Cybersecurity News

DOJ Settles First Case Under Civil Cyber-Fraud Initiative

by

Comprehensive Health Services (CHS) agreed to a $930,000 settlement to resolve False Claims Act allegations, signifying the Department of Justice’s (DOJ) first False Claims Act settlement since...

Healthcare Practices Cyber Incident Response Less Than Most Sectors

by

Although cyberattacks and data breaches have bombarded the healthcare sector in recent years, recent research from Immersive Labs found that healthcare conducts cyber incident response exercises far...

Conti Ransomware Group Continues to Threaten Healthcare

by

The Cybersecurity and Infrastructure Security Agency (CISA), the Federal Bureau of Investigation (FBI), and the United States Secret Service (USSS) re-released their September 2021 advisory on Conti...

HSCC Focuses On Medical Device Security in New Contract Language Template

by

The Healthcare & Public Health Sector Coordinating Councils (HSCC) published model contract language to help healthcare organizations ensure medical device security when crafting contracts with...

7 New Vulnerabilities Threaten Supply Chain, Medical Device Security

by

Forescout's global research team, Vedere Labs, and CyberMDX discovered seven vulnerabilities that impact the PTC Axeda agent and threaten supply chain and medical device security. The...

HC3 Outlines History of Healthcare Cybersecurity From 1980s to Now

by

As organizations navigate the complexities of the current cyber threat landscape, it is important to take a step back and look at how healthcare cybersecurity has evolved over time. Following this...

BD Discloses Viper, Pyxis Medical Device Vulnerabilities

by

The Cybersecurity and Infrastructure Security Agency (CISA) issued two advisories concerning medical device vulnerabilities in some Becton, Dickinson and Company (BD) products. If exploited, the...

Healthcare IoT, Medical Device Vulnerability Disclosures Skyrocket

by

Healthcare IoT, IT, and medical device vulnerability disclosures have increased in recent years, signaling a need for better industrial control system (ICS) security, a new report by Claroty found....

75% of Infusion Pumps Contain Known Security Gaps, Report Finds

by

Researchers from Unit 42 analyzed over 200,000 infusion pumps and found known security gaps in 75 percent of them, a recent report revealed. The discovery has grim implications for medical device...

Conti, Karma Ransomware Groups Target 1 Healthcare Org Simultaneously

by

Two separate ransomware groups orchestrated simultaneous cyberattacks against a Canadian healthcare organization in late 2021, Sophos disclosed in a recent report. Both Karma and Conti targeted the...

Employee Cyber Hygiene Is Critical to Healthcare Cybersecurity

by

Proper employee cyber hygiene is crucial to maintaining healthcare cybersecurity, a new report conducted by the Center for Generational Kinetics (CGK) and commissioned by Mobile Mentor suggested. A...

OCR Director Urges Healthcare to Prioritize Cybersecurity This Year

by

Office for Civil Rights (OCR) director Lisa J. Pino urged healthcare organizations to prioritize cybersecurity in 2022 in a recent blog post on HHS’s website. Healthcare data breaches are still...

Destructive Malware Used to Target Ukraine Poses Threat to Healthcare

by

The Cybersecurity and Infrastructure Security Agency (CISA) and the Federal Bureau of Investigation (FBI) released a joint advisory to warn organizations about HermeticWiper and WhisperGate malware,...

NIST Requests Public Comments On Improving Cybersecurity Framework

by

The National Institute of Standards and Technology (NIST) issued a request for public comments on improving the NIST Cybersecurity Framework, a resource initially launched in 2014 that established best...

AHA: Russia’s Invasion of Ukraine Could Lead to Healthcare Cyberattacks

by

The American Hospital Association (AHA) urged hospitals and health systems to remain vigilant against healthcare cyberattacks amid Russia’s invasion of Ukraine. “The [US] government and...

Log4j Vulnerabilities Put Strain on Overburdened Cybersecurity Workforce

by

Since researchers discovered numerous Apache Log4j vulnerabilities in December, the cybersecurity workforce has been stretched thin trying to patch systems, deescalate network intrusions, and manage...

HHS Warns of EMR, EHR Security Risks

by

HHS's Health Sector Cybersecurity Coordination Center (HC3) warned of electronic medical record (EMR) and electronic health record (EHR) security risks in a recent brief. EHRs and EMRs are top...

CaptureRx to Consider Filing For Bankruptcy if $4.75M Settlement Not Approved

by

CaptureRx CEO Chris Hotchkiss said the company would “strongly consider” filing for bankruptcy if a $4.75 million settlement to resolve multiple class-action lawsuits resulting from a 2021...

KLAS: Evaluating Top Healthcare IoT Security Vendors

by

Medigate, Ordr, and Armis are among the most considered and adopted healthcare Internet of Things (IoT) security vendors in 2022, according to a new KLAS report. Healthcare IoT solutions can help...