What is ISO/IEC 27001 in Healthcare?
ISO/IEC 27001 in healthcare is a standard for managing the security of confidential data that sets out a framework for establishing, implementing, maintaining, and continually improving an information security management system. Healthcare organizations that achieve ISO/IEC 27001 certification can use the certification to demonstrate a good faith attempt to comply with the HIPAA Security Rule. Most organizations in the healthcare sector are required to comply with the HIPAA Security Rule – a set of standards and implementation specifications designed to ensure the confidentiality, integrity, and availability of electronic Protected Health Information (ePHI). To fulfil the requirement, most organizations implement the necessary security controls and develop emergency preparedness plans. However, this approach to protecting the confidentiality, integrity, and availability of ePHI is not always effective. In its most recent report to Congress on reported breaches of unsecured PHI, HHS’ Office for Civil Rights received 64,180 notifications of data breaches affecting more than...
Emerging Ransomware Groups Disproportionately Attack Healthcare Organizations
Ransomware activity almost doubled in 2023 according to the annual GuidePoint Research and Intelligence Team (GRIT) Ransomware Report. The GRIT team identified 4,519 victims of ransomware attacks in 2023 up from 2,507 in 2022. The United States was the most targeted country accounting for 49% of attacks, with 8 out of the 10 most impacted countries located in North America or Europe. On average, 12.4 victims were posted on data leak sites each day in 2023, an 80.1% increase in public postings from 2022. While the increase was largely driven by mass exploitation campaigns, these attacks only accounted for 5% of total victims in 2023, showing there was also a significant increase in ransomware activity overall. The main ransomware players in 2023 were LockBit, Alphv, and Clop, with LockBit by far the most active, having conducted more attacks than Alphv and Clop combined. These established groups conducted 85% of attacks and used well-defined tactics. They are also drivers of innovation and tactical change across the ransomware ecosystem with emerging and developing groups tending to...
ITRC: Data Compromises Reach All-time High in 2023
There was a huge increase in data compromises in 2023 but a fall in the number of individuals affected by those incidents, according to the Identity Theft Resource Center’s (ITRC) 2023 Data Breach Report. There was a 78% increase in publicly reported data compromises in 2023 with 3,205 incidents reported which is a 72% increase from the previous high-water mark of 1,860 data compromises that was set in 2021. The increase in incidents is staggering, as ITRC CEO Eva Velasquez explained. “Just the increase from the past record high to 2023’s number is larger than the annual number of events from 2005 until 2020 (except for 2017).” Even with such a high percentage increase, the estimated number of individuals affected by data compromises fell by 16% year-over-year to 353,027,892 individuals. ITRC reports that there is a general downward trend in the number of individuals affected by data breaches as criminals are focusing on quality rather than quantity and are searching for specific information that can be used for identity-related fraud and scams rather than conducting mass attacks....
Florida Leads the Way for Affordable Care Act Plans
Florida leads the way for Affordable Care Act health insurance with 4.2 million people in the state having signed up for Affordable Care Act insurance plans, according to data from the Department of Health and Human Services (HHS). A record 21.4 million people across the United States have now signed up for Affordable Care Act insurance plans, including around 5 million new registrations and 16 million people who renewed their coverage in the Open Enrollment Period from November 1, 2023, to January 16, 2024. The high number of individuals with Affordable Care Act plans in Florida is partly due to the large population and also because many people have retired and moved to the state, which means they no longer have access to employer-sponsored coverage. Florida has the third highest number of uninsured people behind Texas and California and for many Florida residents, Affordable Care Act plans are the only option available. “For decades, when it came to federal programs we could depend on to keep Americans covered, three were always top of mind – Medicare, Medicaid, and Social...
Ann & Robert H. Lurie Children’s Hospital Responding to Cyberattack
On February 1, 2024, Ann & Robert H. Lurie Children’s Hospital in Chicago announced on its website and social media channels that it is responding to a cybersecurity incident and has been forced to take its network systems offline. The cyberattack has been reported to law enforcement agencies and Lurie Children’s is working collaboratively with those agencies and third-party cybersecurity experts to investigate the attack and bring network systems back online as soon as it is safe to do so. The 360-bed acute care hospital is a leading provider of pediatric care in Illinois and one of the biggest children’s healthcare providers in the Midwest, serving 239,000 children each year. The cyberattack has disrupted normal operations and caused delays to medical care for certain patients, with ultrasound and CT scan results temporarily unavailable. Some appointments and elective procedures have been canceled to ensure patient safety. The hospital has confirmed that its emergency services are unaffected, and it is operating under a first-come, first-served approach and is...



