Cybersecurity

The digital security of healthcare institutions and data is a growing concern, with an increasing number of cyberattacks each year against healthcare systems, which are seen as easy targets. Cyber attacks often use ransomware to target personal health information, patient data and medical devices to cut off access to the data until a ransom is payed to the hacker. Cybercriminals have become more sophisticated, using malware, ransomware and spyware to attack outdated and vulnerable systems and software. Due to the interconnected nature of hospital IT systems today, the weakest link can be older web-enabled medical devices, including clinical and non-clinical systems. Employees are also a major target of attacks via malicious e-mails that prompt them to open attachments that then download malware onto the hospital's IT system.

Thumbnail

OIG: OCR failed to meet federal requirements in HIPAA oversight

The Office of Civil Rights failed to meet several federal requirements necessary to the oversight and enforcement of the Health Insurance Portability and Accountability Act security rule, according to a recent report from the Department of Health and Human Services Office of Inspector General.

Calif. system's patient data was available on Google

A California hospital system left the data of 32,755 of its patients exposed online.

Missing flash drive cause of Kaiser breach

The protected health information of more than 49,000 patients at Kaiser’s Anaheim Medical Center is at risk after a computer flash drive went missing, according to the Los Angeles Times.

NJ Blues laptop theft affects 800K

More than 800,000 Horizon Blue Cross Blue Shield of New Jersey members are impacted by the theft of two password-protected but unencyrpted laptop computers.

Laptop theft puts transplant patients’ information at risk

Sensitive information concerning 1,300 transplant patients at Houston Methodist Hospital was compromised after the theft of a hospital laptop, reports the Houston Chronicle.

HITPC: Update on HIPAA compliance activities

Susan McAndrews, deputy director for health information privacy, Office for Civil Rights (OCR), offered the latest in OCR’s privacy and security efforts and opened up about the audit program during the Health IT Policy Committee meeting on Dec. 4.

Happtique certifies first round of apps

Happtique, a mobile health solutions company, has certified 19 health and medical apps that meet certain benchmarks in privacy, security and operability.

Lost drive source of KP's second data breach this fall

A lost USB flash drive is the source of Kaiser Permanente's second data breach this fall.

Around the web

U.S. health systems are increasingly leveraging digital health to conduct their operations, but how health systems are using digital health in their strategies can vary widely.

When human counselors are unavailable to provide work-based wellness coaching, robots can substitute—as long as the workers are comfortable with emerging technologies and the machines aren’t overly humanlike.

A vendor that supplies EHR software to public health agencies is partnering with a health-tech startup in the cloud-communications space to equip state and local governments for managing their response to the COVID-19 crisis.