The Evolution and Impact of NIST CSF 2.0

NIST, or the U.S. National Institute of Standards and Technology, is at the forefront of the evolving realm of cybersecurity. Their goal is to provide recommendations that can be used as guideposts for industry best practices and more efficient ways of working However, cybersecurity is notoriously difficult to build standards around because the threat landscape […]

Recommendations on NIST Resource Guide

Fortified recently responded to an opportunity from NIST to comment on the utility of NIST Special Publication (SP) 800-66, Revision 1, commonly referred to as the Resource Guide. The Resource Guide and other industry standards are critical to the success of our clients to safeguard electronic protected health information (ePHI) and personally identifiable information (PII). […]

CISO Brief: Regulatory Update on the 2026 National Cybersecurity Strategy

The 2026 National Cybersecurity Strategy focuses on deterring geopolitical adversaries, protecting critical infrastructure, accelerating global technological leadership, modernizing federal systems and their private-sector partners, simplifying cyber regulations, and strengthening the cyber workforce. One of the more important signals for healthcare is that hospitals are increasingly being discussed alongside the energy grid, water utilities, and other critical […]

Is “Sorry” Good Enough? Insights from UHG’s Change Healthcare Testimony

On Wednesday, May 1, Andrew Witty, CEO of United Health Group (UHG), appeared before two congressional committees to discuss the recent Change Healthcare Breach. Mr. Witty expressed deep regret for the significant disruption the incident caused throughout the healthcare sector. During his testimony, he provided insight into how the attack happened, evaluated United Health Group’s […]

Navigating New York’s Cybersecurity Regulations for Hospitals

Unwilling to wait for the federal government to implement its cybersecurity regulations in healthcare, New York decided to take matters into its own hands by adopting groundbreaking new legislation.  On October 2nd the New York Department of Health announced new state cybersecurity requirements for hospitals, under Section 405.46 of Title 10. “New York state finalizing […]

Cybersecurity Resolutions: Focus on the Fundamentals

2018 is here. While many of us are a couple of weeks into our New Year’s resolutions, some may have already broken them, or are waiting for “tomorrow” to start them. Some resolutions remain the same and some are filled with new ambitions. Regardless, the only way to keep things moving forward is to start. […]

What’s Different About Securing PHI?

Cybersecurity and data loss prevention are critical IT components at any organization. Especially in the case of Protected Health Information (PHI). However, for companies that handle protected health information, ramping up network security to prevent a cybersecurity attack requires a heightened sense of urgency. A corporate online security breach can reveal consumer data such as […]

Is Your Healthcare Organization HIPAA Compliant?

For healthcare IT teams across the country, maintaining network security throughout an organization isn’t just about keeping data safe – it’s also about keeping their operations compliant. The medical industry’s rapidly increasing reliance on cloud-based technology and connected medical devices to transmit critical patient data have made cybersecurity issues and data loss prevention efforts top […]

What Does It Mean to Be HITRUST-Certified?

Healthcare providers across every specialty rely on high-performing technology to both treat and support their patients. Whether it’s integrating a cloud-based CRM to automate back office functioning such as appointment scheduling or billing, or incorporating the latest, state-of-the-art connected medical devices into a treatment protocol, innovation is at the very core of most healthcare organization’s […]

5 Things Healthcare Companies Miss When Preparing Audits

Audit. The mere mention of the word can instantly stir mild to moderate panic throughout even the most diligent healthcare IT department. For myriad of reasons, most healthcare organizations dread the idea of conducting industry-mandated cybersecurity risk assessments. Compliance evaluations are time-consuming, disrupting normal business activities, and potentially exposing network security risks and compromises. While […]