The AHA July 2 submitted comments to the Cybersecurity and Infrastructure Security Agency on its proposed rule establishing reporting requirements for cybersecurity incidents under the Cyber Incident Reporting for Critical Infrastructure Act. The AHA called the requirements redundant to those from other federal agencies and that they add an unnecessary burden to hospitals while maintaining care through a cybersecurity incident. AHA urged CISA and other agencies to guarantee data anonymity across all federal agencies, and said applicability of the reporting rules are confusing, calling for them to be simplified due to compliance and operational burdens to hospitals in addition to privacy risks. AHA also expressed concern about the proposed rule’s penalties, calling them “vague and potentially severe,” and recommended that CISA revise the rule to incentivize collaboration instead.

Headline
A joint advisory released Aug. 19 by the FBI, Cybersecurity and Infrastructure Security Agency, and the Department of Health and Human Services provides…
Headline
The Department of Health and Human Services Aug. 14 released a request for comments through the Office of the National Coordinator for Health IT on a proposed…
Perspective
Public
Every day, hospitals and health systems perform a remarkable balancing act. They invest in talented caregivers, advanced technologies, innovative partnerships…
Headline
U.S. and international agencies released a joint cybersecurity advisory Aug. 10 warning of actions by Gunra ransomware. Gunra is a ransomware-as-a-service…
Headline
The Cybersecurity and Infrastructure Security Agency and other U.S. and international agencies July 29 released joint guidance outlining minimum elements for a…
Headline
John Riggi, AHA national advisor for cybersecurity and risk, shares insights from a conversation with two FBI leaders about the surge of cyberattacks on the U.…