79% Of Healthcare Organizations Experienced an API Security Incident in the Past 12 Months
78% of healthcare organizations experienced an Application Programming Interface (API) security incident in the past 12 months, up 9% from 2022, according to a new survey from Noname Security. APIs continue to pose significant risks to organizations and security incidents are increasing, especially in industries that store large volumes of personally identifiable information such as healthcare, eCommerce, and financial services, which saw the biggest increases in attacks. Healthcare experienced the biggest increase in API security incidents out of the 6 industries represented in the study and is the second most likely industry to experience an API security incident, behind financial services. Healthcare organizations need to share information internally between different medical systems, communicate data to other healthcare organizations, and share medical records with patients’ personal health and well-being devices, with data sharing facilitated through APIs. While APIs facilitate compliant data sharing, the lack of data standards across the industry and multiple siloed...
FDA Publishes New Guidance on Medical Device Cybersecurity Requirements
The U.S. Food and Drug Administration (FDA) has published new guidance on its requirement for medical device manufacturers to include details of the cybersecurity measures that have been implemented for new products in premarket submissions. Medical devices with wireless, internet, and network-connected capabilities are increasingly being used in healthcare and while these devices have helped to improve the care provided to patients, they have the potential to threaten patient safety if they lack appropriate cybersecurity protections. Cyberattacks on the healthcare industry have increased, with advanced persistent threat actors and cybercriminal groups actively targeting the sector. Many attacks have rendered medical devices inoperable and have forced critical IT systems to be shut down which have clinical impacts that put patient safety at risk, such as delaying diagnoses and treatments. “Increased connectivity has resulted in individual devices operating as single elements of larger medical device systems. These systems can include healthcare facility networks, other devices, and...
Users of Progress Software WS_FTP Server Urged to Immediately Upgrade
Progress Software, the company behind the MOVEit Transfer file transfer solution that was recently subject to mass hacking and data theft attacks by the Clop threat group, has issued a warning to all users of its WS_FTP Server file transfer software to apply patches to fix 8 vulnerabilities, including two critical flaws that can be exploited in low-complexity attacks that require no user interaction. The vulnerabilities affect the WS_FTP Server Ad hoc Transfer Module and the WS_FTP Server Manager interface. CVE-2023-40444 (CVSS: 10) is a maximum-severity remote code execution vulnerability that affects all versions of WS_FTP Server prior to 8.7.4 and 8.8.2. A pre-authenticated attacker could exploit a .NET deserialization vulnerability in the Ad hoc Transfer Module and remotely execute commands on the underlying WS_FTP Server operating system. CVE-2023-42657 (CVSS: 9.9) is a critical directory traversal vulnerability that affects all versions of WS_FTP Server prior to 8.7.4 and 8.8.2. Successful exploitation of the vulnerability would allow an attacker to perform file operations...
The HIPAA Journal’s Response to Sen. Cassidy’s RFI on Health Data Privacy
Dear Sen. Cassidy, The HIPAA Journal appreciates the opportunity to submit comments per your September 7, 2023, request for information on improving health data privacy while balancing the need to support medical research and medical technology innovation, specifically with respect to potential Health Insurance Portability and Accountability Act (HIPAA) updates. While HIPAA is not perfect, it has served as an effective framework that restricts uses and disclosures of protected health information (PHI) while allowing legitimate uses of healthcare data, and requires covered entities and their business associates that collect, store, maintain, and transmit PHI implement appropriate safeguards to ensure the privacy of PHI. It has been two decades since the HIPAA Privacy and Security Rules were signed into law, during which time the amount of health information collected by non-HIPAA-regulated entities has been increasing to a point where the health data collected by non-HIPAA-covered entities through fitness trackers, mobile devices, and health apps likely exceeds the data collected by...
Interview: Rachel Sheley, Security Strategist/vCISO, GreyCastle Security
The HIPAA Journal has spoken with Rachel Sheley, Security Strategist and Virtual Chief Information Security Officer (vCISO) at GreyCastle Security to find out about her career in the healthcare industry, her current role in cybersecurity, and her experiences with HIPAA compliance. Tell the readers about your career in the healthcare industry. My career in the healthcare industry has been centered around ensuring the confidentiality, integrity, and availability of healthcare data while navigating the complex landscape of healthcare regulations. My expertise in information security, risk management, and compliance is crucial in safeguarding patient information and maintaining the trust of healthcare organizations and their patients. Obtaining the Healthcare Information Security & Privacy Practitioner (HCISPP) certification in 2019 indicates my knowledge of healthcare information security and privacy. This certification is highly relevant in the healthcare sector, as it demonstrates expertise in safeguarding sensitive healthcare data, complying with regulations like HIPAA, and...



