The Department of Health and Human Services’ Health Sector Cybersecurity Coordination Center (HC3) yesterday released a guide to help health care organizations protect their internet-connected devices and networks from Distributed Denial of Service attacks, which can keep providers and patients from accessing critical resources such as electronic health records and software-based medical equipment. In addition, HC3 last week released a report reviewing 2022 cybersecurity threats and some likely long-term trends to consider.

John Riggi, AHA’s national advisor for cybersecurity and risk, said, “Both of these guides contain specific recommendations to help mitigate the risk of various forms of cyberattack, from the simple to the complex, including high-impact ransomware attacks that disrupt care delivery. The information in these guides is a compilation of government threat intelligence, private-sector incident response findings and information provided by victim organizations. The HC3 trends report predicts that ransomware and data breaches will continue to plague the health care sector in 2023. The good news is that attention to cybersecurity basics such as email security, security of remote access technologies, patching and robust third-party risk management programs will go a long way in reducing the risk of cyberattacks in 2023 and beyond.” 
 
For more information on this or other cyber and risk issues, contact Riggi at jriggi@aha.org. For the latest cyber and risk resources and threat intelligence, visit aha.org/cybersecurity.

Headline
A joint advisory released April 23 from U.S. and international cybersecurity agencies, including the Cybersecurity and Infrastructure Security Agency, FBI,…
Headline
FBI Co-deputy Director Andrew Bailey discussed a rise in cyber and physical threats impacting health care. He discussed health care as the top critical…
Headline
Health care and public health was the top sector targeted for cyberthreats in 2025, according to the FBI’s latest annual report on internet crimes. There were…
Headline
The Cybersecurity and Infrastructure Security Agency released an alert March 27 on a vulnerability in F5 BIG-IP Access Policy Manager software that is being…
Headline
The FBI released an alert March 20 warning of a technique used by cyber actors working on behalf of the Iranian government to conduct malicious cyber activity…
Headline
The Cybersecurity and Infrastructure Security Agency March 18 released an alert urging U.S. organizations to harden their endpoint management systems following…