HHS proposes new cybersecurity requirements for hospitals through HIPAA, Medicaid and Medicare

The United States Department of Health and Human Services said it is planning to take a range of actions in an effort to better address cyberattacks on hospitals, which have caused dozens of outages across the country in recent months.
First reported by Politico, HHS published a planning document on Wednesday that outlines several voluntary and potentially mandatory actions hospitals will need to take.
HHS said it is seeking comment on proposals that would see new cybersecurity requirements for hospitals pushed through Medicare and Medicaid programs, ostensibly tying federal payments to baseline standards.
A similar concept has been floated by HHS Deputy Secretary Andrea Palm and Sen. Mark Warner, according to Politico.
In addition to adding cybersecurity requirements to Medicare and Medicaid, HHS floated potential updates to the Health Insurance Portability and Accountability Act Security Rule in the spring of 2024 that would also include new cybersecurity requirements.
HHS said it is planning to work with Congress on increasing civil monetary penalties for HIPAA violations and expanding their resources so they can investigate more potential HIPAA violations, conduct audits and provide more technical assistance.
The plan comes as hospitals continue to face near-relentless attacks from ransomware gangs that have caused weeks-long outages and have forced ambulances to be diverted and appointments to be canceled.
A study from University of Minnesota researchers released in October found that ransomware incidents increased the in-hospital mortality for patients admitted to attacked hospitals.
The researchers estimate that from 2016 to 2021, between 42 and 67 Medicare patients died as a result of the outages caused by ransomware attacks.
In addition to the immediate effects of ransomware attacks, the information stolen by hackers during incidents has long-term effects on victims.
Through the Office for Civil Rights, HHS tracks large data breaches and has found a 93% increase in large breaches reported from 2018 to 2022, with a 278% increase in large breaches reported to OCR involving ransomware from 2018 to 2022.
Just this week, a ransomware gang took credit for an attack on Tri-City Medical Center - which forced the San Diego hospital on November 9 to take its systems offline, halt elective procedures and take other actions in light of the damaging attack.
The hospital was only able to return to full functionality on December 2.
Ransomware attacks on Capital Health, Ardent Health Services and Prospect Medical Holdings this year left dozens of hospitals scrambling to provide patient care amid near-catastrophic technology outages.
Recorded Future - the parent company of The Record - reported at least 19 ransomware attacks on healthcare facilities last month and steep increases in incidents throughout 2023.
The most recent efforts and plans are being built off of the 2023 Hospital Cyber Resiliency Landscape Analysis conducted in the wake of the release of the National Cybersecurity Strategy - which ordered sector management agencies like HHS to use every tool available to increase cybersecurity protections.
HHS plans to now establish voluntary cybersecurity performance goals for the healthcare sector, incentivise better cybersecurity practices and implement an HHS-wide strategy to support greater enforcement and accountability.
HHS also wants to further expand and mature its own cybersecurity resources.
Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia.
He previously covered cybersecurity at ZDNet and TechRepublic.


This Cyber News was published on therecord.media. Publication date: Thu, 07 Dec 2023 21:30:09 +0000


Cyber News related to HHS proposes new cybersecurity requirements for hospitals through HIPAA, Medicaid and Medicare

HHS proposes new cybersecurity requirements for hospitals through HIPAA, Medicaid and Medicare - The United States Department of Health and Human Services said it is planning to take a range of actions in an effort to better address cyberattacks on hospitals, which have caused dozens of outages across the country in recent months. First reported ...
1 year ago Therecord.media
Cyberattacks on Hospitals Are Likely to Increase, Putting Lives at Risk, Experts Warn - Cybersecurity experts are warning that hospitals around the country are at risk for attacks like the one that is crippling operations at a premier Midwestern children's hospital, and that the U.S. government is doing too little prevent such breaches. ...
1 year ago Securityweek.com
Hospitals Must Treat Patient Data and Health With Equal Care - COMMENTARY. Hospitals are in the crosshairs: As collectors of some of the most personal and sensitive data available, hospitals are a prime target for hackers and cyberattacks. Patient data needs to be treated with as much care and sensitivity as the ...
1 year ago Darkreading.com
HHS to Investigate Change's Security in Wake of Crippling Cyberattack - The U.S. Department of Health and Human Services is opening an investigation into UnitedHealth and its Change Healthcare subsidiary following a ransomware attack that for three weeks has essentially shut down payments to health care providers and ...
1 year ago Securityboulevard.com
CyberCrime & Doing Time: Identification Documents: an Obsolete Fraud Countermeasure - When I'm talking to bankers and other fraud fighters, I often mention how easy it is for a criminal to obtain a Drivers License bearing any information they desire. In the new case, Brianna Mills, a 28-year old bank teller in Loganville, Georgia ...
1 year ago Garwarner.blogspot.com
Capital Health Hospitals hit by cyberattack causing IT outages - Capital Health hospitals and physician offices across New Jersey are experiencing IT outages after a cyberattack hit the non-profit organization's network earlier this week. The healthcare system manages two hospitals, an outpatient facility in ...
1 year ago Bleepingcomputer.com DAIXIN
Feds cough up 'voluntary' cybersecurity goals for hospitals The Register - Plus, you're going to be in for a world of hurt when new regulations - which will very likely mirror these voluntary practices - take effect, according to Taylor Lehmann, a director in Google Cloud's Office of the Chief Information Security Officer. ...
1 year ago Go.theregister.com
HHS reverses course, allows Change Healthcare to file breach notifications for others - The Department of Health and Human Services changed course on Friday and announced that it will allow Change Healthcare to file breach notifications on behalf of the thousands of organizations impacted by February's ransomware attack. HHS updated a ...
1 year ago Therecord.media
SW Ontario hospitals confirm patient data compromised in cyberattack - As the fallout from last week's cyberattack against five southwestern Ontario hospitals continues to spread, the organizations confirmed Tuesday that patient information was stolen and they now fear the blackmailers might publish it online. TransForm ...
1 year ago Windsorstar.com
Understanding the New SEC Rules for Disclosing Cybersecurity Incidents - The U.S. Securities and Exchange Commission recently announced its new rules for public companies regarding cybersecurity risk management, strategy, governance, and incident exposure. "Currently, many public companies provide cybersecurity disclosure ...
1 year ago Feeds.dzone.com
Lawmakers warn of impact HHS firings will have on medical device cybersecurity efforts | The Record from Recorded Future News - During a subcommittee hearing of the House Committee on Energy and Commerce , multiple members of Congress peppered five medical device cybersecurity expert witnesses with questions about how the firings will impact efforts to check the devices for ...
7 months ago Therecord.media
LockBit targets hospitals - We did not see much research released on ransomware this week, with most of the news focusing on new attacks and LockBit affiliates increasingly targeting hospitals. These attacks include ones against Yakult Australia and the Ohio Lottery by the new ...
1 year ago Bleepingcomputer.com 8base LockBit Dragonforce
New Jersey, Pennsylvania hospitals affected by cyberattacks - Hospitals in New Jersey and Pennsylvania are dealing with the ramifications of cyberattacks this week following several similar incidents that took place during the Thanksgiving holiday. This week, Capital Health said it is experiencing network ...
1 year ago Therecord.media
How Hospitals Can Help Improve Medical Device Data Security - COMMENTARY. Hospitals and medical device manufacturers must team up to help create a secure environment to protect the personal health information derived from patient monitors and other medical devices. For some time, this notion of shared ...
1 year ago Darkreading.com
Hospitals ask courts to force cloud storage firm to return stolen data - Two not-for-profit hospitals in New York are seeking a court order to retrieve data stolen in an August ransomware attack and now stored on the servers of a Boston cloud storage company. Carthage Area Hospital and Claxton-Hepburn Medical Center have ...
1 year ago Bleepingcomputer.com LockBit Akira
Leader of Russian hacktivist group Killnet 'retires,' appoints new head - This leadership change comes just a few weeks after Russian journalists uncovered the alleged identity of Killmilk, who became famous during the war for representing a collective of politically motivated hackers. The report said Killmilk is a ...
1 year ago Therecord.media
Fortinet Contributes to World Economic Forum's Strategic Cybersecurity Talent Framework - Shining a light on the cybersecurity workforce challenge, the World Economic Forum recently published its Strategic Cybersecurity Talent Framework, which is intended to serve as a reference for public and private decision-makers concerned by the ...
1 year ago Feeds.fortinet.com
Data breach hits Heart of Texas Behavioral Health Network - The Heart of Texas Behavioral Health Network this week is notifying current and former patients of a data breach could have compromised their medical privacy. A network security incident on Oct. 22 allowed an unauthorized party to gain access to the ...
1 year ago Wacotrib.com
HHS warns of 'Citrix Bleed' attacks after hospital outages - The U.S. Department of Health and Human Services is warning hospitals and healthcare facilities across the country to patch a vulnerability known as "Citrix Bleed" that is being used in attacks by ransomware gangs. For weeks, cybersecurity experts ...
1 year ago Therecord.media CVE-2023-4966 LockBit
US to hospitals: Meet security standards or no federal money The Register - US hospitals will be required to meet basic cybersecurity standards before receiving federal funding, according to rules the White House is expected to propose in the next few weeks. This comes as hospitals and health clinics nationwide continue to ...
1 year ago Go.theregister.com
Cybersecurity in the Healthcare Industry: Protecting Patient Data - In the rapidly advancing era of technology, the healthcare industry faces a critical challenge: protecting patient data from cyber threats. This article will emphasize the significance of cybersecurity in the healthcare industry and explore the ...
1 year ago Securityzap.com
Lockbit Ransomware Attack Affects Three German Hospitals - Katholische Hospitalvereinigung Ostwestfalen, a German hospital network, has confirmed that a cyberattack launched by the Lockbit ransomware group is the cause of recent service disruptions at three hospitals in its network. The attack occurred in ...
1 year ago Heimdalsecurity.com LockBit
Nearly 3 million affected by ransomware attack on medical software firm - Millions of people across the U.S. had their information exposed following a ransomware attack on a company that provides software to hospitals and emergency medical services. The data theft occurred before the gang attempted to encrypt the ...
1 year ago Therecord.media
Cybersecurity and Infrastructure Security Agency Reports Minimal Impact of Killnet Distributed Denial of Service Attacks on American Hospitals - The Cybersecurity and Infrastructure Security Agency (CISA) reported that it had assisted numerous hospitals in responding to a series of distributed denial-of-service (DDoS) attacks last week, which were launched by a pro-Kremlin hacking group known ...
2 years ago Therecord.media
Welltok Data Breach: 8.5M US Patients' Information Exposed - In a recent cybersecurity incident, Welltok, a leading healthcare Software as a Service provider, reported unauthorized access to its MOVEit Transfer server, affecting the personal information of approximately 8.5 million patients in the United ...
1 year ago Securityboulevard.com

Cyber Trends (last 7 days)