Cybersecurity

The digital security of healthcare institutions and data is a growing concern, with an increasing number of cyberattacks each year against healthcare systems, which are seen as easy targets. Cyber attacks often use ransomware to target personal health information, patient data and medical devices to cut off access to the data until a ransom is payed to the hacker. Cybercriminals have become more sophisticated, using malware, ransomware and spyware to attack outdated and vulnerable systems and software. Due to the interconnected nature of hospital IT systems today, the weakest link can be older web-enabled medical devices, including clinical and non-clinical systems. Employees are also a major target of attacks via malicious e-mails that prompt them to open attachments that then download malware onto the hospital's IT system.

Malicious software infects Kaiser Permanente’s server

Kaiser Permanente has notified approximately 5,100 members of a privacy incident that compromised one server at its Northern California Division of Research.

Thumbnail

Data breach triggered by phishing emails

About 12,000 patients potentially had their personal health information breached due to a phishing scam.

HHS offers security risk assessment tool for smaller practices

A new security risk assessment (SRA) tool from the Department of Health & Human Services is designed to help guide healthcare providers in small to medium-sized offices conduct risk assessments of their organizations.

eBridge earns high marks in rigorous data security examination; Completes HIPAA and SOC 2 third-party assessment

Hosted document management firm eBridge Inc. has successfully completed a rigorous data management security examination by an outside assurance/compliance auditor, and has met the strict compliance requirements of the Health Insurance Portability and Accountability Act (HIPAA) and the Service Organization Control 2 (SOC 2) process.

Thumbnail

Stanford Hospital, associates to pay $4.1M to resolve data breach lawsuit

Calif.-based Stanford Hospital & Clinics and two of its vendors, Multi-Specialty Collection Services and Corcino & Associates, are required to pay more than $4.1 million to settle a class action lawsuit involving a health data breach.

Thumbnail

N.J. hospital invests in patient matching technology

In an effort to solve challenges in patient matching, Saint Peter’s University Hospital, based in New Brunswick, N.J., signed a three-year agreement with Malta Systems for use of its patient health identity solution, Privasent.

Indian Health Service fails testing of IT security

The Indian Health Service failed a penetration test of its computer network conducted last June by the Department of Health & Human Services’ Office of Inspector General.

Secret Service investigating Detroit patient data breach

The U.S. Secret Service is investigating a breach of personal patient information at two Detroit-area hospital systems, according to Detroit Free Press.

Around the web

U.S. health systems are increasingly leveraging digital health to conduct their operations, but how health systems are using digital health in their strategies can vary widely.

When human counselors are unavailable to provide work-based wellness coaching, robots can substitute—as long as the workers are comfortable with emerging technologies and the machines aren’t overly humanlike.

A vendor that supplies EHR software to public health agencies is partnering with a health-tech startup in the cloud-communications space to equip state and local governments for managing their response to the COVID-19 crisis.