Cybersecurity

The digital security of healthcare institutions and data is a growing concern, with an increasing number of cyberattacks each year against healthcare systems, which are seen as easy targets. Cyber attacks often use ransomware to target personal health information, patient data and medical devices to cut off access to the data until a ransom is payed to the hacker. Cybercriminals have become more sophisticated, using malware, ransomware and spyware to attack outdated and vulnerable systems and software. Due to the interconnected nature of hospital IT systems today, the weakest link can be older web-enabled medical devices, including clinical and non-clinical systems. Employees are also a major target of attacks via malicious e-mails that prompt them to open attachments that then download malware onto the hospital's IT system.

Phishing attack affects 16,000 in Michigan

A phishing attack on an employee's email is the source of a potential data breach affecting 16,000 patients of a Michigan practice. 

55K affected by employee's data theft

It's another inside job. In July, a former CVS Health employee inappropriately accessed the data of a California healthcare organization, compromising the information of 54,203 patients.

Vt. theft affects 2K patients

The health data of about 2,000 patients has been compromised after burglers broke into the medical offices of a family medicine physician in Vermont.

NY senator pushes cybersecurity bill in wake of Excellus breach

The latest widescale cyberattack led Sen. Charles Schumer (D-N.Y.) to urge Congress to draft a cybersecurity bill and prioritize the development of universal data breach notification standards.

Thumbnail

Another massive breach

Despite top stories regarding ICD-10, interoperability and more, privacy and security dominated the headlines in the healthcare arena again this week. 

Thumbnail

Report covers health data security offerings

Seventy percent of providers use an average of four different vendors to meet their security requirements, according to the inaugural report on healthcare security from KLAS.

NY Blues cyberattack affects 10M

New York insurer Excellus Blue Cross and Blue Shield has experienced a sophisticated cyberattack by hackers who may have gained access to over 10 million personal records. 

UCLA cleared in data breach lawsuit

A court has found that the UCLA Health System is not responsible for the unauthorized release of information from a woman's medical record and therefore the organization does not have to pay the $1.25 million the plaintiff sought for emotional distress and invasion of privacy.

Around the web

The tirzepatide shortage that first began in 2022 has been resolved. Drug companies distributing compounded versions of the popular drug now have two to three more months to distribute their remaining supply.

The 24 members of the House Task Force on AI—12 reps from each party—have posted a 253-page report detailing their bipartisan vision for encouraging innovation while minimizing risks. 

Merck sent Hansoh Pharma, a Chinese biopharmaceutical company, an upfront payment of $112 million to license a new investigational GLP-1 receptor agonist. There could be many more payments to come if certain milestones are met.