Healthcare organizations in the US may soon get a cybersecurity overhaul

A set of new requirements proposed by the US Department of Health and Human Services’ (HHS) Office for Civil Rights could bring healthcare organizations up to par with modern cybersecurity practices. The proposal, posted to the Federal Register on Friday, includes requirements for multifactor authentication, data encryption and routine scans for vulnerabilities and breaches. It would also make the use of anti-malware protection mandatory for systems handling sensitive information, along with network segmentation, the implementation of separate controls for data backup and recovery, and yearly audits to check for compliance.

HHS also shared a fact sheet outlining the proposal, which would update the Health Insurance Portability and Accountability Act of 1996 (HIPAA) Security Rule. A 60-day public comment period is expected to open soon. In a press briefing, US deputy national security advisor for cyber and emerging technology Anne Neuberger said the plan would cost $9 billion in the first year to execute, and $6 billion over the subsequent four years, Reuters reports. The proposal comes in light of a marked increase in large-scale breaches over the past few years. Just this year, the healthcare industry was hit by multiple major cyberattacks, including hacks into Ascension and UnitedHealth systems that caused disruptions at hospitals, doctors’ offices and pharmacies.

“From 2018-2023, reports of large breaches increased by 102 percent, and the number of individuals affected by such breaches increased by 1002 percent, primarily because of increases in hacking and ransomware attacks,” according to the Office for Civil Rights. “In 2023, over 167 million individuals were affected by large breaches — a new record.”

This article originally appeared on Engadget at https://www.engadget.com/cybersecurity/healthcare-organizations-in-the-us-may-soon-get-a-cybersecurity-overhaul-220933165.html?src=rss https://www.engadget.com/cybersecurity/healthcare-organizations-in-the-us-may-soon-get-a-cybersecurity-overhaul-220933165.html?src=rss
Creato 18d | 28 dic 2024, 23:50:26


Accedi per aggiungere un commento

Altri post in questo gruppo

LG Display's new OLEDs are even brighter and more power-efficient

LG Display is introducing its 4th-generation OLED TV displays today, which manage to not only be brighter than what it

16 gen 2025, 03:50:05 | Engadget
Tubi will livestream the 2025 Super Bowl for free in 4K

The Super Bowl tends to be a cultural moment, even for people who don't know an extra point from a safety. This year, if you want to see the whole program, including the halftime show by Kendrick L

16 gen 2025, 01:30:09 | Engadget
How to watch the Samsung Galaxy S25 Unpacked event

We're nearly a month into 2025, and it's time for another flagship smartphone announcement. Samsung's

15 gen 2025, 23:20:14 | Engadget
Google brings real-time information from The Associated Press to Gemini

Google is partnering with The Associated Press to bring real-time information from the news agency to its Gemini app, the search giant

15 gen 2025, 20:50:18 | Engadget
God of War Ragnarök headlines the PlayStation Plus Game Catalog additions for January

Sony is set to freshen up the PlayStation Plus Game Catalog for Extra and Premium subscribers with a

15 gen 2025, 20:50:17 | Engadget
FTC sues John Deere over ‘unfair corporate tactics’ and ‘high repair costs’

The Federal Trade Commission (FTC) has

15 gen 2025, 20:50:16 | Engadget
The Acura RSX calls dibs on Honda's proprietary Asimo OS

Honda has announced that its first original EV design, the

15 gen 2025, 18:31:07 | Engadget