Health IT Security and HIPAA News

1 in 5 Connected Medical Devices Run On Unsupported Operating Systems

by

New data from asset visibility and security company Armis found that 1 in 5 connected medical devices run on unsupported operating systems (OS). To inform its research, Armis analyzed data collected by...

Excel File Exposed to Internet at CA Health System

by

San Francisco-based John Muir Health (JMH) notified 821 patients of a security incident that occurred when an Excel file containing patient information was accidentally exposed to the internet. JMH...

DC Health Link Points to Human Error as Cause of Data Leak

by

At a recent House Oversight Committee hearing, Mila Kofman, executive director of the DC Health Benefit Exchange Authority (DCHBX) delivered a testimony providing new information about the data breach...

Threat Actors Deviate From Common Tactics in Global Cyberattacks, Mandiant Observes

by

Mandiant observed threat actors favoring the financial, professional services, high tech and healthcare industries in 2022, according to its newly released M-Trends 2023 report. The report aimed to...

Parent of 2 Major Massachusetts Health Insurers Suffers Ransomware Attack

by

Massachusetts-based Point32Health, the parent of Harvard Pilgrim Health Care and Tufts Health Plan, posted a notice on its website regarding a “cybersecurity ransomware incident” that it...

Quantifying the Financial Impact of Healthcare Ransomware Attacks

by

The average cost of a healthcare ransomware attack was $4.82 million in 2021, according to IBM Security’s “Cost of a Data Breach Report.” In a new report by ThreatConnect, the cyber...

CISA Reveals Enhanced Zero Trust Maturity Model

by

The Cybersecurity and Infrastructure Security Agency (CISA) unveiled the upgraded Zero Trust Maturity Model Version 2 in line with President Biden's National Cybersecurity Strategy. The new model...

55% of Surveyed Healthcare Workers Believe Security Policies Keep Up With New Tech

by

A survey of more than 400 healthcare workers revealed perceived gaps in healthcare security programs, Salesforce discovered. As new technologies such as generative AI gain popularity, security experts...

HHS Cybersecurity Task Force Releases New Resources to Address Rise in Healthcare Cyberattacks

by

The HHS 405(d) Program and the Health Sector Coordinating Council Cybersecurity Working Group (HSCC CWG) led efforts to release three new and updated resources to help healthcare organizations manage...

Alcohol Recovery Startup Suffers Healthcare Data Breach, 108K Impacted

by

Alcohol recovery startup Monument disclosed a healthcare data breach to HHS that impacted 108,584 individuals. According to a report from The Verge, Monument, which acquired fellow online alcohol...

Records and Information Management Professionals Pinpoint Digitization, Cybersecurity as Key Challenges

by

Industry professionals across different sectors, including healthcare, view digital transformation and information security as crucial priorities, presenting both challenges and opportunities to meet...

Iowa Medicaid Suffers Third-Party Data Breach, 20K Impacted

by

The Iowa Department of Health and Human Services announced that approximately 20,000 Medicaid members may have had their personal information compromised as a result of a third-party data breach. Iowa...

HHS Proposes Rule to Strengthen HIPAA Protections For Reproductive Healthcare Data

by

The HHS Office for Civil Rights (OCR) issued a Notice of Proposed Rulemaking (NPRM) with the goal of strengthening HIPAA Privacy Rule protections for those seeking and delivering reproductive...

Insight Global Settles Class Action Lawsuit After Contact Tracing Breach

by

Insight Global, the contact tracing program administrator hired by the state of Pennsylvania, has reached a proposed settlement to resolve a class-action healthcare data breach lawsuit. The breach,...

Pandemic-Era Telehealth Rules Set to Expire in May, Shifting HIPAA Compliance Obligations

by

The COVID-19 public health emergency (PHE) is set to end on May 11, marking the expiration of many pandemic-era support programs and lighter compliance obligations. As such, the HHS Office for Civil...

HHS Emphasizes EHR Cybersecurity Risks to Healthcare Sector

by

EHRs are poised to remain a crucial part of the healthcare industry, but the exploitation of patient data casts a shadow over its benefits. A recent HHS threat brief emphasized the need for healthcare...

DNS NXDOMAIN Flood DDoS Attacks Impacting Healthcare, HC3 Warns

by

HHS warned the healthcare sector of ongoing DNS NXDOMAIN flood distributed denial-of-service (DDoS) attacks that could pose significant threats to security and system availability. HHS'...

Microsoft, Fortra, Health-ISAC Crack Down On Cobalt Strike Abuse

by

Microsoft’s Digital Crimes Unit (DCU), along with cybersecurity software company Fortra and the Health Information Sharing and Analysis Center (Health-ISAC), are working together to disrupt...

HC3 Raises Concern Over KillNet DDoS Attacks Targeting Healthcare Sector

by

In just a few months since its emergence in 2022, pro-Russia hacktivist group KillNet has quickly evolved into a significant threat to the healthcare sector by executing distributed denial-of-service...

Tallahassee Memorial Provides Healthcare Data Breach Notice

by

Tallahassee Memorial HealthCare (TMH) provided a healthcare data breach notice to HHS following a February breach. The incident impacted 20,376 individuals in total. As previously reported, TMH began...