Is “Sorry” Good Enough? Insights from UHG’s Change Healthcare Testimony

On Wednesday, May 1, Andrew Witty, CEO of United Health Group (UHG), appeared before two congressional committees to discuss the recent Change Healthcare Breach. Mr. Witty expressed deep regret for the significant disruption the incident caused throughout the healthcare sector. During his testimony, he provided insight into how the attack happened, evaluated United Health Group’s […]

Are You Introducing Risk to Your Organization? Here’s How to Find Out.

The last few years have thrown many curveballs, like Covid, cyberinsurance changes, and a record number of attacks, at healthcare IT and Security teams. During these trying times, many teams were understaffed and resource-constrained, trying to put out daily “fires” and helping maintain efficient patient care. As a result, some fundamental elements of the organization’s […]

How to Make Third-Party Risk Manageable

A new Fortified webinar, “Make Third-Party Risk Manageable,” will help you take steps to protect your organization from the security threats posed by vendors. This informative webinar is hosted by Melissa Adams, Fortified’s Director of Third-Party Risk Management, and Jared Michaels, Principal Solutions Architect. Some of the largest healthcare breaches in recent years have involved […]

Why Healthcare Third-Party Risk Management (TPRM) Must Change

Healthcare organizations are on the front line of protecting some of the most sensitive data in the world. Patients’ health information, treatment records, insurance details, and identifiers must be safeguarded at all times. But as we have seen over the past year, that responsibility does not stop at your firewall. It extends outward into a […]

The Evolution of TPRM in Healthcare: From Spreadsheets to Strategic Change

Third-party risk management (TPRM) is no longer a nice-to-have in healthcare; it’s a strategic necessity. Healthcare organizations are under growing pressure to manage third-party risk more effectively. High-profile incidents like the Change Healthcare breach have shown just how deep the ripple effects of a vendor issue can run; impacting operations, financial systems, and patient care […]

Lessons from the Front Lines: Learning from the SolarWinds Attack

Two security engineers take us into the trenches—and talk about what happened afterward. James Edgell and Dan Colon work in IT security for Lawrence General Hospital in Lawrence, MA. Normally they spend their days scanning systems, working on cybersecurity awareness newsletters, coordinating with Fortified on business impact analyses, and other routine tasks. However, it wasn’t […]

Third-Party Risk Management in Healthcare: The “Must-Haves”

The rising costs associated with cybersecurity breaches, like the Change Healthcare incident and CrowdStrike breach, underscore the severe consequences and need for third-party risk management in healthcare. These incidents serve as urgent reminders of how much damage can result from unmitigated vulnerabilities. Healthcare organizations, which rely heavily on third-party vendors and external partners, must actively […]

Third-Party Risk Management: A Guide to More Secure Partnerships

The use of third-party vendors has become essential for delivering comprehensive patient care, streamlining operations, and enhancing service quality in healthcare. However, these relationships present complex data security challenges for healthcare organizations. This article will explore the complexities of managing third-party risk in healthcare, how threat actors exploit vendor vulnerabilities, and provide best practices for […]

The Next Big Challenge in Healthcare Is Here. Are You Prepared?

Third-Party Risk Management, or TPRM, is a growing concern for healthcare organizations. According to the 2022 Ponemon Industry Report, 63% of respondents stated that while cybersecurity incidents involving third parties are increasing, they feel ineffective at controlling third-party risk. Additionally, 55% of healthcare organizations had experienced a data breach in the twelve months before the […]