More than 1,000 executive leaders from the nation鈥檚 top hospitals and health systems convened at the 2023 AHA Annual Membership Meeting, April 23-25 in Washington, D.C.


Health care cybersecurity has too often been an afterthought, with protections added after an internal review or external attack discover a vulnerability, Sen. Mark Warner, D-Va., told moderator former CNN Washington bureau chief Frank Sesno at today鈥檚 federal plenary session. 
 
Warner called for a clearer chain of command at the federal level when it comes to health care cyber policy; a 鈥渂ill of sale鈥 to make medical device software more visible to patients and providers; and minimum mandatory cybersecurity standards for the health care field.
  
鈥淚 don鈥檛 think you can just say 鈥榓nother unfunded mandate,鈥欌 Warner said about the costs of building a stronger cybersecurity shield for health care. 鈥淏ut we鈥檝e put up with a lot of technology where some firms, frankly, put out vulnerable product on an ongoing basis.鈥 

Putting cybersecurity first, rather than looking at it as tool to use after a system has been compromised, is the best way to protect sensitive data, he said. 鈥淚t鈥檚 like washing your hands before you go into the OR. Otherwise, you find it鈥檚 the weakest link in the chain where the bad guys can get in.鈥 

For more on the 2023 AHA Annual Meeting, read AHA's coverage.

Related News Articles

Headline
The Cybersecurity and Infrastructure Security Agency April 17 released guidance to reduce risks associated with a reported breach of Oracle cloud services.鈥
Headline
The National Counterintelligence and Security Center, the FBI, and the Defense Counterintelligence and Security Center yesterday released guidance on鈥
AHA Cyber Intel
While the rate of cyberattacks on hospitals has risen dramatically, the severity of the impacts has also grown exponentially. Let鈥檚 look at the state of cyber鈥
Headline
The House Energy and Commerce Oversight and Investigations Subcommittee April 1 discussed cybersecurity threats in legacy medical devices during a hearing. The鈥
Headline
The Trump Administration March 28 announced that it renewed for one year the public emergency for ongoing malicious cyber-enabled activities against the U.S.鈥
Headline
The FBI March 26 advised that, after extensive investigation and intelligence review, they have not identified any specific credible threat targeted against鈥