Literature Review
All posts tagged with “Technology / Innovations News | Cyberattack / Ransomware.”
L.A.-area cyber attack could impact 17m patient records
12/16/24 at 03:00 AML.A.-area cyber attack could impact 17m patient records GT - Government Technology - Cybersecurity; by Scott Schwebke; 12/12/24 Hackers claim they have retrieved 17 million patient records, including confidential personal and medical information, in a ransomware attack on PIH Health that has paralyzed operations at three hospitals, the Southern California News Group has learned. The Dec. 1 attack downed computer and most phone systems at PIH Health Downey Hospital, PIH Health Whittier Hospital and PIH Health Good Samaritan Hospital in Los Angeles. Also compromised were urgent care centers, doctors offices and a home health and hospice agency operated by PIH. PIH officials on Wednesday declined to comment on a threatening typewritten letter purportedly faxed by the cyber criminals late last week, saying they are working with a cyber forensic specialist and the FBI to untangle the ransomware attack. The FBI also declined to discuss the ongoing investigation.
Promoting the resilience of health care information systems—The day hospitals stood still
12/14/24 at 03:40 AMPromoting the resilience of health care information systems—The day hospitals stood stillJAMA Health Forum; Daniel B. Kramer, MD, MPH; Kevin Fu, PhD; 11/24On Friday, July 19, 2024, health care workers woke to emails declaring systemwide information technology (IT) emergencies. Because Crowdstrike had access to the most sensitive core parts of the Windows operating system, the automated process caused an immediate global outage of computer systems using the Crowdstrike Falcon product, which is embedded in many computer systems at health care organizations. Rather than accept this event as inherent to a complex, digitized, and wired health care ecosystem, we urge the US Congress, health care regulators, and the public to insist on proactive preventive methods to avoid future IT catastrophic events rather than simply waiting for the next disruptive crisis requiring an emergent response.
Top places to work in IT: 17 health systems rank in 2025
12/12/24 at 03:15 AMTop places to work in IT: 17 health systems rank in 2025 Becker's Health IT; by Laura Dyrda; 12/10/24 Computerworld published a list of the top places to work in IT for 2025, including several prominent health systems. Foundry, the publisher for Computerworld, examined several companies across the size spectrum on their commitment to in-house IT talent, training, technical and soft skills, as well as culture, diversity and satisfaction. The publication reported 79% of companies surveyed increased the number of IT employees in the last three years, and around half plan to continue growing their IT teams next year. The health systems and provider organizations ranked include:
Will AI help improve healthcare security in 2025?
12/12/24 at 03:00 AMWill AI help improve healthcare security in 2025? Health IT Answers; by Roberta Mullin; 12/10/24 The healthcare sector is particularly vulnerable to cybersecurity risks and the stakes for patient care and safety are particularly high. Healthcare facilities are attractive targets for cyber criminals in light of their size, technological dependence, sensitive data, and unique vulnerability to disruptions. Strengthening our cybersecurity infrastructure and defending against malicious attacks requires vigilance, vision, and collaboration. Can AI help improve healthcare security? We asked our experts what improvements to security we might see in 2025. Here is what they had to say. ... [Click on the title's link to read input from 21 healthcare IT experts.]
Protecting staff, patients and the business: Cybersecurity + compliance insights from Becker's/T-Mobile survey
12/11/24 at 03:00 AMProtecting staff, patients and the business: Cybersecurity + compliance insights from Becker's/T-Mobile surveyBecker's Hospital Review; 12/9/24 ... Becker's Healthcare and T-Mobile recently surveyed more than 125 healthcare leaders to learn about the communication tools they use, as well as their cybersecurity and compliance challenges. Insights from this whitepaper include:
PIH Health hospitals targeted in ransomware attack
12/06/24 at 03:00 AMPIH Health hospitals targeted in ransomware attack CBS News KCAL, Los Angeles, CA; by Laurie Perez and Dean Fioresi; 12/4/24 PIH Health was targeted in a ransomware attack, forcing officials to completely shut their network offline and leaving millions in the dark when it comes to healthcare. ... Officials say that they were targeted on Sunday by a "criminal act" that "compromised their network." In turn, network services were turned off at their hospitals in Downey, Whittier and downtown LA. ... "Meeting the healthcare needs of our communities remains our highest priority," said a statement from PIH Health. "We continue to provide care during our downtime procedures at all of our facilities, including all three hospitals, medical offices, home health, hospice, outpatient imaging and laboratory."
Critical components of the digital operating model in health
12/06/24 at 03:00 AMCritical components of the digital operating model in health bounteous x Accolite; by Abby Matchett; 12/4/24 ... To determine how to shape your resources and structure an operating model, you must first assess and evaluate several critical inputs, starting with the overall digital transformation strategy.
What healthcare CFOs don’t know about cybersecurity — and what they should ask their CISOs
12/05/24 at 03:00 AMWhat healthcare CFOs don’t know about cybersecurity — and what they should ask their CISOs Healthcare Finance Technology (HFMA); by Plante Moran; 12/2/24Cybersecurity is a growing concern for all healthcare organizations amid the ongoing rise of ransomware attacks and other threats. In 2023, the number of reported data breaches in the U.S. rose to an all-time high of 3,205, a 78% increase from 2022, while the average cost of a healthcare data breach hit $10.93 million. What’s driving these alarming figures isn’t necessarily a lack of technology or talent. ... By rethinking their approach to collaboration and risk management, healthcare CFOs can more effectively align security with both technology and the business to help their organizations become more resilient. ... How ready is our organization for an attack? ...
A people-centric approach powers successful digital transformations in healthcare
12/04/24 at 03:00 AMA people-centric approach powers successful digital transformations in healthcare HFMA - Healthcare Financial Management Association; by Utlimate Kronos Group; 12/2/24 Digital transformation is a high priority for C-suite executives at healthcare organizations, and a dizzying array of new technologies in a growing market is beckoning. But to succeed, leaders must be able to meld the use of technology with a people-first mindset and embrace their people focus in a systematic, measurable manner. ... McKinsey research suggests that almost 90% of health system executives believe that digital and AI transformation is a high or top priority for their organization, though 75% indicated that budget constraints and issues with legacy systems were hampering achievement of technology goals. ... [The discussion includes the following.]
Ascension president addresses UN on cyberattacks
11/13/24 at 03:00 AMAscension president addresses UN on cyberattacks Becker's Hospital Review; by Kristin Kuchno; 11/11/24 Eduardo Conrado, president of St. Louis-based Ascension, discussed the health system's May ransomware attack at a Nov. 8 United Nations Security Council meeting. The council met to discuss strategies for countering cyberattacks in healthcare, according to a Nov. 8 news release from the U.N. Ascension's response to the May 8 ransomware attack cost the health system approximately $130 million. The attack forced its hospitals and clinics off its EHR system and disrupted key diagnostic services, including MRIs and CT scans. ... "Overnight, nurses were unable to quickly look up patient records from the computer stations and were forced to comb through paper back-ups for patient medical history and medications," Mr. Conrado said at the meeting. ... A comprehensive approach is key, Tedros Adhanom Ghebreyesus, PhD, director-general of the World Health Organization, told the U.N. "Countries should invest not only in technologies for detecting and mitigating cyberattacks but in training staff to respond to them," he added...
Microsoft update warning—400 million Windows PCs now at risk
11/01/24 at 03:00 AMMicrosoft update warning—400 million Windows PCs now at risk Forbes; by Zak Doffman; 10/30/24 Here we go again. Previously fixed Windows vulnerabilities are back to haunt users. And with perfect timing, there’s also a serious new warning for at least 400 million users, all of whom need to act to keep their PCs and data safe from attack. This is all about timing. The public interest advocacy group PIRG is now campaigning for Microsoft to extend the Windows 10 support extension now available to schools to other users. “In one year, Microsoft plans to end support for Windows 10,” they warn, “potentially rendering up to 400 million computers obsolete overnight. This decision could trigger the single largest surge in junked computers in history, with dire consequences for both consumers and the environment.”
A new low? Hacker group targets end-of-life pharmacy provider
10/30/24 at 03:00 AMA new low? Hacker group targets end-of-life pharmacy provider TechInformed (TI); by Ann-Marie Corvin; 10/28/24 OnePoint Patient Care, an Arizona-based hospice pharmacy serving over 40,000 patients per day, has informed customers about a data breach impacting personal information. OnePoint said it first detected suspicious activity on its network in early August. A later investigation revealed that by this point, the attackers had already obtained files containing personal information from the pharmacy’s systems, including names, residence information, medical records, and prescription and diagnosis information. OPPC told the US Department of Health and Human Services that the data breach impacted over 795,000 people.
Change Healthcare cyberattack impacts 100 million people
10/28/24 at 03:00 AMChange Healthcare cyberattack impacts 100 million people Becker's Health IT; by Naomi Diaz; 10/25/24 The Feb. 21 ransomware attack on UnitedHealth Group subsidiary Change Healthcare has impacted 100 million individuals. The number of impacted individuals was posted on the Office for Civil Rights Breach Portal, which is used for reporting breaches of unsecured protected health information under HIPAA. Previously, UnitedHealth said that the data stolen by hackers likely covered a "substantial proportion of people in America." The cyberattack crippled financial operations for hospitals, insurers, pharmacies and medical groups nationwide. In July, the organization began sending out breach notification letters to individuals affected by the attack.
CIOs must prepare their organizations today for quantum-safe cryptography
10/28/24 at 03:00 AMCIOs must prepare their organizations today for quantum-safe cryptography IBM; by Mark Hughes, Joachim Schäfer and Arfan Sabar; 10/24/24Quantum computers are emerging from the pure research phase and becoming useful tools. They are used across industries and organizations to explore the frontiers of challenges in healthcare and life sciences, high energy physics, materials development, optimization and sustainability. However, as quantum computers scale, they will also be able to solve certain hard mathematical problems on which today’s public key cryptography relies. A future cryptographically relevant quantum computer (CRQC) might break globally used asymmetric cryptography algorithms that currently help ensure the confidentiality and integrity of data and the authenticity of systems access.The risks imposed by a CRQC are far-reaching: possible data breaches, digital infrastructure disruptions and even widescale global manipulation. These future quantum computers will be among the biggest risks to the digital economy and pose a significant cyber risk to businesses. ... [Click on the title's link to continue reading.]
Why recent outages are a wake-up call for healthcare and regulators
10/14/24 at 03:00 AMWhy recent outages are a wake-up call for healthcare and regulators Forbes; by Chris Bowen; 10/11/24 When the CrowdStrike outage first started to show itself in the early hours of that hazy July morning, it was hard to believe that this wasn’t a hack or cyberattack. I was driving in my car that morning and looked up to see a digital billboard glitch into the "blue screen of death" before my eyes. Flights were grounded, travel was delayed, and nearly every Windows machine in the world was unusable. It was total mayhem. Clearly, this was an outage of major proportions, as millions of Windows systems worldwide essentially cratered. Caused by a faulty misconfiguration, we saw firsthand how the very digital advancements that have helped transform and modernize our world also expose us to more vulnerabilities than ever. ... In healthcare, this event laid bare the vulnerabilities we cannot overlook—the gaps that directly threaten patient care and safety. It’s a clear reminder of our industry’s utmost responsibility to patient privacy and well-being. ...
Ransomware attack at Texas health system spreads
10/10/24 at 03:00 AMRansomware attack at Texas health system spreadsBecker's Health IT; by Giles Bruce; 10/9/24When hackers strike a health system, it can have far-reaching effects beyond just the original target. That's been the case with the Sept. 26 ransomware attack against Lubbock, Texas-based UMC Health System. That event has also ensnared Lubbock-based Texas Tech University Health Sciences Center and Texas Tech Physicians, which share IT systems with UMC Health. The medical school and its affiliated physician group are now in downtime, unable to access their EHR or receive patient portal messages or faxes. Their phone lines are experiencing intermittent outages as well. However, their clinics remain open, as do their pharmacies, albeit with reduced capacity.
SNF, home health [and hospice] CEOs could be jailed over cybersecurity issues under new bill
10/02/24 at 03:00 AMSNF, home health [and hospice] CEOs could be jailed over cybersecurity issues under new billMcKnight's Senior Living; by Kathleen Steele Gaivin; 9/30/24New legislation aimed at improving cybersecurity in healthcare could see leaders at skilled nursing facilities, home health agencies and hospices jailed if they lie about their cybersecurity precautions, according to one of its sponsors. Senate Finance Committee Chair Ron Wyden (D-OR) and Sen. Mark Warner (D-VA) announced the Health Infrastructure Security and Accountability Act on Thursday. The bill also covers other types of healthcare businesses. “The healthcare industry has some of the worst cybersecurity practices in the nation despite its critical importance to Americans’ well-being and privacy,” Wyden said. “These commonsense reforms, which include jail time for CEOs that lie to the government about their cybersecurity, will set a course to beef up cybersecurity among healthcare companies across the nation and stem the tide of cyberattacks that threaten to cripple the American healthcare system.”
77% of health system IT employees eyeing new jobs
09/26/24 at 03:00 AM77% of health system IT employees eyeing new jobs Becker's Health IT; Naomi Diaz; 9/25/24 Health system IT employees are keeping their options open, with 77% actively seeking new jobs or planning to do so within the next year, according to Bloomforce's "2024 EHR Salary Insights Report." The report, based on an online survey conducted between November and December 2023, gathered responses from 284 healthcare professionals across various roles, including application analysts, team leads, project managers and people managers. It explored areas such as salary, job satisfaction, work-life balance, talent retention and attitudes toward remote work. Here are some key findings from the report: [Click on the title's link to read more.]
Ascension posts $1.8B annual loss; liquidity 'remains strong,' CFO says
09/23/24 at 03:00 AMAscension posts $1.8B annual loss; liquidity 'remains strong,' CFO says Becker's Hospital CFO Report; by Alan Condon; 9/18/24 St.Louis-based Ascension reported a $79 million operating loss (-0.3% margin) for the 10 months ending April 30, a substantial improvement on the $1.2 billion operating loss in the previous 10-month period. The results include $402 million in one-time, non-cash write-downs and non-recurring losses. In May and June 2024, operations were hampered by the May ransomware attack, resulting in reduced revenues from the associated business interruption along with costs incurred to address the issues and other business-related expenses. Despite this incident, Ascension drove a $1.2 billion operational improvement year over year for the 10 months ending April 30. The 136-hospital system's economic improvement plans focused on volume growth, rates and pricing, and cost levers.
CMS teases new cybersecurity policies for third-party vendors
09/14/24 at 03:00 AMCMS teases new cybersecurity policies for third-party vendors Modern Healthcare; by Bridget Early; 9/13/24 The Centers for Medicare and Medicaid Services is planning oversight of third-party healthcare vendors in the wake of the Change Healthcare cyberattack, said Jonathan Blum, the agency's principal deputy administrator. Blum, who also serves as chief operating officer for CMS, said at Modern Healthcare's Leadership Symposium Thursday that the agency is working to determine what levers it can pull to ensure severe disruptions in care like those linked to the cyberattack on the UnitedHealth Group subsidiary aren’t repeated. ... Almost 133 million individuals were affected by healthcare data breaches last year, more than double the number of those affected in 2022 and a number equivalent to about 40% of the U.S. population.
Leadership in the age of AI: At the crossroads of humanity and technology
09/11/24 at 03:00 AMLeadership in the age of AI: At the crossroads of humanity and technology Forbes; by Dr. Adil Dalal, DBA; 9/9/24 It has only been 200 years since the First Industrial Revolution and the mass adoption of what we now call technology... The Second Industrial Revolution in the late 19th and early 20th centuries, marked by great progress in mass production, ... emphasizing the importance of machines over humans and managers over employees. ... Today, the world stands on the precipice of the Fourth Industrial Revolution with artificial intelligence, which is not just reshaping industries but also redefining the very essence of leadership and decision-making. ... A technology-driven leader [TDL] who prioritizes novelty over humanity can pose significant risks, potentially leading to societal downfall. ... A human-centric leader [HCL] prioritizes the well-being, growth and empowerment of people, steering humanity toward greatness. ... So is there an ideal Technology Age leader who can lead humanity through this historical moment? Yes! ... They must embody and demonstrate the following three qualities:
The changing role of chief privacy officers
09/10/24 at 03:00 AMThe changing role of chief privacy officers Becker's Health IT; by Giles Bruce; 9/6/24 Chief privacy officers are expanding their roles to take on artificial intelligence and cybersecurity, according to the International Association of Privacy Professionals. Whereas chief privacy officers traditionally focused on being compliant with privacy laws, 69% now have responsibility for AI or data governance, 37% cover cybersecurity regulatory compliance, and 20% have platform liability duties, according to the IAPP survey of 671 professionals released Sept. 6. Some health systems have standalone chief privacy officers, but the hospital industry is more likely to have chief information security officers with privacy duties or a combined role.
The biggest threat in health IT and RCM
09/09/24 at 03:00 AMThe biggest threat in health IT and RCM Becker's Hospital Review; by Randi Haseman; 9/6/24 Are organizations adopting AI technology too quickly or too slowly? And what's the future of payer relationships? ... As part of an ongoing series, Becker's is talking to healthcare leaders who will speak at our conference. ... Question: What is the biggest threat in health IT and RCM right now? [Responses from 47 executives featured in this article address the following and more: payer programs; modernizing legacy systems while ensuring data security and compliance; cyber-crime / cybersecurity; relieving provider and staff burden thgouth clinical workflows; state and federal legislation; human error; Gen AI 'mission-creep'; extended systems downtimes; the velocity of technical disruption; more ...]
It could happen to you — how to prepare for and mitigate the fallout from a cyberattack
09/03/24 at 03:00 AMIt could happen to you — how to prepare for and mitigate the fallout from a cyberattackMcKnight's Senior Living; by Kimberly Bonvissuto;8/28/24Everyone thinks they know about cybersecurity, but thinking about the effects a cyberattack could have on an organization should be enough to lose sleep over, according to risk management experts. ... Cybersecurity, at its core, is about confidentiality, integrity and availability, according to John P. DiMaggio, co-founder and CEO of Blue Orange Compliance, a risk assessment company. Including senior living in the definition of healthcare, he said that healthcare organizations are targets of cyber criminals because of their relatively weak defenses, the value of the data necessary for operations, and the numerous interfaces and sharing of information that occurs among providers. ... Reasonable security practices — considered the minimum — include risk analysis and management, access control measures, training, incident response planning, physical controls, technical safeguards, third party/vendor management, backup and disaster recovery and patch management. But DiMaggio recommended going above that minimum threshold by using recognized security practices to mitigate penalties and ensure regulatory compliance. Those practices, he said, include email and endpoint protection, access management, data loss prevention, asset and network management, vulnerability management, incident response, medical device security and cybersecurity policies.
Optimizing patient data transfer processes in healthcare settings
08/01/24 at 03:00 AMOptimizing patient data transfer processes in healthcare settings Healthcare Business Today; by Majed Alhajry; 7/28/24 Managing and transferring large and often sensitive datasets is a routine yet critical task for healthcare organizations. Practitioners and administrators regularly share substantial files containing sensitive personal health information (PHI) that must be sent not only securely and reliably, but also quickly. So how should healthcare organizations send large files? ...
