicians are now ready to use GenAI at the point of care, provided they trust the tool in question. Key benefits recognized include time savings in accessing and summarizing medical information and enhancing care team efficiency. The survey also highlights a critical need for transparency about the sources and creation of GenAI content, with the majority of physicians requiring assurance that the data used by GenAI tools are provided by medical professionals. Despite these positive attitudes among healthcare providers, there remains a notable skepticism among patients regarding GenAI's application in healthcare.
Apr 26, 2024·IT Brew
A report from cybersecurity firm Sophos highlights a surge in low-cost, basic ransomware, termed as 'junk-gun ransomware,' making it both accessible for aspiring cybercriminals and challenging for cybersecurity defenses. From June 2023 to February 2024, Sophos identified 19 types of such ransomware, which were inexpensive and simply constructed, some even lacking advanced features. This trend not only lowers the entry barrier for attackers, with some ransomware being available for free or at minimal cost, but also poses detection and monitoring challenges for cybersecurity professionals, due to the small number and low cost of these malicious software versions. Moreover, these rudimentary ransomware varieties evade the traditional Ransomware as a Service (RaaS) models' commission structures, indicating a shift in the cybercrime marketplace.
Apr 26, 2024·CyberScoop
The Cybersecurity and Infrastructure Security Agency (CISA) is set to fully implement an automated vulnerability warning system by the end of the year, designed to notify organizations about software vulnerabilities being leveraged by ransomware groups. This initiative, which is currently in its pilot stage and falls under the mandates of the Cyber Incident Reporting for Critical Infrastructure Act of 2022, seeks to diminish ransomware attacks by encouraging the patching of vulnerable systems before they are compromised. Announced by CISA Director Jen Easterly, the program has already issued over 2,000 warnings since its inception last year and integrates CISA's inventory of exploited vulnerabilities and common misconfigurations tied to ransomware incidents. This effort is in response to the growing threat of ransomware attacks, exemplified by a recent significant breach that affected the U.S. healthcare system, highlighting the urgency of addressing such vulnerabilities.
Apr 26, 2024·BankInfoSecurity
The Department of Health and Human Services (HHS) Office for Civil Rights (OCR) has issued guidance indicating that it has not yet received mandatory HIPAA breach reports from Change Healthcare or its parent company UnitedHealth Group (UHG) following a significant cyberattack. The guidance underscores the requirement for HIPAA-covered entities and their vendors to report breaches of protected health information (PHI) within 60 days of discovery for incidents affecting 500 or more individuals. The notice also discusses the obligations of these entities to notify affected individuals and outlines the unclear timeline for when Change Healthcare and UHG discovered the breach and the extent of their notification responsibilities. Further, HHS has initiated an investigation into the incident due to its broad impact on patient privacy and healthcare provider operations, emphasizing the importance of compliance with HIPAA rules in the wake of the cyberattack's implications.
Apr 25, 2024·Krebs on Security
A division head of the Russian Federal Security Service (FSB) was sentenced to nine years in a penal colony for accepting a $1.7 million bribe to overlook the activities of a cybercrime group involved in hacking thousands of e-commerce sites, selling stolen payment card details online. Russian authorities dismantled this operation in 2022, arresting six members and seizing several carding shops, including Trump’s Dumps, which promised to "make credit card fraud great again." The IT firm Get-net LLC, linked to one of the arrested and leased services to the FSB, was implicated in the registration of the seized domains. Following an investigation that revealed the FSB head’s promise to transfer and potentially dismiss the hackers' case—a promise he couldn't fulfill—the case unraveled, leading to his arrest alongside the seizure of significant assets. The article also touches on historical attacks by these cybercriminals exploiting vulnerabilities in e-commerce platforms to steal and sell credit card information.
Apr 25, 2024·publication
Hugging Face has introduced Open Medical-LLM, a benchmark for evaluating generative AI models in healthcare. This initiative, developed with Open Life Science AI and the University of Edinburgh, amalgamates various existing test sets to assess AI performance on medical tasks, aiming to improve patient care by identifying models' strengths and weaknesses. While the benchmark is positioned as a robust tool, experts emphasize the significant difference between test environments and actual clinical settings, suggesting that these AI models should complement, not replace, medical professionals in practice.
Apr 25, 2024·TechCrunch
UnitedHealth Group has disclosed that its subsidiary, Change Healthcare, was subjected to a ransomware attack which resulted in the large-scale theft of private healthcare data. The stolen data includes personal and protected health information that could affect a significant portion of the U.S. population. Despite paying ransoms to two different hacking groups, including a new entity named RansomHub, the data has been partly leaked online. UnitedHealth is still assessing the full extent of the breach, expecting to spend several months reviewing the compromised data before notifying affected individuals. This cyberattack has caused widespread operational disruptions across U.S. healthcare facilities, with UnitedHealth projecting losses over $870 million due to the incident.
Apr 25, 2024·Reuters
Coca-Cola has entered into a $1.1 billion, five-year contract with Microsoft to utilize its cloud computing and artificial intelligence services, including Azure OpenAI for developing chatbots and AI tools. This deal expands upon a previous agreement from 2020 and will explore Microsoft's AI capabilities like Copilot, which assists in summarizing communications and creating business presentations, alongside other conventional software like Dynamics 365 to boost productivity and efficiency at Coca-Cola.
Apr 25, 2024·Brian Solis
Microsoft has expanded its AI investment portfolio by committing to the French startup Mistral, a developer of large language models and AI technologies. This investment aligns with Microsoft's strategy to extend its range of AI offerings on the Azure platform, positioning the company to have a diversified portfolio and reducing reliance on a single provider like OpenAI. This move allows Microsoft to provide its enterprise customers with more AI options, including Mistral's advanced models and services, thereby enhancing custom AI solutions for specific industry needs. By partnering with a European AI company, Microsoft also positions itself strategically to navigate increasing EU regulatory scrutiny effectively.