News

GAO Calls on HHS to Improve Healthcare Data Breach Reporting Process

by

In its latest report, the US Government Accountability Office (GAO) called on HHS to improve the healthcare data breach reporting process. Specifically, GAO urged HHS to create a mechanism for entities...

Senators Call on FTC to Investigate Apple, Google’s “Deceptive” Data Privacy Practices

by

Senators Ron Wyden (D-OR), Elizabeth Warren (D-MA), Cory Booker (D-NJ), and Rep. Sara Jacobs (D-CA) sent a letter asking the Federal Trade Commission (FTC) to launch an investigation into Apple and...

CISA Alerts Healthcare Sector to OFFIS DCMTK Cybersecurity Vulnerabilities

by

High-severity cybersecurity vulnerabilities in OFFIS DCMTK software could result in remote code execution (RCE) if exploited, the Cybersecurity and Infrastructure Security Agency (CISA) warned in a...

CISA Warns of Continued Log4Shell Exploits in VMware Horizon Systems

by

The Cybersecurity and Infrastructure Security Agency (CISA) and the United States Coast Guard Cyber Command (CGCYBER) released a joint cybersecurity advisory to warn organizations of continued...

MCG Health Data Breach Impacts 8 Organizations, 793K Individuals

by

As previously reported, Seattle-based company MCG Health suffered a data breach in March resulting from unauthorized access. The Seattle-based software company provides patient care guidelines to...

UPMC Reaches $450K Settlement in Healthcare Data Breach Lawsuit

by

University of Pittsburgh Medical Center (UPMC) and Charles J. Hilton, PC, (CJH) agreed to a $450,000 settlement to resolve allegations relating to a 2020 healthcare data breach. UPMC had engaged...

As API Adoption in Healthcare Skyrockets, Cybersecurity Risks Follow

by

Application Programming Interface (API) adoption is steadily increasing in the healthcare sector, but APIs do not come without cybersecurity risks. In fact, Gartner predicted that API attacks would...

Meta Sued For Violating Patient Privacy, Scraping Health Data From Hospitals

by

In the wake of detailed allegations of patient privacy violations covered in a report co-published by The Markup and STAT, Meta (the parent company of Facebook) is facing a lawsuit over the use of its...

Yale New Haven Hospital Research File Implicated in Healthcare Data Breach

by

Yale New Haven Hospital (YNHH) informed an undisclosed number of individuals of a healthcare data breach that involved a radiology file. The file was created for research and was accidentally posted on...

2 Texas Hospitals Infected With Malicious Code May Face PHI Exposure

by

Texas-based Baptist Medical Center and Resolute Health Hospital informed an undisclosed number of patients that its network was infected with malicious code, potentially resulting in protected health...

Select Hillrom Electrocardiograph Products Impacted by Medical Device Vulnerabilities

by

Two medical device vulnerabilities in select Hillrom electrocardiograph products may cause unauthorized access and security risks, a Cybersecurity and Infrastructure Security Agency (CISA) ICS advisory...

Senators Aim to Ban Data Brokers From Selling Health Data With New Bill

by

US Senators introduced the Health and Location Data Protection Act, which would ban data brokers from selling location and health data in anticipation of the potential repeal of Roe v. Wade. Elizabeth...

HHS Provides Tips For Strengthening Cyber Posture in Healthcare

by

The HHS Health Sector Cybersecurity Coordination Center (HC3) issued a brief with tips for strengthening cyber posture in healthcare. HC3 defined cyber posture as “the overall strength of an...

Eye Care Leaders EMR Data Breach Tally Surpasses 2 Million

by

Texas Tech University Health Sciences Center (TTUHSC) added 1.3 million to the total number of individuals impacted by the Eye Care Leaders (ECL) EMR data breach, bringing the total to over 2...

Yuma Regional Medical Center Experiences Ransomware Attack

by

Yuma Regional Medical Center (YRMC) suffered a ransomware attack in late April that exposed the Social Security numbers and other personal information of thousands of individuals. In a notice posted on...

Cybersecurity Professionals Identify Top Cloud Computing Security Risks

by

The Cloud Security Alliance (CSA) released this year’s “Top Threats to Cloud Computing” report, outlining the most prevalent security concerns that trouble cybersecurity experts...

ONC, OCR Release Updated Version of HHS Security Risk Assessment (SRA) Tool

by

The Office for Civil Rights (OCR) and the Office of the National Coordinator for Health Information Technology (ONC) released version 3.3 of the HHS Security Risk Assessment (SRA) Tool. ONC and OCR...

CISA, FBI, NSA Provide Tips For Countering China-Backed Cyber Threats

by

The Cybersecurity and Infrastructure Security Agency (CISA), the National Security Agency (NSA), and the Federal Bureau of Investigation (FBI) released a joint cybersecurity advisory containing tips...

Bill Calls on FDA to Regularly Update Medical Device Security Guidelines

by

The recently introduced Strengthening Cybersecurity for Medical Devices Act called on the US Food and Drug Administration (FDA) to review and update its medical device security guidelines more...

OCR to Release Video on HITECH Recognized Security Practices

by

The HHS Office for Civil Rights (OCR) announced plans to produce a pre-recorded video presentation on the Health Information Technology for Economic and Clinical Health Act (HITECH) recognized security...