Healthcare organizations in the US may soon get a cybersecurity overhaul

A set of new requirements proposed by the US Department of Health and Human Services’ (HHS) Office for Civil Rights could bring healthcare organizations up to par with modern cybersecurity practices. The proposal, posted to the Federal Register on Friday, includes requirements for multifactor authentication, data encryption and routine scans for vulnerabilities and breaches. It would also make the use of anti-malware protection mandatory for systems handling sensitive information, along with network segmentation, the implementation of separate controls for data backup and recovery, and yearly audits to check for compliance.

HHS also shared a fact sheet outlining the proposal, which would update the Health Insurance Portability and Accountability Act of 1996 (HIPAA) Security Rule. A 60-day public comment period is expected to open soon. In a press briefing, US deputy national security advisor for cyber and emerging technology Anne Neuberger said the plan would cost $9 billion in the first year to execute, and $6 billion over the subsequent four years, Reuters reports. The proposal comes in light of a marked increase in large-scale breaches over the past few years. Just this year, the healthcare industry was hit by multiple major cyberattacks, including hacks into Ascension and UnitedHealth systems that caused disruptions at hospitals, doctors’ offices and pharmacies.

“From 2018-2023, reports of large breaches increased by 102 percent, and the number of individuals affected by such breaches increased by 1002 percent, primarily because of increases in hacking and ransomware attacks,” according to the Office for Civil Rights. “In 2023, over 167 million individuals were affected by large breaches — a new record.”

This article originally appeared on Engadget at https://www.engadget.com/cybersecurity/healthcare-organizations-in-the-us-may-soon-get-a-cybersecurity-overhaul-220933165.html?src=rss https://www.engadget.com/cybersecurity/healthcare-organizations-in-the-us-may-soon-get-a-cybersecurity-overhaul-220933165.html?src=rss
Created 1mo | Dec 28, 2024, 11:50:26 PM


Login to add comment

Other posts in this group

Amazon Music Unlimited subscription prices are rising again

Yet another streaming service is raising its prices. This time, it's Amazon Music Unlimited that's getting more expensive. Prime members will pay $11 a month or $109 a year for an individual plan,

Jan 31, 2025, 12:50:11 AM | Engadget
Clair Obscur: Expedition 33 secures a movie adaptation before it's even released

Hollywood has been turning to video games for source material quite a bit in recent years. And while their success rate has been

Jan 31, 2025, 12:50:10 AM | Engadget
Trump's FCC is coming from NPR and PBS now too

In one of his first major acts since taking over

Jan 30, 2025, 10:40:07 PM | Engadget
The Video Game History Foundation's online library is now open

The Video Game History Foundation has unveiled its

Jan 30, 2025, 10:40:06 PM | Engadget
Netflix will stream its 2025 Tudum event on Netflix

Netflix's next

Jan 30, 2025, 10:40:04 PM | Engadget
The 2024 Google Nest Learning Thermostat is $40 off right now

Many of us in the northern hemisphere are contending with the harsh realities of winter and while the weather outside is often awful, at least we can try to be more comfortable when we're home. A s

Jan 30, 2025, 8:20:25 PM | Engadget