Healthcare organizations in the US may soon get a cybersecurity overhaul

A set of new requirements proposed by the US Department of Health and Human Services’ (HHS) Office for Civil Rights could bring healthcare organizations up to par with modern cybersecurity practices. The proposal, posted to the Federal Register on Friday, includes requirements for multifactor authentication, data encryption and routine scans for vulnerabilities and breaches. It would also make the use of anti-malware protection mandatory for systems handling sensitive information, along with network segmentation, the implementation of separate controls for data backup and recovery, and yearly audits to check for compliance.

HHS also shared a fact sheet outlining the proposal, which would update the Health Insurance Portability and Accountability Act of 1996 (HIPAA) Security Rule. A 60-day public comment period is expected to open soon. In a press briefing, US deputy national security advisor for cyber and emerging technology Anne Neuberger said the plan would cost $9 billion in the first year to execute, and $6 billion over the subsequent four years, Reuters reports. The proposal comes in light of a marked increase in large-scale breaches over the past few years. Just this year, the healthcare industry was hit by multiple major cyberattacks, including hacks into Ascension and UnitedHealth systems that caused disruptions at hospitals, doctors’ offices and pharmacies.

“From 2018-2023, reports of large breaches increased by 102 percent, and the number of individuals affected by such breaches increased by 1002 percent, primarily because of increases in hacking and ransomware attacks,” according to the Office for Civil Rights. “In 2023, over 167 million individuals were affected by large breaches — a new record.”

This article originally appeared on Engadget at https://www.engadget.com/cybersecurity/healthcare-organizations-in-the-us-may-soon-get-a-cybersecurity-overhaul-220933165.html?src=rss https://www.engadget.com/cybersecurity/healthcare-organizations-in-the-us-may-soon-get-a-cybersecurity-overhaul-220933165.html?src=rss
Établi 3d | 28 déc. 2024 à 23:50:26


Connectez-vous pour ajouter un commentaire

Autres messages de ce groupe

The best SSDs in 2025

When it comes to boosting your system’s performance, upgrading to one of the fastest SSDs is a no-brainer. Whether you’re building a gaming PC, speeding up an older laptop or simply craving lightni

31 déc. 2024 à 21:30:11 | Engadget
Squid Game's second season is officially Netflix's biggest TV debut

Squid Game has set a new high for Netflix's television programming.

31 déc. 2024 à 21:30:10 | Engadget
Bluesky and Threads showed us very different visions for a post-X future

There’s no longer any question that Threads and Bluesky have created the most viable alternatives to the platform once known as Twitter. But while the two services may share some of the same goals,

31 déc. 2024 à 19:10:16 | Engadget
Terraform Labs co-founder Do Kwon will face securities fraud charges in the US

Terraforms Labs CEO Do Kwon spent the last day of 2024 getting extradited to the US,

31 déc. 2024 à 16:50:05 | Engadget
Russia is trying to make its own game consoles in a bid for technological independence

It’s no secret that Russia has been slowly working towards eschewing as much Western technology as it can and developing its own, and its latest effort seems to be related to video games. On Decemb

31 déc. 2024 à 16:50:04 | Engadget
Dang, 2024 was a great year for horror game fans

When it comes to new horror games, there are times of feast and famine, and this past year we gorged until our bellies bulged and our mouths dripped with gruesome grease. In 2024, we received a ric

31 déc. 2024 à 16:50:03 | Engadget
The Morning After: A microwave with a 27-inch touchscreen

We’re wrapping up 2024, so why not do it with some frivolous CES announcements? Like this premium (it has to be premium!)

31 déc. 2024 à 14:30:10 | Engadget