A new brief from the Department of Health and Human Services’ Health Sector Cybersecurity Coordination Center (HC3) offers tips to protect health care organizations from basic web application attacks, which have targeted patient portals and commonly use stolen credentials or known vulnerabilities to expose patient data. 
 
“This type of attack, which involves cyber adversaries exploiting flaws in internet or public-facing websites such as patient portals, is a serious issue for health care,” said John Riggi, AHA’s national advisor for cybersecurity and risk. “Besides risking the security of patient data, these types of attacks have been leveraged in the past year to conduct high-impact ransomware attacks against at least one large health system and a major health care scheduling and payroll vendor, both of which disrupted health care delivery services for several weeks. It is essential for hospitals and health systems to conduct ongoing vulnerability scanning and regular penetration testing of all web resources, one of the many recommendations contained in the HC3 briefing.”
 
For more information on this or other cyber and risk issues, contact Riggi at jriggi@aha.org.

Related News Articles

Headline
The FBI Sept. 12 released an alert warning of malicious activities by cybercriminal groups UNC6040 and UNC6395, which the agency said are responsible for an…
Headline
The Cybersecurity and Infrastructure Security Agency, National Security Agency and international agencies Sept. 3 released joint guidance outlining a “software…
Headline
Chinese state-sponsored cyber actors are maliciously targeting networks globally, including telecommunications, government and others, according to a joint…
Headline
The FBI Aug. 20 released an advisory warning of malicious activity by Russian cyber actors targeting end-of-life devices running an unpatched vulnerability in…
Headline
The Cybersecurity and Infrastructure Security Agency, Environmental Protection Agency, National Security Agency, FBI and international agencies Aug. 13…
Headline
The Department of Justice Aug. 11 announced a series of actions taken against the BlackSuit ransomware group, also known as “Royal,” including the disruption…