Cybersecurity

The digital security of healthcare institutions and data is a growing concern, with an increasing number of cyberattacks each year against healthcare systems, which are seen as easy targets. Cyber attacks often use ransomware to target personal health information, patient data and medical devices to cut off access to the data until a ransom is payed to the hacker. Cybercriminals have become more sophisticated, using malware, ransomware and spyware to attack outdated and vulnerable systems and software. Due to the interconnected nature of hospital IT systems today, the weakest link can be older web-enabled medical devices, including clinical and non-clinical systems. Employees are also a major target of attacks via malicious e-mails that prompt them to open attachments that then download malware onto the hospital's IT system.

Thumbnail

EHR debate, colossal breach

Bad news dominated the headlines this week. From both a massive breach and smaller breaches to wild claims about the failure of a $1 billion EHR system, the industry had an off week.

Medtronic notifies patients of potential PHI breach

Medical device manufacturer Medtronic has notified 2,764 patients after a box of training records went missing at a facility in Minnesota.

Patient data available to many, report says

State information-collection systems are storing patient information in massive databases but often without patients' consent, according to a report from a consumer advocacy group.

Colossal breach puts 4M on alert

An office burglary at Advocate Medical Group (AGM) in Park Ridge, Ill., put the protected health information of more than four million patients at risk.

New alliance targets medical identity fraud

Several organizations have launched the Medical Identity Fraud Alliance—a public-private effort seeking to unite stakeholders in developing solutions and best practices to prevent, detect and remediate medical identity fraud—and they are looking for additional entities to join their ranks.

Email blooper exposes PHI

An unfortunate mistake resulted in a group of medical center students receiving an email attachment listing protected health information on all 2,281 students.

Email accidentally discloses information of 3,700 disabled patients

An email from Alaska-based Hope Community Resources that had meant to promote a survey of clients and stakeholders instead included attachments with confidential information of its 3,700 disabled clients that contract with Hope, according to an Aug. 20 article in Alaska Dispatch.

Nonprofit to develop medical device security guidelines

The Center for Internet Security announced an initiative to help bolster the protection of internet-enabled medical devices from cyber attacks. CIS has issued a request for information to U.S. medical device manufacturers to invite voluntary participation in the development of security control guidelines for reducing cyber risk to medical devices.

Around the web

U.S. health systems are increasingly leveraging digital health to conduct their operations, but how health systems are using digital health in their strategies can vary widely.

When human counselors are unavailable to provide work-based wellness coaching, robots can substitute—as long as the workers are comfortable with emerging technologies and the machines aren’t overly humanlike.

A vendor that supplies EHR software to public health agencies is partnering with a health-tech startup in the cloud-communications space to equip state and local governments for managing their response to the COVID-19 crisis.