What can your hospital or health system do to proactively prepare for a cyberattack with plans to maintain both business and clinical continuity? Gain insights gleaned from a recent AHA webinar with four health care leader panelists and John Riggi, national advisor for cybersecurity and risk for the AHA. Read Riggi鈥檚 new AHA Cyber Intel blog article to learn four strategies to effectively prepare for a cyberattack.
Cybersecurity News
Latest
The FBI this week advised organizations to protect against certain emerging ransomware trends, including multiple attacks on the same victim and new data destruction tactics.
Cyber actors linked to the People鈥檚 Republic of China are targeting router firmware in government and multinational organizations, which should review all subsidiary connections and consider implementing Zero Trust models to limit a potential compromise, U.S. and Japanese agencies advised聽Sept. 27.聽
The Food and Drug Administration Sept. 26 finalized guidance updating the cybersecurity information device makers should submit to its Center for Devices and Radiological Health or Center for Biologics Evaluation and Research for premarket review of devices that have cybersecurity considerations.
The Health Information Sharing and Analysis Center (H-ISAC) Sept. 19 alerted the health sector to an emerging threat that targets senior executives through phishing emails that contain malicious QR codes, also known as quishing.
The Department of Health and Human Services Sept. 18 alerted聽the health care sector to a critical vulnerability in ManageEngine products that allows an attacker to perform remote code execution and which a North Korean state-sponsored actor is reportedly using to target health care entities in Europe and the United States.
The Department of Health and Human Services鈥 Health Sector Cybersecurity Coordination Center (HC3) yesterday alerted聽the sector to a ransomware group that has claimed over 60 victims since March, demanding payments ranging from $200,000 to $4 million.
The U.S. Treasury Department, in coordination with the United Kingdom, Sept. 7 sanctioned 11 individuals who are part of the Russia-based Trickbot cybercrime group, whose targets have included hospitals and other critical infrastructure organizations.
The Federal Bureau of Investigations, amid one of the largest-ever U.S.-led enforcement actions against a botnet, Aug. 29 announced the successful takedown of QakBot, the botnet infrastructure used by cybercriminals for ransomware, financial fraud and other criminal activity.
A new resource聽from the Cybersecurity and Infrastructure Security Agency, National Security Agency and the National Institute of Standards and Technology is helping hospitals and other critical infrastructure organizations get up to speed on the impacts of quantum capabilities in cybersecurity and assist their early planning for migration to post-quantum cryptographic standards.
The Joint Commission yesterday released an alert reviewing how health care organizations can prepare to deliver safe patient care in the event of a cyberattack, calling the potential to experience a cyberattack that adversely affects operations not an 鈥渋f鈥 but a 鈥渨hen鈥 question. John Riggi, AHA鈥檚 national director for cybersecurity and risk, provided expert advice to TJC as it developed the resource.
U.S. and other allied nations鈥 cybersecurity agencies urged聽software vendors to implement secure design practices and organizations to implement a centralized patch management system and apply timely patches, noting that malicious actors in 2022 most often targeted known vulnerabilities.聽
HHS alerts organizations to Rhysida ransomware.
U.S. and Australian cybersecurity agencies July 27 warned organizations using web applications about vulnerabilities that enable malicious actors to modify, delete or access sensitive data and urged them to implement recommendations to protect their data from compromise.
A May data breach involving MOVEit Transfer software on Medicare contractor Maximus Federal Services鈥 corporate network may have exposed an estimated 612,000 Medicare beneficiaries鈥 personally identifiable information and/or protected health information, the Centers for Medicare & Medicaid Services announced聽July 28.
Malicious actors recently exploited a Citrix vulnerability to steal active directory data from a critical infrastructure organization, the Cybersecurity and Infrastructure Security Agency reported recently, urging organizations to take certain steps to detect a potential system compromise and apply patches.
The Department of Health and Human Services鈥 Office for Civil Rights and Federal Trade Commission yesterday sent a letter to about 130 hospital systems and telehealth providers reminding them to comply with HIPAA Privacy, Security and Breach Notification Rules, the FTC Act and FTC Health Breach Notification Rule when using technologies that can track a user鈥檚 online activities, such as Meta/Facebook Pixel and Google Analytics.
Microsoft聽announced聽plans to offer government and commercial customers free access to additional cloud security logs beginning in September, prompting applause from the Cybersecurity and Infrastructure Security Agency.
The White House the week of July 10 released a federal plan聽for collaborating with the private sector and others to implement the National Cybersecurity Strategy.
In response to recent malicious activity identified in a federal civilian agency鈥檚 Microsoft 365 audit logs, the Cybersecurity and Infrastructure Security Agency and FBI July 12 released guidance聽to help health care and other critical infrastructure organizations detect similar malicious activity and secure their cloud environments.