AHA Calls for HHS to Drop Website Tracking Technology Rule
The American Hospital Association (AHA) has called for Congress to urge the Department of Health and Human Services to withdraw its new rule that prohibits HIPAA-regulated entities from using online tracking technologies on their websites and applications. The AHA represents more than 5,000 member hospitals, health systems, and other healthcare organizations, and its clinician partners include more than 270,000 affiliated physicians and 2 million nurses and other caregivers. The AHA requested the withdrawal of the rule in its response to Sen. Bill Cassidy’s recent request for information on health information privacy and the Health Insurance Portability and Accountability Act of 1996 (HIPAA). Online tracking technologies include Google Analytics and Meta Pixel code, which are used by hospitals for collecting and analyzing information about how individuals interact on their websites. The information collected through these tools helps hospitals to make improvements to their online portals and provide relevant and reliable health information to their communities. A study conducted in...
Amerita Named in Class Action Lawsuit Over Data Breach at PharMerica
The specialty infusion company Amerita is facing a class action lawsuit over a recent cyberattack and data breach at its parent company, PharMerica. On September 5, 2023, suspicious activity was detected within the computer networks of PharMerica and Amerita. The forensic investigation confirmed that an unauthorized third party gained access to its systems between March 12 and March 13, 2023, and potentially accessed the sensitive data of 5.8 million individuals. PharMerica reported the breach on behalf of itself and its parent company, BrightSpring Health Services. The personal and protected health information of almost 220,000 Amerita patients was also compromised in the attack, including names, addresses, diagnoses, medications, and health insurance information. The Money Message ransomware group claimed responsibility for the attack and claimed on its data leak site to have stolen 4.7 terabytes of data, and then proceeded to leak certain files, some of which contained patient data. Class action lawsuits have already been filed against PharMerica over the data breach, and now a...
Cybersecurity Awareness Month 2023 Focuses on 4 Key Behaviors
The Cybersecurity and Infrastructure Security Agency (CISA) has launched a new cybersecurity awareness program – Secure Our World – through which the agency will be promoting behavioral change across the nation. The aim of the campaign is to get individuals, families, and small- to medium-sized businesses to take action every day to protect themselves while online and when using connected devices. The new campaign was launched as part of Cybersecurity Awareness Month, which this year focuses on four key behaviors that can greatly improve security when they are consistently adopted across an organization: Using strong passwords and a password manager Implementing multifactor authentication Learning how to recognize phishing and reporting phishing attempts Updating software promptly While organizations should consider transitioning to passwordless authentication, until it can be fully implemented it is vital to ensure that password best practices are followed. Strong, unique passwords should be sent for each account, with passwords consisting of random letters, numbers, and special...
79% Of Healthcare Organizations Experienced an API Security Incident in the Past 12 Months
78% of healthcare organizations experienced an Application Programming Interface (API) security incident in the past 12 months, up 9% from 2022, according to a new survey from Noname Security. APIs continue to pose significant risks to organizations and security incidents are increasing, especially in industries that store large volumes of personally identifiable information such as healthcare, eCommerce, and financial services, which saw the biggest increases in attacks. Healthcare experienced the biggest increase in API security incidents out of the 6 industries represented in the study and is the second most likely industry to experience an API security incident, behind financial services. Healthcare organizations need to share information internally between different medical systems, communicate data to other healthcare organizations, and share medical records with patients’ personal health and well-being devices, with data sharing facilitated through APIs. While APIs facilitate compliant data sharing, the lack of data standards across the industry and multiple siloed...
FDA Publishes New Guidance on Medical Device Cybersecurity Requirements
The U.S. Food and Drug Administration (FDA) has published new guidance on its requirement for medical device manufacturers to include details of the cybersecurity measures that have been implemented for new products in premarket submissions. Medical devices with wireless, internet, and network-connected capabilities are increasingly being used in healthcare and while these devices have helped to improve the care provided to patients, they have the potential to threaten patient safety if they lack appropriate cybersecurity protections. Cyberattacks on the healthcare industry have increased, with advanced persistent threat actors and cybercriminal groups actively targeting the sector. Many attacks have rendered medical devices inoperable and have forced critical IT systems to be shut down which have clinical impacts that put patient safety at risk, such as delaying diagnoses and treatments. “Increased connectivity has resulted in individual devices operating as single elements of larger medical device systems. These systems can include healthcare facility networks, other devices, and...



