FBI warns healthcare companies about hacker threat
The FBI has issued a warning that hackers are actively targeting the healthcare industry, reports Reuters.
The announcement follows the recent attack on hospital group Community Health Systems, which put the personal information of about 4.5 million patients at risk.
"The FBI has observed malicious actors targeting healthcare related systems, perhaps for the purpose of obtaining protected healthcare information and/or personally identifiable information," the FBI said in a "flash" alert directed to healthcare companies, according to Reuters.
"These actors have also been seen targeting multiple companies in the healthcare and medical device industry typically targeting valuable intellectual property, such as medical device and equipment development data,” the agency said in the notice.
Representatives from the FBI, Dept. of Homeland Security, HITRUST and other organizations addressed the CHS breach during its Aug. 21 monthly cyberthreat briefing.
The FBI's alert is not directly linked to the CHS breach but there are similarities in targets, methods and stolen and sought data, said Michael Rosanova, FBI supervisory special agent. Information security consulting firm TrustedSec said the CHS attackers exploited CVE-2014-0160, also known as the "heartbleed" vulnerability.
During the briefing, HITRUST CEO Daniel Nutkis said his organization has fielded numerous queries regarding the CHS breach such as the implications to their organizations, other potential risks and steps to be taken to mitigate risk. The breach led to a lot of speculative coverage but he acknowledged a lack of empirical information.