H-ISAC Report: Hacking Healthcare - TLP White, March 10, 2020

This edition of Hacking Healthcare, breaksdown new guidance from the Department of Justice (DOJ) on the legal considerations of engaging in cyber threat intelligence activities; examines the European Union Agency for Cybersecurity’s (ENISA) 51-page report on procurement cybersecurity for hospitals that provides comprehensive guidance applicable to many organizations in the healthcare sector; and explores a Government Accountability Office (GAO) report that recommends NIST Cybersecurity Framework adoption and assessment across all critical infrastructure sectors.

In this edition:

  • DOJ Releases Guidance on Gathering Cyber Threat Intelligence
  • ENISA Releases Hospital Procurement Guidelines.
  • GAO Releases Study on Critical Infrastructure Adoption of NIST Cybersecurity
    Framework.

Related Resources

Standards/Guidelines
Public
Agent Tesla is an established Remote Access Trojan (RAT) written in .Net. A successful deployment of Agent Tesla provides attackers with full computer or…
Webinar Recordings
Public
The U.S. Department of Health and Human Services’ (HHS) Health Sector Cybersecurity Coordination Center (HC3) invites you to join its monthly cybersecurity…
Guides/Reports
Working from Home during COVID-19 Pandemic During the COVID-19 pandemic, many physicians are working from home, using their personal computers and mobile…
Guides/Reports
Public
Mozilla Patches Critical Vulnerabilities in Firefox, Firefox ESR 04/03/2020 04:45 PM EDT Original release date: April 3, 2020 Mozilla has released security…
Special Bulletin
Public
A recent campaign of cyberattacks from a foreign threat actor targeted healthcare organizations and specifically exploited Citrix and Zoho technologies used…
Advisory
Public
The Centers for Medicare & Medicaid Services will prioritize and conduct only certain surveys during the COVID-19 national emergency’s three-week…