Survey Highlights Ongoing Healthcare Cybersecurity Challenges
The healthcare industry continues to experience high numbers of cyberattacks and data breaches and healthcare organizations have responded by strengthening their cybersecurity programs, but they continue to face significant challenges, the biggest of which is a lack of cybersecurity staff. That was cited as the main barrier to robust cybersecurity by 61% of respondents to the 2022 HIMSS Healthcare Cybersecurity Survey of healthcare cybersecurity professionals responsible for day-to-day operations or oversight of healthcare cybersecurity programs. The biggest problem is hiring talent. There is a global shortage of cybersecurity professionals, and with the demand for staff high, qualified cybersecurity professionals can afford to pick and choose employers carefully. Almost 84% of respondents said they struggle to attract skilled staff. Unsurprisingly, given the high demand for staff, an insufficient budget for hiring staff was a problem for 55% of respondents, with non-competitive compensation cited as a problem for 43% of respondents. When skilled cybersecurity professionals are...
ONC Proposes New Rule to Advance Care Through Technology and Interoperability
The HHS’ Office of the National Coordinator of Health IT has proposed a new rule that is intended to advance care through technology and interoperability. The new rule – Health Data, Technology, and Interoperability: Certification Program Updates, Algorithm Transparency, and Information Sharing (HTI) – implements certain provisions of the 21st Century Cures Act and makes enhancements to the ONC Health IT Certification Program. The aim of the new rule, which runs to 556 pages, is to advance interoperability, improve transparency, and support the access, exchange, and use of electronic health information which will help to promote innovation and improve data security. The updates cover the movement of health information, introduce new data standards, improve electronic case reporting to support the response to a public health emergency, ensure greater transparency of artificial intelligence algorithms, and changes to improve patient privacy. Implementing the Electronic Health Record Reporting Program The new rule implements the 21st Century Cures Act requirement to establish an EHR...
CISA Updates its Zero Trust Maturity Model
The Cybersecurity and Infrastructure Security Agency (CISA) has released an updated version of its Zero Trust Maturity Model, the purpose of which is to help federal agencies adopt zero trust security. While the guidance is primarily intended for federal agencies, it can be used by any organization looking to improve its security posture through zero trust. The traditional approach to security involves perimeter defenses to keep unauthorized individuals out of protected internal networks, where anyone inside the network is trusted. The perimeter security model has served organizations well for many years, but it is only effective when there is a border to protect and the vast majority of IT resources and critical assets are inside that border. Today, most networks are not entirely on-premises and remote working is now common, so many trusted individuals are outside of the border. Further, with perimeter security, if the perimeter is breached, an attacker could compromise large parts of the network, IT resources, and critical data. Zero trust is based on the assumption that a...
Online Alcohol Counseling Service Provider Reports 109K-record Tracking Tool Data Breach
Monument Inc., a New York-based online alcohol addiction and treatment service provider, has recently notified almost 109,000 individuals about an impermissible disclosure of some of their personal and protected health information. The disclosure occurred due to the use of tracking code on its websites. Monument explained in its breach notification letters that an internal review was conducted in late 2022 into the use of website tracking tools after guidance was issued by the HHS’ Office for Civil Rights on pixels and other tracking tools and how they may violate the HIPAA Rules. The internal review was completed on or around February 6, 2023, and it was determined that the tools on its websites potentially transferred identifiable protected health information to third parties who were unauthorized to receive the information, as consent to disclose that information was not obtained and there were no business associate agreements with the companies that provided the tools. The tracking tools were provided by Google, Facebook (Meta), Pinterest, and Bing, and while present on the...
ILS Data Breach Affects Almost 21K Iowan Medicaid Recipients
The Iowa Department of Health and Human Services (DHHS) has confirmed a HIPAA compliance breach where the personal information of 20,815 Iowans who receive Medicaid was exposed in a cyberattack at a subcontractor of one of its business associates between June 30, 2022, and July 5, 2022. Telligen performs annual assessments on Medicaid recipients for the Iowa DHSS. Telligen subcontracted part of the work to Independent Living Systems (ILS), and it was the systems of ILS that were breached. While ILS discovered the breach in July 2022, it took until February 14, 2023, for Telligen to be notified about the breach. Telligen notified the Iowa DHSS three days later on February 17, 2023. The DHSS will be sending notification letters to the affected individuals over the next few days. Independent Living Systems reported the breach to the HHS’ Office for Civil Rights using a 501 placeholder until the number of affected individuals is determined; however, the breach was reported to the Maine Attorney General as affecting more than 4 million individuals. You can read more about the...



