Search site
Find podcasts, news, articles, webinars, and contributors in one search.
Health IT News
Browse by topic
Most-read stories in the last 7 days
4,419 stories
Apr 23, 2024·Dark Reading
Foreign nation-state hackers exploited vulnerabilities in Ivanti edge devices to gain extensive access to MITRE Corp.'s unclassified network for three months. MITRE, known for its ATT&CK glossary on cyberattack techniques, faced its first major incident in 15 years due to these exploits. The breach targeted the NERVE network, used for research and development, whose extent of damage is still under assessment. The attackers bypassed multifactor authentication and utilized various techniques to infiltrate and persist within MITRE's VMware infrastructure, ultimately exfiltrating data to a command-and-control server. Despite following recommended best practices for securing the compromised Ivanti system, MITRE was unable to detect the breach until three months later, highlighting the sophistication of the attack and the need for improved detection and mitigation strategies.
Apr 22, 2024·Associated Press
The U.S. House of Representatives has passed legislation that could lead to a ban on TikTok unless its Chinese parent company, ByteDance Ltd., sells its stake within a year. Though initially part of a larger foreign aid package, the measure saw bipartisan support due to national security concerns about Chinese influence and potential data privacy issues. The bill, which passed by a significant majority, could face legal challenges from the company, claiming it infringes on First Amendment rights. TikTok has actively opposed the legislation, urging its significant U.S. user base to lobby against the ban. The Senate will now consider the bill, which includes provisions for the sale deadline to be extended if a sale is already underway.
Apr 22, 2024·NEJM AI
The article titled "Patient Portal — When Patients Take AI into Their Own Hands" discusses the proactive use of generative AI by patients for medical diagnostics and other functions, even as the medical community remains cautious about the implementation of AI in clinical settings. The author, Carey Goldberg, argues that these patient-led "DIY" approaches to using AI in healthcare should not only be monitored but integrated into formal medical advice to ensure safe and effective practices.
Apr 22, 2024·publication
The article discusses the financial investments eight hospitals and health systems are making in electronic health record (EHR) systems. It details the expenses ranging from Health First's planned $160 million for an Epic EHR system to AdventHealth's $660 million recently completed Epic implementation. Additionally, various hospitals like Kona Community and Kohala Hospital received federal funding worth $2.5 million for their EHR systems, while systems like MultiCare Health System are planning to spend around $50 million for upgrading EHR at newly acquired facilities. The report emphasizes the significant financial commitments involved in either upgrading or installing new EHR systems to enhance operational efficiency and patient care.
Apr 22, 2024·HHS
The U.S. Office for Civil Rights (OCR) has issued a Dear Colleague letter and initiated a comprehensive investigation into Change Healthcare and UnitedHealth Group (UHG) following a significant cybersecurity incident, analyzing the possible breach of protected health information (PHI) and compliance with HIPAA regulations. The investigation also extends to entities associated with Change Healthcare and UHG, underscoring the importance of maintaining business associate agreements and the necessity for timely breach notifications. OCR has provided various resources to aid healthcare entities in improving cybersecurity measures and complying with the HIPAA Security Rule, emphasizing the necessity of risk analysis and breach protocols to protect patient information.
Apr 22, 2024·SC Magazine
Today's workplace complexities have blurred the lines between standard and privileged user accounts, with many non-administrative roles requiring access to sensitive data and applications. CyberArk's CEO, Matt Cohen, emphasizes that any identity can become privileged under certain circumstances, highlighting the shifting nature of cyber security threats. Hackers exploit outdated authentication methods, with over half of workforce identities having access to critical systems, according to CyberArk's Amita Potnis. This situation necessitates a move beyond traditional security measures to modern Identity and Access Management (IAM) solutions that enforce least privilege access and manage all user accounts, mitigating risks associated with elevated privileges. The article discusses various scenarios where regular users gain unintended privileges, and how attackers exploit these "privilege creeps." To combat these vulnerabilities, organizations are encouraged to implement stronger authentication protocols, such as Multi-Factor Authentication (MFA) and Single Sign-On (SSO), and adopt a zero-trust network model and AI-assisted IAM platforms to ensure secure and appropriate access.
Apr 22, 2024·Bleeping Computer
In January 2024, MITRE Corporation reported a security breach instigated by a state-sponsored hacking group that exploited two zero-day vulnerabilities in Ivanti VPNs. The breach was initially detected due to unusual activity in an unclassified network environment used for research and development, prompting an immediate investigation. Although the breach did not compromise MITRE's core enterprise network or its affiliates, the attackers were able to maneuver through the network and access sensitive data by using sophisticated methods to bypass security measures, including multi-factor authentication. The incident has prompted notifications to impacted parties and collaborations with authorities as MITRE works to establish secure operational alternatives while advocating for improved cybersecurity defenses across the industry.
Apr 22, 2024·Financial Times
As companies increasingly integrate artificial intelligence into their operations, the role of Chief AI Officer (CAIO) is becoming more prevalent. This executive position is dedicated to overseeing and strategically deploying AI technology within a company. The responsibilities of a CAIO include ensuring AI alignment with corporate goals, managing AI projects, and navigating ethical considerations associated with AI use. This role is crucial as businesses seek to harness AI’s potential while addressing the complexities it introduces.
Apr 22, 2024·CRN
Cisco has disclosed and issued a patch for a high-severity vulnerability affecting the Integrated Management Controller in a range of devices, including UCS C-Series Rack Servers and 5000 Series Enterprise Network Compute Systems. This flaw, having an 8.8 out of 10 severity rating, could allow an authenticated, local attacker with at least read-only privileges to execute command injection attacks and gain root access. While Cisco reported no known instances of the vulnerability being exploited, code that could be used for such purposes has been made public. Customers are urged to apply the provided patches, as no alternative mitigations have been advised, and a wide spectrum of Cisco devices could be impacted if running vulnerable versions of the software with default configurations.
Apr 22, 2024·TechCrunch
Omni Hotels & Resorts experienced a ransomware attack last month, resulting in the theft of personal customer information. The stolen data includes names, email and postal addresses, and loyalty program details but does not encompass financial details or Social Security numbers. The hotel chain, which operates numerous properties across the United States and Canada, detected the intrusion on March 29, causing temporary system shutdowns that led to widespread outages affecting services like phone, Wi-Fi, and room keys. The ransomware group Daixin has claimed responsibility for the breach, threatening to release customer records dating back to 2017. Despite these claims, financial information and Social Security numbers were reportedly not compromised in the incident.
Apr 22, 2024·The Register
A team of computer scientists from the University of Illinois Urbana-Champaign demonstrated that AI agents, powered by OpenAI's GPT-4, can exploit real-world security vulnerabilities with high efficiency by analyzing CVE advisories. In their study, GPT-4 successfully exploited 87% of tested vulnerabilities, a significant leap compared to other models and traditional vulnerability scanners. The research highlights the potential of large language models to automate attacks, raising concerns over security practices. The team emphasizes the importance of proactive security measures, as restricting access to vulnerability descriptions proved largely ineffective. This work points to a future where AI could outpace current exploitation tools available to hackers, underlining an impending need for advancements in cybersecurity defenses.
Apr 22, 2024·Meritalk
In response to the significant ransomware attack on UnitedHealth subsidiary Change Healthcare by Russia-based ALPHV BlackCat, industry experts have urged Congress to implement minimum cybersecurity standards for healthcare organizations. This attack highlighted the vulnerabilities of the healthcare sector, with the FBI indicating it as a top victim of ransomware in 2023. Addressing the incident, legislators and cybersecurity professionals recommended increased Federal support, funding for under-resourced organizations, and the development of a Federal playbook for cybersecurity in healthcare, emphasizing the importance of preparedness and quick response to future cyber threats. Additionally, proposed legislation aims to incentivize healthcare providers to enhance their cybersecurity measures through financial rewards for meeting established standards.
Apr 22, 2024·Becker's Payer
Elevance Health has announced a partnership with private-equity firm Clayton, Dubilier and Rice to launch a new primary care venture expected to generate $4 billion in annual revenue. This payer-agnostic initiative will serve 1 million members across Medicare, Medicaid, and commercial markets, combining the services of Apree Health and Millennium Physician Group with Elevance's Carelon health services. This joint effort emphasizes value-based care and physician enablement, targeting chronic and complex care patients, aligning with Elevance’s overall care delivery strategy. The financial specifics of the deal remain undisclosed, and the venture is not expected to impact Elevance's 2024 earnings significantly.
Apr 22, 2024·Emerging Tech Brew
Net neutrality is on the path to being reinstated by the Federal Communications Commission (FCC), which plans to vote on bringing back Obama-era web-browsing protections. Experts explain that net neutrality involves rules that prevent internet service providers (ISPs) from discriminately managing web traffic, ensuring all data is treated equally. These rules, aiming to avoid ISPs charging both consumers and content providers for access, could redefine regulatory oversight by applying Title II of the Communications Act to broadband companies. This move would enhance the FCC's capability to address issues like network outages and data throttling, with potential impacts on public safety and broadband oversight. While there are concerns that reinstating net neutrality could influence broadband pricing, historical trends suggest little immediate effect on consumer costs.
The 2023 AI Index report from Stanford University's Institute for Human-Centered Artificial Intelligence reveals significant trends in AI. It covers the proliferation of multimodal foundation models, with open-sourced models increasing significantly though still lagging behind closed-source models in performance. The report highlights the dominant role of industry, especially big tech companies like Google, in advancing AI technology and underscores a substantial increase in the costs associated with training these sophisticated models. Furthermore, the report notes a shift in global AI investment leadership towards the U.S. and increasing corporate adoption of AI technologies. It also discusses new regulatory measures being implemented in the U.S., reflecting growing attention to the governance of AI application.
Apr 19, 2024·Rafeeq Rehman
The CISO MindMap 2024, an essential tool for security professionals, has been updated to reflect the latest developments and challenges in cybersecurity. This iteration introduces new recommendations for 2024-25, including a focus on Artificial Intelligence and Generative AI (GenAI), strategies for removing redundancies, and enhancing security team branding. It emphasizes the need for CISOs to adapt to the fast-evolving digital landscape, particularly with the adoption of cloud services and GenAI technologies, while still providing actionable guidance on securing these innovations. Additionally, the MindMap suggests rationalizing cybersecurity tools to improve return on investment and integrating security more closely with business continuity and disaster recovery efforts. The importance of soft skills for security leaders, such as negotiation and strategic decision-making, is also highlighted to foster better communication and collaboration with various stakeholders. This update serves as a comprehensive resource for security professionals navigating the complexities of their roles in a rapidly changing environment.
Apr 19, 2024·CIO
In response to the competitive and sparse labor market, Jason Snyder, Massachusetts' Commonwealth CIO, has shifted to a skills-first hiring approach within the Executive Office of Technology Services and Security. This method emphasizes the practical skills of applicants over traditional qualifications like job history and academic degrees. This change aligns with a broader trend as evidenced by increasing adoption of skills-based hiring practices across various sectors, as detailed in recent LinkedIn reports and endorsed by Massachusetts Gov. Maura Healey's executive order. The approach aims to widen the talent pool, enhance workforce diversity, and streamline the hiring and training process, albeit facing challenges in implementation due to the demand for radically rethinking recruitment strategies. While some CIOs express reservations and mix traditional hiring criteria with skills-focused assessments, others, like Snyder, experience shortened vacancy periods and improved diversity through dedicated training programs and reduced education prerequisites.
Apr 19, 2024·WIRED
Change Healthcare, a subsidiary of UnitedHealth Group, is grappling with a significant cybersecurity issue following a ransomware attack by a group known as AlphV in February, which has led to the claimed sale of sensitive medical and financial records by another cybercriminal gang, RansomHub. The stolen data reportedly includes medical and dental records, insurance details, and personal information such as Social Security numbers and email addresses. This breach, which initially disrupted the company's claims-payment operations, has already cost Change Healthcare $872 million in response efforts as of March 31. This incident has caught the attention of lawmakers and regulators, increasing pressure on Change Healthcare to bolster its cybersecurity measures and prevent future breaches.
Apr 19, 2024·Tom's Guide
Microsoft's VASA-1 is an advanced AI developed by Microsoft Research that transforms a single portrait photo and an audio file into a hyper-realistic talking face video. This AI model showcases impressive lip-sync capabilities and realistic facial and head movements. Although it is currently only a research preview and not available for public use, VASA-1 stands out for its ability to process various facial orientations and incorporate emotional nuances into animated characters, suggesting potential future applications in gaming, virtual avatars, and AI-driven media production.
Apr 19, 2024·SiliconANGLE
Microsoft has disclosed a new AI framework named VASA-1, designed to animate highly realistic talking heads from a single photograph and an audio file. This technology is capable of synthesizing facial expressions, head movements, and synchronizing lip movements with the provided audio, allowing even for singing. While similar technologies have been released by Nvidia Corp. and Runway AI Inc., Microsoft's VASA-1 showcases a higher degree of realism with fewer artefacts around the mouth region. Currently a research initiative, VASA-1 has not been made publicly available, citing potential risks of misuse such as creating convincing deepfakes. Microsoft aims to explore positive applications, emphasizing virtual character animation for video games and other media, while ensuring responsible use of the technology.