This section of The HIPAA Guide on Healthcare Cybersecurity focuses on safeguarding sensitive health data from the increasing threats of cyberattacks, which target healthcare organizations. The section provides insights into the latest cybersecurity threats, best practices for protecting Protected Health Information (PHI), and the necessary compliance with HIPAA’s Security Rule. It also highlights the importance of security training, awareness, and the use of advanced technologies like encryption, multi-factor authentication, and phishing prevention to reduce the risk of data breaches in the healthcare sector.
A cybercriminal group that targets law firms, healthcare providers, insurance, and finance companies using
[...]
The New York State Department of Financial Services (NYDFS) has announced that Delta Dental Insurance Company
[...]
The Health Sector Coordinating Council (HSCC) has issued new guidance for healthcare organizations to help
[...]
Earlier this month, the Director of the Department of Health and Human Services (HHS) Office for Civil Rights
[...]
A bipartisan healthcare cybersecurity bill – The Health Care Cybersecurity and Resiliency Act of 2025
[...]
More than 100 hospital systems, healthcare provider organizations, and industry associations have petitioned
[...]
When negotiating contracts with medical device manufacturers (MDMs), the responsibility for ensuring the
[...]
Another warning has been issued about the Akira ransomware group in light of evolving tactics and accelerated
[...]
The use of outdated technology in healthcare is putting patient safety at risk, contributing to clinician
[...]
Three former employees of cybersecurity firms have been accused of conducting ALPHV/BlackCat ransomware
[...]
A hospital management system from the Romanian company, Vertical Systems, has two vulnerabilities that could,
[...]
A recent analysis has shown that healthcare ransomware attacks are continuing at the high levels seen in
[...]
A recent survey of healthcare IT and security professionals has highlighted the impact cyberattacks are
[...]
The state of New York adopted new cybersecurity requirements for general hospitals on October 2, 2024. The
[...]
A new report from Netwrix has revealed that almost half of organizations in the healthcare sector experienced
[...]
If your organization sells – or is planning to sell – software, products, or services to the U.S.
[...]
A ransomware group that has targeted hospitals and other critical infrastructure entities since 2022 has had
[...]
Healthcare organizations have to cover the highest costs for data breaches, although costs have fallen by
[...]
Federal agencies have issued a joint alert about the Interlock ransomware group, which has increased its
[...]
U.S. healthcare organizations are being targeted with ongoing phishing and SMS-phishing (smishing) campaigns.
[...]
Earlier this month, lawmakers in the House and Senate introduced the bipartisan Healthcare Cybersecurity Act
[...]
For some time now, it hasn’t been a case of whether there will be a cyberattack, but rather when and how
[...]
The healthcare industry is targeted by ransomware groups, one of which has been accelerating attacks. The
[...]
Several reports published this month on the current state of ransomware indicate Q1, 2025 has been a
[...]
Hospitals in the United States have been warned about a potential terror threat and have been urged to
[...]
Healthcare and other critical infrastructure sectors are being targeted by the Medusa ransomware group, which
[...]
A warning has been issued about the Ghost ransomware group following attacks on healthcare organizations and
[...]
A China-based threat group is conducting a malware distribution campaign using malicious installers disguised
[...]
Finance and healthcare have long been the two industries most targeted by cybercriminals; however, healthcare
[...]
One of the biggest concerns in healthcare in 2025 is the continuing threat of cyberattacks. Last year was a
[...]
A recent report from the blockchain analytics firm Chainalysis has revealed ransomware attacks are becoming
[...]
HIPAA-covered entities and their business associates are facing much tougher cybersecurity requirements,
[...]
A bipartisan group of Senators has introduced the Health Care Cybersecurity Resiliency Act of 2024, the aim
[...]
The Department of Health and Human Services (HHS) Health Sector Cybersecurity Coordination Center (HC3) has
[...]
The HHS’ Office for Civil Rights (OCR) in conjunction with the Assistant Secretary for Technology Policy
[...]
Malicious actors often use social engineering in their attacks on individuals to trick them into installing
[...]
Hospitals in New York must report cyberattacks to the State Department of Health within 72 hours of discovery
[...]
The threat actor Vice Society, tracked by Microsoft as Vanilla Tempest, is targeting the healthcare sector
[...]
The RansomHub ransomware group emerged in February 2024 and has already conducted at least 210 attacks,
[...]
Cyberattacks on healthcare organizations have increased significantly in recent years. According to the
[...]
For the past two years, Royal ransomware has been one of the most prolific ransomware groups; however, in
[...]
On Friday, the cybersecurity firm CrowdStrike released an update for its Falcon Sensor endpoint detection and
[...]
The harm caused by the ransomware attack on Change Healthcare is unprecedented and while it has yet to be
[...]
The Advanced Research Projects Agency for Health (ARPA-H), part of the HHS, has launched the Universal
[...]
The Department of Health and Human Services’ Health Sector Cybersecurity Coordination Center (HC3) has
[...]
A joint cybersecurity advisory has been issued about the Black Basta ransomware group. Black Basta is known
[...]
The FBI has released its annual Internet Crime Report which confirms that healthcare suffered more ransomware
[...]
The Department of Health and Human Services (HHS) has released details of the voluntary cybersecurity goals
[...]
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has published a healthcare cybersecurity
[...]
New York has proposed new cybersecurity regulations for hospitals in a bid to combat increasing numbers of
[...]
A joint cybersecurity advisory has been issued by the U.S. Cybersecurity and Infrastructure Security Agency
[...]
There has been a 59% increase in vulnerabilities in medical devices and the software applications on which
[...]
The Cyber Safety Review Board (CSRB) has recently shared details of the tactics, techniques, and procedures
[...]
The healthcare and public health (HPH) sector has been warned about a new ransomware-as-a-service (RaaS)
[...]
SEO poisoning (search engine poisoning) is a tactic used by cybercriminals to manipulate search results and
[...]
The healthcare and public health (HPH) sector is in the crosshairs of the Clop and MedusaLocker ransomware
[...]
Artificial Intelligence tools have been incorporated into many cybersecurity solutions to improve their
[...]
Data breaches are being reported by healthcare organizations at a rate of around two per day when just four
[...]
A warning has been issued to the healthcare and public health (HPH) sector by the U.S. Office of Information
[...]
The healthcare and public health sector have long been attractive targets for cybercriminals due to the value
[...]
The Department of Health and Human Services’ Health Sector Cybersecurity Coordination Center (HC3) has
[...]
Ransomware attacks are increasing at an alarming rate. Attacks increased by 13% in 2021, which is a bigger
[...]
A bipartisan bill has been proposed to update the Federal Food, Drug, and Cosmetic Act (FD&C Act) to
[...]
A warning has been issued to hospitals that use the Atheon TUG mobile robots about five vulnerabilities –
[...]
The United States Cybersecurity and Infrastructure Security Agency (CISA), in conjunction with the U.S.
[...]
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning to all organizations in
[...]
Excellus Blue Cross Blue Shield has agreed to settle a class action lawsuit filed in response to the data
[...]
The Department of Health and Human Services is facing an unprecedented number of cyber threats and more data
[...]
Most healthcare organizations in the United States are required to comply with the Health Insurance
[...]
Cybercriminals and Advanced Persistent Threat (APT) actors are increasingly using Cobalt Strike in attacks on
[...]
Limiting access to protected health information (PHI) is one of the fundamental requirements of the Health
[...]
A Michigan man who hacked into the human resources databases of University of Pittsburg Medical Center (UPMC)
[...]
The HIPAA Breach Notification Rule requires HIPAA-regulated entities to report data breaches and issue
[...]
New guidance has recently been released by the Cloud Security Alliance (CSA) Health Information Management
[...]
The 2021 IBM Security/Ponemon Institute Cost of a Data Breach Study determined the average cost of a data
[...]
The National Institute of Standards and Technology (NIST) has released a draft version of updated guidance to
[...]
A new study published in the Journal of the American Medical Informatics Association has explored the link
[...]
According to the 2021 IBM Security Cost of a Data Breach report, the average cost of a data breach has risen
[...]
On May 14, 2021, the Health Service Executive (HSE) in Ireland suffered a ransomware attack. The attack was
[...]
The recently enacted American Rescue Plan has made funding available to speed the recovery from the pandemic,
[...]
Verizon has published its 2021 Data Breach Investigations Report (DBIR) which shows the majority of
[...]
In 2019, the largest reported healthcare data breach was at American Medical Collection Agency (AMCA), a debt
[...]
Ransomware gangs stepped up their attacks on healthcare organizations in 2020 with some ransomware operations
[...]
The National Cybersecurity Center of Excellence (NCCoE) at the National Institute of Standards and Technology
[...]
A study conducted by the cybersecurity firm CyberAngel has revealed more than 45 million medical images are
[...]
September is National Insider Threat Awareness Month – A month dedicated to raising awareness of the
[...]
The HIPAA Security Rule requires covered entities and their business associates to implement safeguards to
[...]
Research recently published in a collaborative report by security researcher Jelle Ursem and DataBreaches has
[...]
Joint guidance on managing the cybersecurity tactical response has recently been published by the Healthcare
[...]
The Federal Trade Commission is seeking feedback from healthcare industry stakeholders about its breach
[...]
Advanced Persistent Threat (APT) groups are continuing to exploit the SARS-CoV-2 (COVID-19) pandemic and are
[...]
The Federal Bureau of Investigation (FBI) has issued a fresh warning about the use of the 2019 Novel
[...]
The U.S. Food and Drug Administration (FDA) and the Department of Homeland Security’s Cybersecurity
[...]
On January 14, 2020 Microsoft issued patches to correct critical vulnerabilities in Windows and Windows
[...]
Following a data breach, hospitals implement additional measures to improve their security posture and make
[...]
New guidance has been released by the National Cybersecurity Center of Excellence (NCCoE) on securing picture
[...]
and transmit patient information. They ensure healthcare professionals are always contactable and can quickly
[...]
It has been another terrible month for healthcare data breaches – The worst of the year to date in terms of
[...]
February was a particularly bad month for healthcare data breaches, so it is no surprise there was a fall in
[...]
On February 21, 2019, Sen. Mark Warner (D-Va) requested feedback from a number of healthcare organizations
[...]
In its spring cybersecurity newsletter, the HHS’ Office for Civil Rights has warned healthcare
[...]
The Ponemon Institute conducted a survey for the Global Encryption Trends Study on behalf of nCipher, a
[...]
The U.S. Food and Drug Administration (FDA) is assessing the responses to its draft guidance for medical
[...]
Clearwater CyberIntelligence Institute (CCI) has analyzed security risks in healthcare and found that laptops
[...]
Cybercriminals are targeting the healthcare industry and one of the leading ways that access to healthcare
[...]
The Verizon Mobile Security Index 2019 report shows 25% of healthcare companies have had a security breach
[...]
The College of Healthcare Information Management Executives (CHIME) has told Congress that HIPAA compliance
[...]
Senator Mark Warner (D-Va) has written letters to the leaders of the Department of Health and Human Services
[...]
The College of Healthcare Information Management Executives (CHIME), the Association for Executives in
[...]
An analysis of the data collection practices of Facebook by the Wall Street Journal recently revealed
[...]
The Department of Health in the United Kingdom has commissioned a report on the costs of pagers and their use
[...]
The National Cybersecurity Center of Excellence (NCCoE) recently published final guidance on mobile device
[...]
A complaint has been submitted to the FTC alleging Facebook as engaged in deceptive practices and has
[...]
The Romanian police has developed a new free decryptor for GandCrab ransomware, assisted by
[...]
Proofpoint revealed in its recent healthcare email security report that there has been a 473% increase in
[...]
The Department of Health and Human Services’ Office of Inspector General (OIG) has released a report of the
[...]
2018 saw a massive increase in the number of exposed healthcare records according to the 2019 Breach
[...]
HIMSS has published the results of its annual cybersecurity survey. The aim of the survey is to identify
[...]
Hackers could exploit vulnerabilities in networked security and surveillance cameras to gain access to the
[...]
The Healthcare and Public Health Sector Coordinating Council (HSCC) has published a new cybersecurity
[...]
Radware’s new report provides information regarding the threat landscape in 2018 and the dramatic
[...]
People with Medicare have now been issued new Medicare cards that have no Social Security numbers printed on
[...]
According to a recently issued Department of Defense (DoD) Office of Inspector General report (PDF), the
[...]
The National Counterintelligence and Security Center (NCSC) at the at the Office of the Director of National
[...]
A new study has investigated how advertising expenditures are affected by healthcare data breaches. The
[...]
The Department of Homeland Security (DHS) United States Computer Emergency Readiness Team (US-CERT) has
[...]
The U.S. Department of Health and Human Services (HHS) has published voluntary cybersecurity best practices
[...]
Clearwater has identified the most prevalent security weaknesses in healthcare from IRM analyses carried out
[...]
The National Institute of Standards and Technology (NIST) has released the final version of its updated Risk
[...]
New research has revealed the scale of phishing attacks and the number of employees being misled by phishing
[...]
Intsights, an enterprise threat management platform provider, conducted a survey which revealed an alarming
[...]
The Easy EHR Issues Reporting Challenge was launched by the Department of Health and Human Services’ Office
[...]
The Department of Health and Human Services’ Office of Inspector General (OIG) has conducted security
[...]
The U.S. Department of Justice (DOJ) has announced that two threat actors responsible for SamSam ransomware
[...]
The National Institute of Standards and Technology’s National Cybersecurity Center of Excellence (NCCoE)
[...]
The Department of Health and Human Services’ Office of Inspector General (OIG) has released its yearly
[...]
The U.S. Department of Homeland Security will be forming a new agency exclusively focused on cybersecurity
[...]
The HHS’ Office of Inspector General (OIG) has released the results of an audit of the policies and
[...]
The 2018 CHIME Healthcare’s Most Wired survey has revealed many healthcare organizations do not have a
[...]
The cybercriminals behind SamSam ransomware have been highly active this year. 67 organizations have been
[...]
The Beazley’s Q3 Breach Insights Report shows there has been a significant increase in ransomware attacks
[...]
The Department of Health and Human Services’ Office for Civil Rights has reminded healthcare organizations
[...]
For three years now, MediaPRO, the security awareness training firm, has conducted a yearly study to assess
[...]
September saw 25 healthcare data breaches of more than 500 records reported to the Department of Health and
[...]
Healthcare providers and HIPAA-covered entities have been caught up in the mobile technology movement. Many
[...]
A memorandum of agreement has been announced by the U.S. Food and Drug Administration (FDA) and the
[...]
The most common types of phishing emails that cybercriminals send to healthcare organizations have been
[...]
The U.S. Food and Drug Administration (FDA) has issued an alert after it confirmed that certain Medtronic
[...]
The Healthcare & Public Health Sector Coordinating Council (HSCC) will soon release voluntary
[...]
On October 1, 2018, the U.S. Food and Drug Administration released a Medical Device Cybersecurity Regional
[...]
The healthcare sector is frequently attacked by phishers seeking access to healthcare information located in
[...]
The National Institute of Standards and Technology (NIST) has released a draft of a guidance document that
[...]
In June 2018, the California Consumer Privacy Act (CCPA) was approved by the California legislature. The Act
[...]
The Department of Health and Human Services’ Office of Inspector General (OIG) has issued a report
[...]
The National Institute of Standards and Technology (NIST) developed a Cybersecurity Framework in 2014 to
[...]
A recent report from NTT Security has revealed 66% of UK senior executives believe their company is not fully
[...]
The final version of the NIST Cybersecurity Practice Guide for Securing Wireless Infusion Pumps in Healthcare
[...]
July 2018 is by far the worst month in 2018 with respect to healthcare data breaches. There were 33
[...]
This week, the Industrial Control Systems Cyber Emergency Team (ICS-CERT) has issued two advisories about
[...]
Ovum conducted a survey recently on behalf of analytics firm FICO, which revealed there has been a major
[...]
Phishing is currently the top cyber threat encountered by companies; however, regardless of a high
[...]
The Department of Health and Human Services’ Office of Inspector General (OIG) has released the results of
[...]
Douglas McKee, a security researcher at McAfee, discovered a flaw in the communications protocol used to send
[...]
Healthcare companies still extensively use faxes for communication and in some hospitals, as much as 75% of
[...]
The Anti-Phishing Working Group has published its Q1, 2018 Phishing Activity Trends Report. The report
[...]
The SamSam ransomware attack on Atlanta City was expected to cost around $6 million to resolve; however a
[...]
Protenus has released its Q2 2018 Breach Barometer Report – A summary and analysis of healthcare data
[...]
OpenEMR is a free, open-source electronic health record (EHR) management system that is used by a large
[...]
The hacktivist, Martin Gottesfeld, 32, who was responsible for the Distributed Denial of Service (DDoS)
[...]
In the past year, email account compromises have been steadily increasing according to the July edition of
[...]
Physical, technical, and administrative controls can be implemented to secure ePHI on servers and desktop
[...]
The healthcare marketing agency SCOUT recently conducted a survey that revealed consumers are less concerned
[...]
The United States Computer Emergency Readiness Team (US-CERT) has warned companies abut the growing risk of
[...]
HIMSS has published its June Healthcare and Cross-Sector Cybersecurity Report, in which warnings have been
[...]
The FBI 2017 Internet Crime Report has been released. The report is based on the complaints received by the
[...]
ICS-CERT has released an advisory following the discovery of eight vulnerabilities in version 8 of Natus
[...]
CSO Online’s 2018 list of the best security software solutions for 2018 included Cofense Triage: The
[...]
Siemens published a bulletin about two recently identified vulnerabilities in RAPIDLab and RAPIDPoint Blood
[...]
HIMSS recently conducted a survey that confirmed that medical device security is a major priority at most
[...]
An advisory was issued by the Department of Homeland Security’s Industrial Control Systems Cyber
[...]
The Industrial Control Systems Cyber Emergency Response Team (ICS-CERT) has issued a bulletin warning
[...]
According to Dtex Systems’ 2018 Insider Threat Intelligence Report, security teams are not able to
[...]
Healthcare organizations can use DMARC, the Domain-based Message Authentication, Reporting and Conformance
[...]
HITRUST, the security and privacy standards development and accreditation organization, is now providing
[...]
Healthcare companies quickly fall victim to cyberattacks as a result of continually utilizing out-of-date
[...]
Black Book Research conducted a survey where over 2,400 security professionals from 680 healthcare
[...]
The number of successful phishing attacks on healthcare organizations has increased in the past few weeks. In
[...]
The Department of Homeland Security’s (DHS) Industrial Control Systems Cyber Emergency Response Team
[...]
The Defense Health Agency (DHA), the Navy and the Air Force recently had their second Department of Defense
[...]
Ten SamSam ransomware attacks occurred since December 2017. Most of the attacks were on government and
[...]
The Department of Homeland Security (DHS) warned about a vulnerability that is affecting a lot of medical
[...]
As reported by Symantec, there is a recently discovered threat group labeled as Orangeworm, which is
[...]
The U.S. Food and Drug Administration issued a warning on the cybersecurity vulnerabilities of certain Abbott
[...]
Jemison Internal Medicine of Alabama had a ransomware attack on December 20, 2017. Electronic health records
[...]
The protected health information of 925 patients was compromised because of a ransomware attack on Coastal
[...]
Phishing threats continue to cause problems for healthcare organizations. Investing in phishing defenses
[...]
The Office for Civil Rights warned HIPAA-covered entities in an email about the Spectre and Meltdown chip
[...]
Decatur County General Hospital in Tennessee discovered on November 27, 2017 that its server housing the
[...]
Ponemon Institute conducted a survey regarding data security and cyber risk. The survey was Opus-sponsored
[...]
Onco360 and CareMed Specialty Pharmacy notified 53,173 patients that their protected health information was
[...]
The last day for reporting 2017 HIPAA data breaches to the Department of Health and Human Services’ Office
[...]
In 2017, McAfee Labs report a steady increase in the volume of new malware samples detected every quarter. Q3
[...]
Black Book Research conducted a survey in Q4 2017 that revealed that the healthcare industry is not taking
[...]
NIST published Version 1.1 or the second draft of the revised Cybersecurity Framework. Version 1.0 or the
[...]
Researcher Saurabh Harit of Spirent SecurityLabs discovered vulnerabilities in digital smart pens and IV
[...]
On the last week of November, Apple was informed of a flaw in MacOS High Sierra. Devices running High Sierra
[...]
An employee of Colorado Mental Health Institute at Pueblo became a victim of a phishing scam that allowed the
[...]
The House Committee on Energy and Commerce is pushing HHS to take the advice of Healthcare Cybersecurity Task
[...]
GoToMeeting is an online meeting and video conferencing tool offered by LogMeIn. It helps businesses improve
[...]
A individual connected to the hacking group TheDarkOverlord has been given a three year jail sentence for
[...]
Amazon has incorporated new safeguards into its cloud servers so that users won’t misconfigure their S3
[...]
All staff members must receive training on HIPAA Rules and Compliance, but when is the best time to provide
[...]
It is a widely held view, among IT staff, that members of staff are the biggest data security risk; however,
[...]
The HIMSS October Cybersecurity has highlighted five current cybersecurity threats that could possibly be
[...]
A new ransomware threat has been discovered, labelled Bad Rabbit ransomware, that has affected companies in
[...]
While the healthcare sector remained largely unharmed during unaffected by the NotPetya wiper cyberattacks in
[...]
Blockchain is probably most recognized for maintaining the security of cryptocurrency transactions, however
[...]
Before cloud providers can be employed by healthcare companies for keeping or processing protected health
[...]
The HHS’ Office of Inspector General (OIG) reviewed Alabama’s Medicaid data and information systems to
[...]
A phishing attack on Augusta University Medical Center resulted in the unauthorized access of an individual
[...]
Arkansas Department of Human Services (DHS) fired a former employee from her new job at the state hospital
[...]
The University of Pittsburgh Medical Center’s Bedford Memorial hospital was investigated for a privacy
[...]
The U.S. Food and Drug Administration (FDA) published the final guidance about medical device
[...]
Healthcare providers should be careful not to disclose protected health information (PHI) in mailings.
[...]
The Neurology Foundation located in Providence, RI found out that one of its employees used the
[...]
Alaska Department of Health and Social Services found a Trojan horse virus on two of its computers. The virus
[...]