Healthcare organizations in the US may soon get a cybersecurity overhaul

A set of new requirements proposed by the US Department of Health and Human Services’ (HHS) Office for Civil Rights could bring healthcare organizations up to par with modern cybersecurity practices. The proposal, posted to the Federal Register on Friday, includes requirements for multifactor authentication, data encryption and routine scans for vulnerabilities and breaches. It would also make the use of anti-malware protection mandatory for systems handling sensitive information, along with network segmentation, the implementation of separate controls for data backup and recovery, and yearly audits to check for compliance.

HHS also shared a fact sheet outlining the proposal, which would update the Health Insurance Portability and Accountability Act of 1996 (HIPAA) Security Rule. A 60-day public comment period is expected to open soon. In a press briefing, US deputy national security advisor for cyber and emerging technology Anne Neuberger said the plan would cost $9 billion in the first year to execute, and $6 billion over the subsequent four years, Reuters reports. The proposal comes in light of a marked increase in large-scale breaches over the past few years. Just this year, the healthcare industry was hit by multiple major cyberattacks, including hacks into Ascension and UnitedHealth systems that caused disruptions at hospitals, doctors’ offices and pharmacies.

“From 2018-2023, reports of large breaches increased by 102 percent, and the number of individuals affected by such breaches increased by 1002 percent, primarily because of increases in hacking and ransomware attacks,” according to the Office for Civil Rights. “In 2023, over 167 million individuals were affected by large breaches — a new record.”

This article originally appeared on Engadget at https://www.engadget.com/cybersecurity/healthcare-organizations-in-the-us-may-soon-get-a-cybersecurity-overhaul-220933165.html?src=rss https://www.engadget.com/cybersecurity/healthcare-organizations-in-the-us-may-soon-get-a-cybersecurity-overhaul-220933165.html?src=rss
Établi 1mo | 28 déc. 2024 à 23:50:26


Connectez-vous pour ajouter un commentaire

Autres messages de ce groupe

Reddit temporarily bans r/WhitePeopleTwitter after Elon Musk claimed it had ‘broken the law’

Reddit has temporarily banned the subreddit r/WhitePeopleTwitter after Elon Musk complained about the community. The subreddit is

4 févr. 2025 à 23:10:19 | Engadget
Google now thinks it's OK to use AI for weapons and surveillance

Google has made one of the most substantive changes to its AI principles since first publishing them in 2018. In

4 févr. 2025 à 23:10:18 | Engadget
Netflix scuttles plans to add six previously announced games to its service

Netflix has been revamping its games division in recent months, including making

4 févr. 2025 à 20:50:05 | Engadget
Cruise lays off half its staff after GM sunsets robotaxi program

Autonomous vehicle company Cruise is laying off around half of its workforce,

4 févr. 2025 à 20:50:04 | Engadget
Government workers sue over potentially illegal DOGE server

Federal employees are suing to disconnect a server, reportedly operated by associates of Elon Musk, from the US Office of Personnel Management. A

4 févr. 2025 à 20:50:02 | Engadget
Adobe's Acrobat AI Assistant can now assess contracts for you

Adobe has updated the Acrobat AI Assistant, giving it the ability to un

4 févr. 2025 à 18:30:40 | Engadget
WhatsApp brings image and voice inputs to its ChatGPT integration

The tech sector’s ongoing effort to force-feed generative AI features into widely used services continues with updates to

4 févr. 2025 à 18:30:39 | Engadget