A biweekly collection of cyber-related articles affecting the healthcare industry, curated with the goal of helping NIHCC members improve their cybersecurity posture.

February 20, 2024

New Guides Aim to Help Health Sector Beef Up Cyber, Privacy

Two new guidance resources - one from government regulators and the other from an industry council - aim to help healthcare sector firms strengthen their approaches to protecting sensitive patient information and critical IT systems. The publications come as the Biden administration is pushing the sector to up its cyber game.

Link to Article

They're Back: HHS OCR Plans to Resurrect Random HIPAA Audits

As U.S. federal regulators fine-tune a strategy to push the healthcare sector into strengthening its cybersecurity posture, they are dusting off a HIPAA compliance audit program that's been dormant for the last seven years. A new round of HIPAA audits for regulated entities is in the works.

Link to Article

HHS alerts health sector to 21 new cyber vulnerabilities | AHA News

The health care sector should quickly implement patches or mitigations to address 21 new cyber vulnerabilities identified by the Cybersecurity and Infrastructure Security Agency in January, the Department of Health and Human Services' Health Sector Cybersecurity Coordination Center (HC3) advised this week.

Link to Article

Feds Warn Health Sector About Akira Again, Amid New Attacks

The Department of Health and Human Services' Health Sector Cybersecurity Coordination Center on Wednesday issued its second alert about Akira in the last five months, warning that while the ransomware gang has only been operating since March 2023, it has become "a significant threat" to the U.S. public and private health sectors

Link to Article

Boise State 'Cyberdome' program trains students in responding to cyberattacks | EdScoop

Students in a cybersecurity program at Boise State University in Idaho are helping rural schools and governments monitor for cyberattacks.

Link to Article

Russian Threat Actors Targeting the HPH Sector


Presentation by the HHS Office of Information Security and the Health Sector Cybersecurity Coordination Center.


https://www.hhs.gov/sites/default/files/russian-threat-actors-targeting-the-hph-sector-tlpclear.pdf

City of Coeur d'Alene finds malware in its computer system

The city of Coeur d'Alene announced Monday it had detected malware in its computer network the day before.

Link to Article

Bipartisan Senate Bill Requires HHS to Bolster Cyber Efforts

The Strengthening Cybersecurity in Health Care Act - introduced Friday by Sens. Angus King, I-Maine, and Marco Rubio, R-Fla. - is the latest congressional effort in recent months aimed at bolstering cybersecurity in the healthcare sector.

Link to Article

Integris Health says data breach impacts 2.4 million patients

The emails the patients received from the threat actor contained accurate information and linked to a website in the Tor network hosting the stolen details, but access was not free. Visitors could pay $50 and trust the attacker's word on removing the details, or pay $3 to view information belonging to any other impacted individual.

Link to Article

Chinese hacking campaign aimed at critical infrastructure goes back five years, US says

The U.S. National Security Agency, U.S. cyber watchdog CISA, the FBI, and the Transportation Security Administration said that the group known as "Volt Typhoon" had quietly burrowed into the networks of aviation, rail, mass transit, highway, maritime, pipeline, water and sewage organizations.

Link to Article

Cybercriminals have Small Town, USA, in their crosshairs: How to fight back

Bustling main streets. Neighbors and business owners who greet you with your first name. Independence Day parades. These are some of the hallmarks of small-town American life. Increasingly, cyberattacks are joining the list as threat actors set their sights on small-town America’s critical infrastructure.

Link to Article

Resources & Tools | CISA

CISA offers an array of free resources and tools, such as technical assistance, exercises, cybersecurity assessments, free training, and more.

Link to Website




This newsletter was made possible by Grant U2REP190572 from the Administration for Strategic Preparedness and Response (ASPR). Its contents are solely the responsibility of the authors and do not necessarily represent the official view of the Department or ASPR. Kootenai Health, 2024.