Is “Sorry” Good Enough? Insights from UHG’s Change Healthcare Testimony

On Wednesday, May 1, Andrew Witty, CEO of United Health Group (UHG), appeared before two congressional committees to discuss the recent Change Healthcare Breach. Mr. Witty expressed deep regret for the significant disruption the incident caused throughout the healthcare sector. During his testimony, he provided insight into how the attack happened, evaluated United Health Group’s […]

Is Electronic Protected Health Information (ePHI) Getting Outside Your Healthcare Organization?

Under HIPAA regulations, health information or data that can be used to identify an individual patient is categorized as protected health information (PHI) and must undergo a wide range of practices explicitly designed to protect patient confidentiality. Covered entities must implement processes and controls to ensure confidentiality, integrity, and availability of physical PHI and electronic […]

Intro to Healthcare SIEM

Healthcare cybersecurity environments continue to become more complex as they embrace and rely on a diverse range of technologies to both manage and treat patients. Mobile access, cloud platforms, connected medical equipment, and IoT devices are just some of the many recent innovations used in practices across the country. This rapid rise of newly introduced […]

How to Successfully Navigate HIPAA Cybersecurity Requirements

In a world where technology evolves faster than we can say “cybersecurity,” one might wonder if the Health Insurance Portability and Accountability Act of 1996 (HIPAA) is still relevant. Surprisingly, it’s not just relevant; it’s an unsung guardian of our healthcare data.  Compliance with HIPAA is essential for healthcare organizations to maintain data security and […]

How to Protect your Healthcare Organization Against Social Engineering

Social engineering tactics, such as phishing, have become the go-to starting point for threat actors, especially against healthcare organizations. The success cybercriminals have with these attack methods means that it’s unlikely they’ll slow down any time soon. This is why it’s vital to arm your team and healthcare organization with knowledge about what social engineering […]

How to Make Cybersecurity Training Part of your Healthcare Culture

Ever clicked on a website link that you shouldn’t have? We’ve all made that mistake at least once, and chances are nothing bad happened. But the stakes are considerably higher in a hospital environment. Patient care takes place 24/7/365, and any cyberattack can cripple the ability to treat patients.  More than 90% of cyberattacks start […]

How the Best Organizations Manage Security Awareness Training Programs

Yawn. I’ve been here for six hours and all I’ve seen so far is someone who cut their finger slicing potatoes and someone who burned themselves trying to fry a turkey. What a lame Thanksgiving. I thought my first time working a holiday at a prestigious hospital would be more eventful than this. Time to […]

How Mature is your Healthcare SOC?

To combat increasingly sophisticated cybersecurity threats, healthcare entities must transition their Security Operations Center (SOC) from a reactive resource to a proactive and predictive force. But a SOC, especially in healthcare, doesn’t reach optimum levels overnight. In this post, we explore the evolutionary stages of SOC maturity, offering key insights on how healthcare organizations can […]

How Healthcare Organizations Should Strengthen Their Cybersecurity Framework

A strong cybersecurity framework guards against the most prominent cyber threats in healthcare.  This framework should also be scalable to meet new threats.  By staying aware of the latest cyber attacks in healthcare and prepping your security team, your organization can keep a step ahead of today’s cyber criminals. Here is what every healthcare organization […]

How Health Systems Can Reduce their Attack Surface with VTM

What is attack surface management? Think of your attack surface as a fortress with multiple entry points. Each entry point represents a system or network weakness that could potentially be breached by an intruder. These weaknesses, like outdated patches, misconfigurations, and traditional vulnerabilities, serve as open doors or unguarded walls that can be exploited by […]