Health IT Vendor’s Data Breach Exposes Nearly 4M Patient Records
Revenue cycle vendor Unlimited Technology Systems disclosed a ransomware attack affecting 3.8 million patients — the second-largest healthcare data breach reported to HHS this year.
Revenue cycle vendor Unlimited Technology Systems disclosed a ransomware attack affecting 3.8 million patients — the second-largest healthcare data breach reported to HHS this year.
In a sector where delays are measured in lives, early detection, lower attacker dwell time, and system-level misdirection can literally save lives. By marrying preemptive and deceptive technologies, organizations can blunt the attack surface while simultaneously exposing hidden threats before damage is done.
Let’s not add salt to the wound of funding cuts and personnel changes by inadvertently inviting even more ransomware - here's a closer look at health’s endpoint holes, how federal cuts could ultimately help ransomware hackers, and what ecosystem defenders can do to step up and fight back.
Threat actors continue to refine their strategies, and the financial incentives for cybercrime persist. However, the combination of stronger defenses, regulatory pressure, and industry collaboration is starting to shift the balance in favor of defenders.
About 90% of healthcare organizations are insecurely connected to the internet and running systems vulnerable to exploitation by ransomware gangs, according to new research. It also found that 78% of providers have made ransomware payments of $500,000 or more.
U.S. healthcare organizations lose $1.9 million on average during each day of downtime following a ransomware attack, according to new research from Comparitech. Rebecca Moody, Comparitech’s head of data research, predicted that the rate of ransomware attacks in the healthcare sector will accelerate even more in 2025.
More than three-quarters of healthcare organizations reported paying more than $500,000 in ransom as a result of cyberattacks, according to a new report.
Ransomware group Black Basta has quickly gained prominence as one of the biggest threats to healthcare providers’ cybersecurity. The group, which is responsible for the Ascension cyberattack, has hit more than 500 organizations across the globe since it first appeared in April 2022.
Healthcare industry leaders think there is much to learn from the Change Healthcare cyberattack, and they hope the sector can apply these lessons to prevent a hack like this from ever happening again. Overall, the chaotic aftermath of the attack underscores the dire need for a more unified approach to cybersecurity within the healthcare sector.
The aftermath the cyberattack on Change Healthcare remains messy, with patients across the country still struggling to obtain their prescriptions. The federal government has even stepped in to help address the fallout of the attack, urging payers to quickly alleviate the digital bottlenecks that providers and pharmacies are facing.
Mari Savickis, Vice President of Public Policy with CHIME, will be moderating a panel discussion as part of the Cybersecurity Pavilion at the ViVE 2024 event in Los Angeles, scheduled for February 25-28. She said her organization anticipates several developments addressing cybersecurity this year.
HHS recently published guidance outlining voluntary cybersecurity performance goals for the healthcare sector. Taylor Lehmann, a cybersecurity executive at Google Cloud, noted that "what is on HHS paper will most likely become what is in the actual final rulemaking or new regulatory requirements that become law."
Many hospitals remain underprepared to protect themselves against cybercriminals’ barrage of increasingly sophisticated attacks, but there are a couple concrete steps they can take to build a stronger defense structure — like virtual patching and thinking twice about moving to the cloud.
HHS issued an alert warning providers about Rhysida, a ransomware gang that recently begun launching attacks on healthcare organizations. The group deploys its ransomware primarily through phishing attacks or the exploitation of legitimate cybersecurity tools.
To prevent the proliferation of data security incidents in the healthcare industry, providers must examine their use of legacy systems as well as their reliance on third parties, according to a new report. It pointed out that most providers fail to probe their third-party partners' cybersecurity measures, and many continue to use legacy systems that are no longer supported by vendors or are hard to patch and update.