Healthcare organizations in the US may soon get a cybersecurity overhaul

A set of new requirements proposed by the US Department of Health and Human Services’ (HHS) Office for Civil Rights could bring healthcare organizations up to par with modern cybersecurity practices. The proposal, posted to the Federal Register on Friday, includes requirements for multifactor authentication, data encryption and routine scans for vulnerabilities and breaches. It would also make the use of anti-malware protection mandatory for systems handling sensitive information, along with network segmentation, the implementation of separate controls for data backup and recovery, and yearly audits to check for compliance.

HHS also shared a fact sheet outlining the proposal, which would update the Health Insurance Portability and Accountability Act of 1996 (HIPAA) Security Rule. A 60-day public comment period is expected to open soon. In a press briefing, US deputy national security advisor for cyber and emerging technology Anne Neuberger said the plan would cost $9 billion in the first year to execute, and $6 billion over the subsequent four years, Reuters reports. The proposal comes in light of a marked increase in large-scale breaches over the past few years. Just this year, the healthcare industry was hit by multiple major cyberattacks, including hacks into Ascension and UnitedHealth systems that caused disruptions at hospitals, doctors’ offices and pharmacies.

“From 2018-2023, reports of large breaches increased by 102 percent, and the number of individuals affected by such breaches increased by 1002 percent, primarily because of increases in hacking and ransomware attacks,” according to the Office for Civil Rights. “In 2023, over 167 million individuals were affected by large breaches — a new record.”

This article originally appeared on Engadget at https://www.engadget.com/cybersecurity/healthcare-organizations-in-the-us-may-soon-get-a-cybersecurity-overhaul-220933165.html?src=rss https://www.engadget.com/cybersecurity/healthcare-organizations-in-the-us-may-soon-get-a-cybersecurity-overhaul-220933165.html?src=rss
Created 19h | Dec 28, 2024, 11:50:26 PM


Login to add comment

Other posts in this group

Parker Solar Probe survived its close approach to the sun and will make two more in 2025

NASA said on Friday that it received a signal from the Parker Solar Probe confirming that the spacecraft had survived its closest ever flyby of the sun. The approach took it just 3.8 million miles

Dec 28, 2024, 7:20:08 PM | Engadget
Donald Trump asks the Supreme Court to delay the TikTok ban

President-elect Donald Trump has asked

Dec 28, 2024, 12:40:15 AM | Engadget
2024 is on its way to being the hottest year ever

2023 was the hottest year on record. This past year is on

Dec 27, 2024, 10:30:09 PM | Engadget
Apple just dropped the first eight minutes of Severance season two

The second season of the smash hit sci-fi drama Severance

Dec 27, 2024, 8:10:17 PM | Engadget
Xbox Cloud Gaming has had trouble loading games for the last 24 hours

If you've tried to use Xbox Cloud Streaming and experienced issues loading games or unexpected disconnects, you're not alone. Microsoft's game streaming services has been experiencing issues since

Dec 27, 2024, 8:10:16 PM | Engadget
The FTC’s Microsoft antitrust probe reportedly focuses on software bundling

The Federal Trade Commission (FTC) is reportedly investigating Microsoft like it’s 1998. In the waning days of the Biden administration, outgoing chair Lina Khan’s probe is said to be picking up st

Dec 27, 2024, 8:10:15 PM | Engadget