cybersecurity Archives - MedCity News https://medcitynews.com/tag/cybersecurity/ Healthcare technology news, life science current events Fri, 15 Sep 2023 22:28:43 +0000 en-US hourly 1 https://wordpress.org/?v=6.3.1 https://medcitynews.com/uploads/2021/03/cropped-mblue-32x32.png cybersecurity Archives - MedCity News https://medcitynews.com/tag/cybersecurity/ 32 32 40682243 Most Hospitals Are Still Violating HIPAA By Using Web Tracking Tools, Despite Federal Warnings https://medcitynews.com/2023/09/social-media-healthcare-hipaa/ https://medcitynews.com/2023/09/social-media-healthcare-hipaa/#respond Fri, 15 Sep 2023 18:13:35 +0000 https://medcitynews.com/?p=648708

The federal government has warned hospitals that using third-party analytics tools on their websites could violate HIPAA, and more than 20 hospitals are facing class-action lawsuits over the use of these tools. But a recent analysis found that hospitals are doing a poor job of fixing their websites and preventing patient data collection.

]]>
https://medcitynews.com/2023/09/social-media-healthcare-hipaa/feed/ 0 648708
How Hospitals Should Manage Cybersecurity Risks, Per Baptist Health’s CIO https://medcitynews.com/2023/09/cybersecurity-data-breach-healthcare/ https://medcitynews.com/2023/09/cybersecurity-data-breach-healthcare/#respond Tue, 12 Sep 2023 23:02:11 +0000 https://medcitynews.com/?p=648414

As health systems shore up their defenses against cybercriminals, they should openly communicate with their third-party vendors about data security risks and work together to actively manage those risks. That was some of the advice given by Aaron Miri, Baptist Health’s chief digital and information officer, during a Tuesday webinar.

]]>
https://medcitynews.com/2023/09/cybersecurity-data-breach-healthcare/feed/ 0 648414
HHS Warns Providers About a New Cybercriminal Gang Attacking the Healthcare Sector https://medcitynews.com/2023/08/healthcare-hackers-cybersecurity-ransomware/ https://medcitynews.com/2023/08/healthcare-hackers-cybersecurity-ransomware/#respond Tue, 08 Aug 2023 21:35:00 +0000 https://medcitynews.com/?p=644628

HHS issued an alert warning providers about Rhysida, a ransomware gang that recently begun launching attacks on healthcare organizations. The group deploys its ransomware primarily through phishing attacks or the exploitation of legitimate cybersecurity tools.

]]>
https://medcitynews.com/2023/08/healthcare-hackers-cybersecurity-ransomware/feed/ 0 644628
Average Healthcare Data Breach Cost Reaches Nearly $11M https://medcitynews.com/2023/07/healthcare-data-breach-cybersecurity-ransomware/ https://medcitynews.com/2023/07/healthcare-data-breach-cybersecurity-ransomware/#respond Mon, 31 Jul 2023 21:54:56 +0000 https://medcitynews.com/?p=643503

The average cost of a healthcare data breach is now $10.93 million, up from $10.10 million in 2022, according to a new report. Healthcare has the highest data breach costs of all industries — breaches are second costliest in the financial sector, where the average cost is $5.9 million.

]]>
https://medcitynews.com/2023/07/healthcare-data-breach-cybersecurity-ransomware/feed/ 0 643503
6 Ways Providers Can Better Manage 3rd-Party Cybersecurity Risks https://medcitynews.com/2023/07/cybersecurity-data-breach-healthcare-upmc/ https://medcitynews.com/2023/07/cybersecurity-data-breach-healthcare-upmc/#respond Thu, 27 Jul 2023 11:00:12 +0000 https://medcitynews.com/?p=642732

The Health3PT Initiative recently released recommendations on how providers can better address the cybersecurity risks linked to their third party reliance. Some of the group’s recommendations included ensuring that contract language ties financial terms to a vendor’s data management transparency and establishing metrics and reporting requirements for organization-wide vendor risks.

]]>
https://medcitynews.com/2023/07/cybersecurity-data-breach-healthcare-upmc/feed/ 0 642732
How Can Providers Avoid Data Breaches? https://medcitynews.com/2023/07/healthcare-data-breach-hacker-cybersecurity-software/ https://medcitynews.com/2023/07/healthcare-data-breach-hacker-cybersecurity-software/#respond Thu, 13 Jul 2023 19:51:47 +0000 https://medcitynews.com/?p=641556

To prevent the proliferation of data security incidents in the healthcare industry, providers must examine their use of legacy systems as well as their reliance on third parties, according to a new report. It pointed out that most providers fail to probe their third-party partners’ cybersecurity measures, and many continue to use legacy systems that are no longer supported by vendors or are hard to patch and update.

]]>
https://medcitynews.com/2023/07/healthcare-data-breach-hacker-cybersecurity-software/feed/ 0 641556
1,000+ Facilities Impacted by HCA Data Breach https://medcitynews.com/2023/07/hca-healthcare-data-breach-cybersecurity-hackers/ https://medcitynews.com/2023/07/hca-healthcare-data-breach-cybersecurity-hackers/#respond Tue, 11 Jul 2023 19:37:21 +0000 https://medcitynews.com/?p=641280 data breach, cybersecurity, breach, security

HCA Healthcare recently suffered a data breach affecting 1,038 hospitals and physician clinics across 20 states. The health system said hackers stole data from an external data storage location “exclusively used to automate the formatting of email messages.” It also said that the incident has not caused any disruption to HCA’s daily operations or the services it provides to patients.

]]>
https://medcitynews.com/2023/07/hca-healthcare-data-breach-cybersecurity-hackers/feed/ 0 641280
Providers Should Beware of Ransomware Gang Clop & The Latest Software Vulnerability It’s Targeting https://medcitynews.com/2023/06/ransomware-cybersecurity-healthcare-software/ https://medcitynews.com/2023/06/ransomware-cybersecurity-healthcare-software/#respond Wed, 28 Jun 2023 22:45:00 +0000 https://medcitynews.com/?p=639933

Clop, a Russian ransomware gang known for going after healthcare providers, has been recently exploiting a software vulnerability called MOVEit. Johns Hopkins University and its health system were recently victims of a data breach caused by hackers targeting this vulnerability, as was Texas-based Harris Health System.

]]>
https://medcitynews.com/2023/06/ransomware-cybersecurity-healthcare-software/feed/ 0 639933
Feds Warn Healthcare Providers About ‘Obscure’ Ransomware Gang https://medcitynews.com/2023/06/ransomware-cyberattack-cybersecurity-healthcare/ https://medcitynews.com/2023/06/ransomware-cyberattack-cybersecurity-healthcare/#respond Wed, 21 Jun 2023 00:32:16 +0000 https://medcitynews.com/?p=638811

HC3 recently warned healthcare providers about a “relatively unknown” ransomware gang named TimisoaraHackerTeam. The group leverages legitimate software tools like Microsoft’s BitLocker and Jetico’s BestCrypt to deliver its malware.

]]>
https://medcitynews.com/2023/06/ransomware-cyberattack-cybersecurity-healthcare/feed/ 0 638811
Federal Agencies Release New Guidelines to Help Providers Fend Off Ransomware https://medcitynews.com/2023/05/ransomware-fbi-healthcare-cybersecurity-cyberattack/ https://medcitynews.com/2023/05/ransomware-fbi-healthcare-cybersecurity-cyberattack/#respond Tue, 30 May 2023 23:11:12 +0000 https://medcitynews.com/?p=636397

A group of federal agencies recently released an updated set of guidelines to help healthcare organizations protect themselves from ransomware attacks and the data breaches that often follow. The guidance lays out best practices to prevent the six major ways that bad actors gain access to providers’ systems, which include compromised credentials and phishing.

]]>
https://medcitynews.com/2023/05/ransomware-fbi-healthcare-cybersecurity-cyberattack/feed/ 0 636397
How Can Medtechs Prepare for the FDA’s Shift Left Strategy on Cybersecurity https://medcitynews.com/2023/05/how-can-medtechs-prepare-for-the-fdas-shift-left-strategy-on-cybersecurity/ https://medcitynews.com/2023/05/how-can-medtechs-prepare-for-the-fdas-shift-left-strategy-on-cybersecurity/#respond Wed, 10 May 2023 13:00:59 +0000 https://medcitynews.com/?p=631728

Regulators have become increasingly concerned about the potential for medical devices to become a vector for spreading malware attacks across hospital networks, resulting in untold patient harm and billions of dollars globally.

]]>
https://medcitynews.com/2023/05/how-can-medtechs-prepare-for-the-fdas-shift-left-strategy-on-cybersecurity/feed/ 0 631728
Healthcare’s Recent Cybercriminal Activity Attributed to Ransomware Gangs Cl0p & LockBit https://medcitynews.com/2023/05/cybercriminal-ransomware-malware-cyberattack-hacker-healthcare-cl0p-lockbit-data-breach/ https://medcitynews.com/2023/05/cybercriminal-ransomware-malware-cyberattack-hacker-healthcare-cl0p-lockbit-data-breach/#respond Wed, 03 May 2023 20:37:19 +0000 https://medcitynews.com/?p=633513 Data breach, cybersecurity, hacking,

Federal officials are sounding the alarm on two ransomware groups that are actively targeting the healthcare sector: Cl0p and LockBit. In recent months, the groups have been exploiting three known software vulnerabilities in cyberattacks they have waged against healthcare businesses across the country. 

]]>
https://medcitynews.com/2023/05/cybercriminal-ransomware-malware-cyberattack-hacker-healthcare-cl0p-lockbit-data-breach/feed/ 0 633513
What Healthcare Organizations Should Know About Russian Hacking Gang KillNet https://medcitynews.com/2023/04/what-healthcare-organizations-should-know-about-russian-hacking-gang-killnet/ https://medcitynews.com/2023/04/what-healthcare-organizations-should-know-about-russian-hacking-gang-killnet/#respond Mon, 10 Apr 2023 18:29:26 +0000 https://medcitynews.com/?p=630657

The Health Sector Cybersecurity Coordination Center (HC3) recently issued a report letting healthcare organizations know that they are still being heavily targeted by KillNet, a Russian group of cybercriminals. The number of daily attacks KillNet waged against healthcare organizations using Microsoft Azure increased significantly between November 18 and February 17 — from 10-20 attacks per day in November to 40-60 attacks per day in February.

]]>
https://medcitynews.com/2023/04/what-healthcare-organizations-should-know-about-russian-hacking-gang-killnet/feed/ 0 630657
Navigating the Challenges of Price Transparency: Highlights from ViVE [Sponsored] https://medcitynews.com/2023/04/navigating-the-challenges-of-price-transparency-and-more-highlights-from-vive/ https://medcitynews.com/2023/04/navigating-the-challenges-of-price-transparency-and-more-highlights-from-vive/#respond Mon, 03 Apr 2023 11:30:39 +0000 https://medcitynews.com/?p=629787

The ViVE conference in Nashville, powered by HLTH and CHIME, offered an overview of the latest developments in health tech spanning interoperability, cybersecurity, price transparency, behavioral health and health equity.

]]>
https://medcitynews.com/2023/04/navigating-the-challenges-of-price-transparency-and-more-highlights-from-vive/feed/ 0 629787
The Areas That Intermountain Health’s CIO Wants To Address With Technology (And the One He Doesn’t) https://medcitynews.com/2023/03/the-areas-that-intermountain-healths-cio-wants-to-address-with-technology-and-the-one-he-doesnt/ https://medcitynews.com/2023/03/the-areas-that-intermountain-healths-cio-wants-to-address-with-technology-and-the-one-he-doesnt/#respond Wed, 29 Mar 2023 03:01:36 +0000 https://medcitynews.com/?p=629271

In an interview at the Vive conference in Nashville, Tennessee, Craig Richardville, Intermountain’s chief digital and information officer outlined the three areas of priority for Intermountain Health for which technology can be leveraged. But when it comes to a major headache for CIOs, Richardville seems to suggest that a government-led all-hands-on-deck approach is what is needed.

]]>
https://medcitynews.com/2023/03/the-areas-that-intermountain-healths-cio-wants-to-address-with-technology-and-the-one-he-doesnt/feed/ 0 629271
One Way To Improve Cybersecurity in Healthcare: Provide Training in Smaller Doses More Frequently [Sponsored] https://medcitynews.com/2023/03/one-way-to-improve-cybersecurity-at-health-systems-provide-training-in-smaller-doses-more-frequently/ Tue, 28 Mar 2023 12:33:19 +0000 https://medcitynews.com/?p=629148

Executives from health systems and subject matter experts shared how they are contending with data security challenges, particularly training to change behavior and acquiring expertise in cybersecurity.

]]>
629148
Cybersecurity in the Connected Medical Future https://medcitynews.com/2023/03/cybersecurity-in-the-connected-medical-future/ https://medcitynews.com/2023/03/cybersecurity-in-the-connected-medical-future/#respond Fri, 10 Mar 2023 18:03:38 +0000 https://medcitynews.com/?p=622003

The healthcare industry of the future will be defined by interoperable systems that need to securely share critical data across devices, distributed applications, and networks. Device manufacturers play a pivotal role in the delivery of these secure and connected solutions

]]>
https://medcitynews.com/2023/03/cybersecurity-in-the-connected-medical-future/feed/ 0 622003
Royal Ransomware Poses a Big Threat to Healthcare & Other Industries, Federal Agencies Say https://medcitynews.com/2023/03/royal-ransomware-poses-a-big-threat-to-healthcare-other-industries-federal-agencies-say/ https://medcitynews.com/2023/03/royal-ransomware-poses-a-big-threat-to-healthcare-other-industries-federal-agencies-say/#respond Mon, 06 Mar 2023 23:52:32 +0000 https://medcitynews.com/?p=626505

The FBI, CISA and HHS have all recently issued warnings about the dangers associated with the Royal Ransomware gang. Since approximately September of last year, cybercriminals have been using a Royal ransomware variant to compromise organizations across the U.S., many of which have been healthcare providers.

]]>
https://medcitynews.com/2023/03/royal-ransomware-poses-a-big-threat-to-healthcare-other-industries-federal-agencies-say/feed/ 0 626505
Understanding the Healthcare Cybersecurity War and How to Defend Against It [Sponsored] https://medcitynews.com/2023/02/healthcare-cybersecurity-war/ https://medcitynews.com/2023/02/healthcare-cybersecurity-war/#respond Tue, 21 Feb 2023 12:30:00 +0000 https://medcitynews.com/?p=624403

David Finn, CHIME Association Executive Healthcare and Information Sector, lead of the cybersecurity pavilion initiatives at ViVE 2023, does not mince words. With ransomware attacks surging to an all time high this month, Finn said in an interview that security is no longer a defensive posture; we are engaged in a war.

]]>
https://medcitynews.com/2023/02/healthcare-cybersecurity-war/feed/ 0 624403
Russian Hackers Take Down At Least 17 U.S. Health System Websites https://medcitynews.com/2023/02/russian-hackers-take-down-at-least-17-u-s-health-system-websites/ https://medcitynews.com/2023/02/russian-hackers-take-down-at-least-17-u-s-health-system-websites/#respond Wed, 01 Feb 2023 19:14:03 +0000 https://medcitynews.com/?p=622579

Russian hacker group Killnet has claimed responsibility for a string of recent cyberattacks that took more than a dozen hospital websites offline across the U.S. — including the websites for Cedars-Sinai, Michigan Medicine, and UPMC. The group has been active for at least a year and is known to target countries that support and/or send resources to Ukraine.

]]>
https://medcitynews.com/2023/02/russian-hackers-take-down-at-least-17-u-s-health-system-websites/feed/ 0 622579
BlackCat Ransomware Gang Hits NextGen Healthcare, Becomes Even More Formidable Threat https://medcitynews.com/2023/01/blackcat-ransomware-gang-hits-nextgen-healthcare-becomes-even-more-formidable-threat/ https://medcitynews.com/2023/01/blackcat-ransomware-gang-hits-nextgen-healthcare-becomes-even-more-formidable-threat/#respond Tue, 24 Jan 2023 00:10:09 +0000 https://medcitynews.com/?p=621643

Ransomware group BlackCat has been targeting healthcare organizations in recent months, and it just went after NextGen Healthcare. Healthcare organizations would be wise to enhance their cybersecurity strategy in defense against BlackCat, as it is “one of the more adaptable ransomware operations in the world,” according to HHS.

]]>
https://medcitynews.com/2023/01/blackcat-ransomware-gang-hits-nextgen-healthcare-becomes-even-more-formidable-threat/feed/ 0 621643
4 Health Systems Invest in a Cybersecurity Startup as Threats Loom https://medcitynews.com/2023/01/4-health-systems-invest-in-a-cybersecurity-startup-as-threats-loom/ https://medcitynews.com/2023/01/4-health-systems-invest-in-a-cybersecurity-startup-as-threats-loom/#respond Tue, 17 Jan 2023 22:34:56 +0000 https://medcitynews.com/?p=620725

MemorialCare, Ballad Health, Cedars-Sinai and UNC REX Healthcare recently participated in Censinet’s $9 million funding round. The company’s flagship product is a cloud-based network that allows healthcare organizations to share and manage risk data to strengthen cybersecurity planning.

]]>
https://medcitynews.com/2023/01/4-health-systems-invest-in-a-cybersecurity-startup-as-threats-loom/feed/ 0 620725
How Much of a Risk Is a Potential Class-action Lawsuit against CommonSpirit? https://medcitynews.com/2023/01/commonspirit-sued-over-data-breach-that-exposed-600000-patients-information/ https://medcitynews.com/2023/01/commonspirit-sued-over-data-breach-that-exposed-600000-patients-information/#respond Fri, 06 Jan 2023 19:14:08 +0000 https://medcitynews.com/?p=619507

CommonSpirit Health is facing a proposed class-action lawsuit over a ransomware attack it suffered last fall that exposed 623,774 patients’ personal data. However, hospitals’ data breach lawsuits usually never make it court, a legal expert said.

]]>
https://medcitynews.com/2023/01/commonspirit-sued-over-data-breach-that-exposed-600000-patients-information/feed/ 0 619507
Health Tech Innovation: How to Advance Data Security To Support Healthcare Accessibility https://medcitynews.com/2022/12/health-tech-innovation-how-to-advance-data-security-to-support-healthcare-accessibility/ https://medcitynews.com/2022/12/health-tech-innovation-how-to-advance-data-security-to-support-healthcare-accessibility/#respond Tue, 20 Dec 2022 22:01:23 +0000 https://medcitynews.com/?p=615250

As with most industries, healthcare should consider adopting a zero-trust approach. This security measure can help decrease an organization’s attack surface, create accurate response automation and prevent the compromise.

]]>
https://medcitynews.com/2022/12/health-tech-innovation-how-to-advance-data-security-to-support-healthcare-accessibility/feed/ 0 615250
What We Learned From Cybersecurity Attacks in Healthcare in 2022 https://medcitynews.com/2022/12/what-we-learned-from-cybersecurity-attacks-in-healthcare-in-2022/ https://medcitynews.com/2022/12/what-we-learned-from-cybersecurity-attacks-in-healthcare-in-2022/#respond Sun, 18 Dec 2022 16:12:10 +0000 https://medcitynews.com/?p=617308

In 2022, the healthcare sector is on track to meet or exceed the more than 50.4 million patient records that were breached last year. As we look ahead to 2023, increasing cybersecurity budgets will be a necessity for healthcare organizations, despite their tight financial circumstances.

]]>
https://medcitynews.com/2022/12/what-we-learned-from-cybersecurity-attacks-in-healthcare-in-2022/feed/ 0 617308
Beware of a False Sense of Cybersecurity https://medcitynews.com/2022/11/beware-of-a-false-sense-of-cybersecurity/ https://medcitynews.com/2022/11/beware-of-a-false-sense-of-cybersecurity/#respond Tue, 22 Nov 2022 14:05:16 +0000 https://medcitynews.com/?p=611224

Based on some independent research that my company commissioned with more than 200 companies, we came to several conclusions that are highlighted in the article. Broadly, however, it signals the false sense of (cyber)security that many companies are currently harboring.

]]>
https://medcitynews.com/2022/11/beware-of-a-false-sense-of-cybersecurity/feed/ 0 611224
Did Duke Health Violate Privacy by Sharing Patient Data With Facebook? https://medcitynews.com/2022/11/did-duke-health-violate-privacy-by-sharing-patient-data-with-facebook/ https://medcitynews.com/2022/11/did-duke-health-violate-privacy-by-sharing-patient-data-with-facebook/#respond Fri, 11 Nov 2022 00:08:11 +0000 https://medcitynews.com/?p=613165 In the lawsuit, two patients claimed Facebook’s pixel tracking tool is being improperly used on hospital websites, and redirecting people to sign in through their Facebook account to be able to sign-in or out of the hospital’s patient portal to request an appointment or talk with a provider. 

]]>
https://medcitynews.com/2022/11/did-duke-health-violate-privacy-by-sharing-patient-data-with-facebook/feed/ 0 613165
Hospitals Should Be Wary of Using Meta Pixel & Other Third-Party Analytics Tools https://medcitynews.com/2022/11/hospitals-should-be-wary-of-using-meta-pixel-other-third-party-analytics-tools/ https://medcitynews.com/2022/11/hospitals-should-be-wary-of-using-meta-pixel-other-third-party-analytics-tools/#respond Tue, 08 Nov 2022 21:19:44 +0000 https://medcitynews.com/?p=612694

ECRI recently issued an alert warning hospitals about the cybersecurity risks associated with the use of third-party analytics tools, such as Meta Pixel, Google Analytics and Adobe Analytics. When providers install these tools on their websites and patient portals, they may be exposing patient data — which tech companies can use to target medical-related ads to consumers as they browse the Internet.

]]>
https://medcitynews.com/2022/11/hospitals-should-be-wary-of-using-meta-pixel-other-third-party-analytics-tools/feed/ 0 612694
Medical Device Security Startup Reels in $25M as Cyber Threats Escalate https://medcitynews.com/2022/11/medical-device-security-startup-reels-in-25m-as-cyber-threats-escalate/ https://medcitynews.com/2022/11/medical-device-security-startup-reels-in-25m-as-cyber-threats-escalate/#respond Thu, 03 Nov 2022 22:53:51 +0000 https://medcitynews.com/?p=611980

MedCrypt, a San Diego-based provider of cybersecurity solutions for medical devices, recently closed a $25 million Series B funding round. The startup sells its software to medical devices manufacturers so they can enhance the security of their products, which range from pacemakers to CT scanners.

]]>
https://medcitynews.com/2022/11/medical-device-security-startup-reels-in-25m-as-cyber-threats-escalate/feed/ 0 611980
Patient Files Class-action Suit Against Advocate Aurora Health Following Data Breach https://medcitynews.com/2022/11/class-action-suit-advocate-aurora-health-data-breach-3-million-patients/ https://medcitynews.com/2022/11/class-action-suit-advocate-aurora-health-data-breach-3-million-patients/#respond Tue, 01 Nov 2022 23:52:12 +0000 https://medcitynews.com/?p=611326 Data breach, cybersecurity, hacking,

The patient is alleging that the patient portal he used to communicate with his doctors at Advocate Aurora and to schedule appointments used a pixelated code that also enabled logging in via Facebook and then shared data with Facebook.

]]>
https://medcitynews.com/2022/11/class-action-suit-advocate-aurora-health-data-breach-3-million-patients/feed/ 0 611326