Literature Review

All posts tagged with “Technology / Innovations News | Cyberattack / Ransomware.”



Ascension president addresses UN on cyberattacks

11/13/24 at 03:00 AM

Ascension president addresses UN on cyberattacks Becker's Hospital Review; by Kristin Kuchno; 11/11/24 Eduardo Conrado, president of St. Louis-based Ascension, discussed the health system's May ransomware attack at a Nov. 8 United Nations Security Council meeting. The council met to discuss strategies for countering cyberattacks in healthcare, according to a Nov. 8 news release from the U.N. Ascension's response to the May 8 ransomware attack cost the health system approximately $130 million. The attack forced its hospitals and clinics off its EHR system and disrupted key diagnostic services, including MRIs and CT scans. ... "Overnight, nurses were unable to quickly look up patient records from the computer stations and were forced to comb through paper back-ups for patient medical history and medications," Mr. Conrado said at the meeting.  ... A comprehensive approach is key, Tedros Adhanom Ghebreyesus, PhD, director-general of the World Health Organization, told the U.N. "Countries should invest not only in technologies for detecting and mitigating cyberattacks but in training staff to respond to them," he added...

Read More

Microsoft update warning—400 million Windows PCs now at risk

11/01/24 at 03:00 AM

Microsoft update warning—400 million Windows PCs now at risk Forbes; by Zak Doffman; 10/30/24 Here we go again. Previously fixed Windows vulnerabilities are back to haunt users. And with perfect timing, there’s also a serious new warning for at least 400 million users, all of whom need to act to keep their PCs and data safe from attack. This is all about timing. The public interest advocacy group PIRG is now campaigning for Microsoft to extend the Windows 10 support extension now available to schools to other users. “In one year, Microsoft plans to end support for Windows 10,” they warn, “potentially rendering up to 400 million computers obsolete overnight. This decision could trigger the single largest surge in junked computers in history, with dire consequences for both consumers and the environment.” 

Read More

A new low? Hacker group targets end-of-life pharmacy provider

10/30/24 at 03:00 AM

A new low? Hacker group targets end-of-life pharmacy provider TechInformed (TI); by Ann-Marie Corvin; 10/28/24 OnePoint Patient Care, an Arizona-based hospice pharmacy serving over 40,000 patients per day, has informed customers about a data breach impacting personal information. OnePoint said it first detected suspicious activity on its network in early August. A later investigation revealed that by this point, the attackers had already obtained files containing personal information from the pharmacy’s systems, including names, residence information, medical records, and prescription and diagnosis information. OPPC told the US Department of Health and Human Services that the data breach impacted over 795,000 people.

Read More

Change Healthcare cyberattack impacts 100 million people

10/28/24 at 03:00 AM

Change Healthcare cyberattack impacts 100 million people Becker's Health IT; by Naomi Diaz; 10/25/24 The Feb. 21 ransomware attack on UnitedHealth Group subsidiary Change Healthcare has impacted 100 million individuals. The number of impacted individuals was posted on the Office for Civil Rights Breach Portal, which is used for reporting breaches of unsecured protected health information under HIPAA. Previously, UnitedHealth said that the data stolen by hackers likely covered a "substantial proportion of people in America." The cyberattack crippled financial operations for hospitals, insurers, pharmacies and medical groups nationwide. In July, the organization began sending out breach notification letters to individuals affected by the attack.  

Read More

CIOs must prepare their organizations today for quantum-safe cryptography

10/28/24 at 03:00 AM

CIOs must prepare their organizations today for quantum-safe cryptography IBM; by Mark Hughes, Joachim Schäfer and Arfan Sabar; 10/24/24Quantum computers are emerging from the pure research phase and becoming useful tools. They are used across industries and organizations to explore the frontiers of challenges in healthcare and life sciences, high energy physics, materials development, optimization and sustainability. However, as quantum computers scale, they will also be able to solve certain hard mathematical problems on which today’s public key cryptography relies. A future cryptographically relevant quantum computer (CRQC) might break globally used asymmetric cryptography algorithms that currently help ensure the confidentiality and integrity of data and the authenticity of systems access.The risks imposed by a CRQC are far-reaching: possible data breaches, digital infrastructure disruptions and even widescale global manipulation. These future quantum computers will be among the biggest risks to the digital economy and pose a significant cyber risk to businesses. ... [Click on the title's link to continue reading.]

Read More

Why recent outages are a wake-up call for healthcare and regulators

10/14/24 at 03:00 AM

Why recent outages are a wake-up call for healthcare and regulators Forbes; by Chris Bowen; 10/11/24 When the CrowdStrike outage first started to show itself in the early hours of that hazy July morning, it was hard to believe that this wasn’t a hack or cyberattack. I was driving in my car that morning and looked up to see a digital billboard glitch into the "blue screen of death" before my eyes. Flights were grounded, travel was delayed, and nearly every Windows machine in the world was unusable. It was total mayhem. Clearly, this was an outage of major proportions, as millions of Windows systems worldwide essentially cratered. Caused by a faulty misconfiguration, we saw firsthand how the very digital advancements that have helped transform and modernize our world also expose us to more vulnerabilities than ever. ... In healthcare, this event laid bare the vulnerabilities we cannot overlook—the gaps that directly threaten patient care and safety. It’s a clear reminder of our industry’s utmost responsibility to patient privacy and well-being. ...

Read More

Ransomware attack at Texas health system spreads

10/10/24 at 03:00 AM

Ransomware attack at Texas health system spreadsBecker's Health IT; by Giles Bruce; 10/9/24When hackers strike a health system, it can have far-reaching effects beyond just the original target. That's been the case with the Sept. 26 ransomware attack against Lubbock, Texas-based UMC Health System. That event has also ensnared Lubbock-based Texas Tech University Health Sciences Center and Texas Tech Physicians, which share IT systems with UMC Health. The medical school and its affiliated physician group are now in downtime, unable to access their EHR or receive patient portal messages or faxes. Their phone lines are experiencing intermittent outages as well. However, their clinics remain open, as do their pharmacies, albeit with reduced capacity.

Read More

SNF, home health [and hospice] CEOs could be jailed over cybersecurity issues under new bill

10/02/24 at 03:00 AM

SNF, home health [and hospice] CEOs could be jailed over cybersecurity issues under new billMcKnight's Senior Living; by Kathleen Steele Gaivin; 9/30/24New legislation aimed at improving cybersecurity in healthcare could see leaders at skilled nursing facilities, home health agencies and hospices jailed if they lie about their cybersecurity precautions, according to one of its sponsors. Senate Finance Committee Chair Ron Wyden (D-OR) and Sen. Mark Warner (D-VA) announced the Health Infrastructure Security and Accountability Act on Thursday. The bill also covers other types of healthcare businesses. “The healthcare industry has some of the worst cybersecurity practices in the nation despite its critical importance to Americans’ well-being and privacy,” Wyden said. “These commonsense reforms, which include jail time for CEOs that lie to the government about their cybersecurity, will set a course to beef up cybersecurity among healthcare companies across the nation and stem the tide of cyberattacks that threaten to cripple the American healthcare system.”

Read More

77% of health system IT employees eyeing new jobs

09/26/24 at 03:00 AM

77% of health system IT employees eyeing new jobs Becker's Health IT; Naomi Diaz; 9/25/24 Health system IT employees are keeping their options open, with 77% actively seeking new jobs or planning to do so within the next year, according to Bloomforce's "2024 EHR Salary Insights Report." The report, based on an online survey conducted between November and December 2023, gathered responses from 284 healthcare professionals across various roles, including application analysts, team leads, project managers and people managers. It explored areas such as salary, job satisfaction, work-life balance, talent retention and attitudes toward remote work. Here are some key findings from the report: [Click on the title's link to read more.]

Read More

Ascension posts $1.8B annual loss; liquidity 'remains strong,' CFO says

09/23/24 at 03:00 AM

Ascension posts $1.8B annual loss; liquidity 'remains strong,' CFO says Becker's Hospital CFO Report; by Alan Condon; 9/18/24 St.Louis-based Ascension reported a $79 million operating loss (-0.3% margin) for the 10 months ending April 30, a substantial improvement on the $1.2 billion operating loss in the previous 10-month period. The results include $402 million in one-time, non-cash write-downs and non-recurring losses. In May and June 2024, operations were hampered by the May ransomware attack, resulting in reduced revenues from the associated business interruption along with costs incurred to address the issues and other business-related expenses. Despite this incident, Ascension drove a $1.2 billion operational improvement year over year for the 10 months ending April 30. The 136-hospital system's economic improvement plans focused on volume growth, rates and pricing, and cost levers. 

Read More

CMS teases new cybersecurity policies for third-party vendors

09/14/24 at 03:00 AM

CMS teases new cybersecurity policies for third-party vendors Modern Healthcare; by Bridget Early; 9/13/24 The Centers for Medicare and Medicaid Services is planning oversight of third-party healthcare vendors in the wake of the Change Healthcare cyberattack, said Jonathan Blum, the agency's principal deputy administrator. Blum, who also serves as chief operating officer for CMS, said at Modern Healthcare's Leadership Symposium Thursday that the agency is working to determine what levers it can pull to ensure severe disruptions in care like those linked to the cyberattack on the UnitedHealth Group subsidiary aren’t repeated. ... Almost 133 million individuals were affected by healthcare data breaches last year, more than double the number of those affected in 2022 and a number equivalent to about 40% of the U.S. population.

Read More

Leadership in the age of AI: At the crossroads of humanity and technology

09/11/24 at 03:00 AM

Leadership in the age of AI: At the crossroads of humanity and technology Forbes; by Dr. Adil Dalal, DBA; 9/9/24 It has only been 200 years since the First Industrial Revolution and the mass adoption of what we now call technology... The Second Industrial Revolution in the late 19th and early 20th centuries, marked by great progress in mass production, ... emphasizing the importance of machines over humans and managers over employees. ... Today, the world stands on the precipice of the Fourth Industrial Revolution with artificial intelligence, which is not just reshaping industries but also redefining the very essence of leadership and decision-making. ...  A technology-driven leader [TDL] who prioritizes novelty over humanity can pose significant risks, potentially leading to societal downfall. ... A human-centric leader [HCL] prioritizes the well-being, growth and empowerment of people, steering humanity toward greatness. ... So is there an ideal Technology Age leader who can lead humanity through this historical moment? Yes! ... They must embody and demonstrate the following three qualities:

Read More

The changing role of chief privacy officers

09/10/24 at 03:00 AM

The changing role of chief privacy officers Becker's Health IT; by Giles Bruce; 9/6/24 Chief privacy officers are expanding their roles to take on artificial intelligence and cybersecurity, according to the International Association of Privacy Professionals. Whereas chief privacy officers traditionally focused on being compliant with privacy laws, 69% now have responsibility for AI or data governance, 37% cover cybersecurity regulatory compliance, and 20% have platform liability duties, according to the IAPP survey of 671 professionals released Sept. 6. Some health systems have standalone chief privacy officers, but the hospital industry is more likely to have chief information security officers with privacy duties or a combined role. 

Read More

The biggest threat in health IT and RCM

09/09/24 at 03:00 AM

The biggest threat in health IT and RCM Becker's Hospital Review; by Randi Haseman; 9/6/24 Are organizations adopting AI technology too quickly or too slowly? And what's the future of payer relationships? ... As part of an ongoing series, Becker's is talking to healthcare leaders who will speak at our conference. ... Question: What is the biggest threat in health IT and RCM right now? [Responses from 47 executives featured in this article address the following and more: payer programs; modernizing legacy systems while ensuring data security and compliance; cyber-crime / cybersecurity; relieving provider and staff burden thgouth clinical workflows; state and federal legislation; human error; Gen AI 'mission-creep'; extended systems downtimes; the velocity of technical disruption; more ...]

Read More

It could happen to you — how to prepare for and mitigate the fallout from a cyberattack

09/03/24 at 03:00 AM

It could happen to you — how to prepare for and mitigate the fallout from a cyberattackMcKnight's Senior Living; by Kimberly Bonvissuto;8/28/24Everyone thinks they know about cybersecurity, but thinking about the effects a cyberattack could have on an organization should be enough to lose sleep over, according to risk management experts. ... Cybersecurity, at its core, is about confidentiality, integrity and availability, according to John P. DiMaggio, co-founder and CEO of Blue Orange Compliance, a risk assessment company. Including senior living in the definition of healthcare, he said that healthcare organizations are targets of cyber criminals because of their relatively weak defenses, the value of the data necessary for operations, and the numerous interfaces and sharing of information that occurs among providers. ... Reasonable security practices — considered the minimum — include risk analysis and management, access control measures, training, incident response planning, physical controls, technical safeguards, third party/vendor management, backup and disaster recovery and patch management. But DiMaggio recommended going above that minimum threshold by using recognized security practices to mitigate penalties and ensure regulatory compliance. Those practices, he said, include email and endpoint protection, access management, data loss prevention, asset and network management, vulnerability management, incident response, medical device security and cybersecurity policies.

Read More

Empowering patient access, protection, and choice: The 21st Century Cures Act eight years on

08/01/24 at 03:00 AM

Empowering patient access, protection, and choice: The 21st Century Cures Act eight years on Healthcare Business Today; by David Navarro; 7/26/24 The 21st Century Cures Act, signed into law in December 2016, marked a significant shift in the healthcare landscape by focusing on patient empowerment through enhanced access to medical records, stringent privacy protections, and increased choices in healthcare options. Eight years later, this landmark legislation continues to revolutionize the interaction between patients, providers, and the healthcare system. Recently, The U.S. Department of Health and Human Services (HHS) issued an updated ruling to the Act to establish penalties for healthcare providers who engage in information blocking. This rule, aims to deter practices that prevent or discourage the access, exchange, or use of electronic health information (EHI).

Read More

Optimizing patient data transfer processes in healthcare settings

08/01/24 at 03:00 AM

Optimizing patient data transfer processes in healthcare settings Healthcare Business Today; by Majed Alhajry; 7/28/24 Managing and transferring large and often sensitive datasets is a routine yet critical task for healthcare organizations. Practitioners and administrators regularly share substantial files containing sensitive personal health information (PHI) that must be sent not only securely and reliably, but also quickly. So how should healthcare organizations send large files? ... 

Read More

Following the CrowdStrike outage, healthcare stresses the importance of prevention

07/31/24 at 03:00 AM

Following the CrowdStrike outage, healthcare stresses the importance of prevention HealthCare Brew; by Cassie McGrath; 7/25/24... [The recent CrowdStrike outage] affected millions across all sorts of industries, from healthcare to travel. ... However, amid the chaos, what has largely gone untold are stories of the companies that emerged unscathed. And within those unaffected companies lies a lesson for others, according to Andrew Molosky, president and CEO of Tampa-based Chapters Health System. ... “We’ve really focused on business continuity, redundancies, safety nets, and understanding of the difference between cybersecurity as a task and cybersecurity as a cultural commitment of your organization,” Molosky said. ... These investments, Molosky said, included protocols for documenting on paper, using a backup application that provides patient information when electronic medical records and other systems are offline, and allowances for bringing in personal devices to use if company devices go down. 

Read More

HHS unveils major revamp to shift health data, AI strategy and policy under ONC

07/31/24 at 03:00 AM

HHS unveils major revamp to shift health data, AI strategy and policy under ONC Fierce Healthcare; by Emma Beavins; 7/25/24 The Office of the National Coordinator for Health Information Technology (ONC) has been renamed and restructured, the Department of Health and Human Services (HHS) announced [July 25]. The restructuring will affect technology, cybersecurity, data and artificial intelligence strategy and policy functions. The agency will be renamed the Office of the Assistant Secretary for Technology Policy and Office of the National Coordinator for Health Information Technology (ASTP/ONC). Head of ONC, Micky Tripathi, will hold the new title of assistant secretary for technology policy in addition to his title of national coordinator for health IT. ... Under ASTP, there will be an Office of Policy, an Office of Technology, an Office of Standards, Certification and Analysis and an Office of the Chief Operating Officer. 

Read More

Baptist Health taps 3 vendors to build a population health system that works

07/29/24 at 03:00 AM

Baptist Health taps 3 vendors to build a population health system that works Healthcare IT News; by Bill Siwicki; 7/26/24With help from Oracle, Innovaccer and Salesforce, the South Florida provider is scoring big population health wins, including a 7% increase in coding gap closure rate and a 17% increase in annual wellness visit completion rates. Baptist Health South Florida operates a network of 11 hospitals covering four counties. It also includes numerous ambulatory facilities, urgent care centers and emergency departments to provide comprehensive healthcare services across the region. ... "One of our primary issues was the fragmented nature of patient data across multiple provider organizations and electronic health record systems," said Milady Cervera, vice president, population health and physician integrated networks, at Baptist Health South Florida. "This lack of interoperability made it difficult to gain a comprehensive view of our patients' health status, care history and ongoing needs. ..."

Read More

Keeping staff members safe and sound by optimizing security technology

07/15/24 at 03:00 AM

Keeping staff members safe and sound by optimizing security technology Security; by Paul Sarnese; 7/12/24 Nobody wants to invest in technology, only to have it go the way of the stationary bike that sits unused in the corner of a room. That holds true for healthcare organization leaders who are looking to invest in staff safety alarm systems that can help avert potentially dangerous situations. With workplace violence against caregivers increasing 115% since 2021, many healthcare organizations are, indeed, looking to protect workers from harm — and to shield their organizations from resultant financial distress.Editor's Note: Workplace violence and staff safety continues to trend as a root cause for nursing and other healthcare strikes across the nation. Examine your organization's Incident Reports and QAPI initiatives. What needs to be addressed?

Read More

Health systems oppose new cybersecurity rules

07/11/24 at 03:00 AM

Health systems oppose new cybersecurity rules Becker's Health IT; by Giles Bruce; 7/8/24 Health systems and industry trade groups are objecting to new cybersecurity reporting requirements proposed by the Cybersecurity and Infrastructure Security Agency. The recommended rule under the Cyber Incident Reporting for Critical Infrastructure Act of 2022 would, among other things, require covered entities to report cyberattacks within 72 hours and ransom payments within 24 hours. The proposal, which is estimated to cost the industry $1.4 billion, would exempt small and critical access hospitals.

Read More

7 of the top tech and IT jobs in demand for the future

06/28/24 at 03:00 AM

7 of the top tech and IT jobs in demand for the future TechTarget; by David Weldon; 6/24/24 Businesses of the future will rely on workers with IT skills even more than they do today. Find out which jobs might be most in demand and what those roles entail. ... Organizations are having to create new tech roles and redefine existing ones to manage the integration of AI and data into core business functions. Meanwhile, cybersecurity continues to be a top concern, as do digital transformation and cloud computing. These challenges are increasing the demand for job roles that merge technical expertise with strategic business acumen. ... So, what will be some of the hottest IT jobs of the future? ... Roles are listed in alphabetical order. 

Read More

Telemedicine and e-Health: May issue

06/26/24 at 03:00 AM

Telemedicine and e-Health: May issue Telemedicine and e-Health; Editor-in-Chief Charles R. Doearn, MBA, FATA and Executive Editor Karen Rheuban, MD, FATA; published monthly The leading peer-reviewed journal for cutting-edge telemedicine applications for achieving optimal patient care and outcomes. [Relevant titles include the following. These are included in this current May's print edition, many were previously published "online ahead of print."]

Read More

Ransomware spikes after Change hack

06/18/24 at 03:00 AM

Ransomware spikes after Change hack Becker's Health IT; by Naomi Diaz; 6/13/24 Following Change Healthcare's admission that it paid off hackers after its ransomware attack, there has been a spike in healthcare-related cyber incidents, Wired reported June 12. In April, cybersecurity firm Recorded Future identified 44 instances of cybercriminal groups targeting healthcare organizations with ransomware attacks. These attacks involved stealing data, encrypting systems and demanding ransom payments while holding networks hostage. This marks the highest number of healthcare ransomware victims recorded in a single month during Recorded Future's four years of data collection, Allan Liska, a threat intelligence analyst at the company told Wired. 

Read More