HHS Unveils Next Steps to Enhance Cybersecurity of Health Care Records

December 6, 2023 by Dan McCue
HHS Unveils Next Steps to Enhance Cybersecurity of Health Care Records
(Photo via Pixabay)

WASHINGTON — The bad guys in cyberspace want your health care records. 

Between 2018 and 2022, there was a 93% increase in large breaches in the health care sector, with a 278% increase in large breaches involving ransomware, according to the Department of Health and Human Services’ Office for Civil Rights.

As a result of the breaches, the bad actors behind them have caused extended care disruptions, patient diversions to other facilities and delayed medical procedures, all putting patient safety at risk.

In an effort to address the issue, HHS on Wednesday released a concept paper that succinctly outlines its cybersecurity strategy for the health care sector. 

The concept paper builds on the National Cybersecurity Strategy that President Joe Biden released last year, focusing specifically on strengthening resilience for hospitals, patients and communities threatened by cyberattacks. 

In doing so, it details four pillars for action, including publishing new voluntary health care-specific cybersecurity performance goals, working with Congress to develop support and incentives for domestic hospitals to improve cybersecurity, and increasing accountability and coordination within the health care sector.

“Since entering office, the Biden-Harris administration has worked to strengthen the nation’s defenses against cyberattacks. The health care sector is particularly vulnerable, and the stakes are especially high,” said HHS Secretary Xavier Becerra in a written statement.

“HHS is working with health care and public health partners to bolster our cybersecurity capabilities nationwide. We are taking necessary actions that will make a big difference for the hospitals, patients and communities who are being impacted,” he said.

The specific actions outlined in the HHS concept paper are as follows. It has committed to:

  • Publish voluntary Health care and Public Health sector Cybersecurity Performance Goals. HHS will release HPH CPGs to help health care institutions plan and prioritize implementation of high-impact cybersecurity practices.
  • Provide resources to incentivize and implement cybersecurity practices. HHS will work with Congress to obtain new authority and funding to administer financial support and incentives for domestic hospitals to implement high-impact cybersecurity practices.
  • Implement an HHS-wide strategy to support greater enforcement and accountability. HHS will propose new enforceable cybersecurity standards, informed by the HPH CPGs, that would be incorporated into existing programs, including Medicare and Medicaid and the HIPAA Security Rule.
  • Expand and mature the one-stop shop within HHS for health care sector cybersecurity. HHS will mature the Administration for Strategic Preparedness and Response’s coordination role as a “one-stop shop” for health care cybersecurity with the aim of improving coordination within HHS and the federal government, deepen HHS and the federal government’s partnership with industry, and increase HHS’s incident response capabilities.

“The health care sector is experiencing a significant rise in cyberattacks, putting patient safety at risk. These attacks expose vulnerabilities in our health care system, degrade patient trust and ultimately endanger patient safety,” said HHS Deputy Secretary Andrea Palm in a statement. 

“HHS takes these threats very seriously, and we are taking steps that will ensure our hospitals, patients and communities impacted by cyberattacks are better prepared and more secure,” she said.

Dan can be reached at [email protected] and @DanMcCue

A+
a-
  • cybersecurity
  • Department of Health and Human Services
  • health care records
  • security breaches
  • In The News

    Health

    Voting

    Cybersecurity

    December 31, 2024
    by Tom Ramstack
    Chinese Accused of Hacking US Treasury Dept. Computers

    WASHINGTON — A Chinese intelligence agency recently hacked the workstations and unclassified documents of the U.S. Treasury Department, the Biden... Read More

    WASHINGTON — A Chinese intelligence agency recently hacked the workstations and unclassified documents of the U.S. Treasury Department, the Biden administration announced Monday. The hack attack is one of several Chinese-sponsored incidents the U.S. Cybersecurity and Infrastructure Security Agency says have compromised the data privacy of... Read More

    The US and Microsoft Disrupt a Russian Hacking Group Targeting American Officials and Nonprofits

    WASHINGTON (AP) — A hacking group tied to Russian intelligence tried to worm its way into the systems of dozens... Read More

    WASHINGTON (AP) — A hacking group tied to Russian intelligence tried to worm its way into the systems of dozens of Western think tanks, journalists and former military and intelligence officials, Microsoft and U.S. authorities said Thursday. The group, known as Star Blizzard to cyberespionage experts,... Read More

    Americans Reporting Nationwide Cellular Outages From AT&T, Cricket Wireless and Others

    A number of Americans are dealing with cellular outages on AT&T, Cricket Wireless, Verizon, T-Mobile and other service providers, according... Read More

    A number of Americans are dealing with cellular outages on AT&T, Cricket Wireless, Verizon, T-Mobile and other service providers, according to data from Downdetector. AT&T had more than 73,000 outages around 9:30 a.m. ET, in locations including Houston, Atlanta and Chicago. The outages began at approximately... Read More

    States and Congress Wrestle With Cybersecurity at Water Utilities Amid Renewed Federal Warnings

    HARRISBURG, Pa. (AP) — The tiny Aliquippa water authority in western Pennsylvania was perhaps the least-suspecting victim of an international... Read More

    HARRISBURG, Pa. (AP) — The tiny Aliquippa water authority in western Pennsylvania was perhaps the least-suspecting victim of an international cyberattack. It had never had outside help in protecting its systems from a cyberattack, either at its existing plant that dates to the 1930s or the... Read More

    December 6, 2023
    by Dan McCue
    HHS Unveils Next Steps to Enhance Cybersecurity of Health Care Records

    WASHINGTON — The bad guys in cyberspace want your health care records.  Between 2018 and 2022, there was a 93%... Read More

    WASHINGTON — The bad guys in cyberspace want your health care records.  Between 2018 and 2022, there was a 93% increase in large breaches in the health care sector, with a 278% increase in large breaches involving ransomware, according to the Department of Health and Human... Read More

    Insider Q&A: Pentagon AI Chief on Network-Centric Warfare, Generative AI Challenges

    The Pentagon's chief digital and artificial intelligence offer, Craig Martell, is alarmed by the potential for generative artificial intelligence systems... Read More

    The Pentagon's chief digital and artificial intelligence offer, Craig Martell, is alarmed by the potential for generative artificial intelligence systems like ChatGPT to deceive and sow disinformation. His talk on the technology at the DefCon hacker convention in August was a huge hit. But he's anything... Read More

    News From The Well
    scroll top