The AHA July 2 submitted comments to the Cybersecurity and Infrastructure Security Agency on its proposed rule establishing reporting requirements for cybersecurity incidents under the Cyber Incident Reporting for Critical Infrastructure Act. The AHA called the requirements redundant to those from other federal agencies and that they add an unnecessary burden to hospitals while maintaining care through a cybersecurity incident. AHA urged CISA and other agencies to guarantee data anonymity across all federal agencies, and said applicability of the reporting rules are confusing, calling for them to be simplified due to compliance and operational burdens to hospitals in addition to privacy risks. AHA also expressed concern about the proposed rule’s penalties, calling them “vague and potentially severe,” and recommended that CISA revise the rule to incentivize collaboration instead.

Headline
The Cybersecurity and Infrastructure Security Agency and other U.S. and international partners July 22 released an updated advisory on Iranian-affiliated cyber…
Headline
Edward You, former FBI Supervisory Special Agent and founder of EHY Consulting, explains why healthcare organizations must look beyond artificial intelligence…
Headline
The Cybersecurity and Infrastructure Security Agency has issued an alert warning of four Microsoft SharePoint vulnerabilities being exploited by cyber threat…
Headline
The White House July 14 announced the establishment of Gold Eagle, a clearinghouse to enhance cybersecurity for critical infrastructure entities that will…
Headline
The Centers for Medicare & Medicaid Services, the Centers for Disease Control and Prevention, and the Department of Health and Human Services July 15…
Headline
The Cybersecurity and Infrastructure Security Agency and other U.S. and international agencies released a joint advisory July 13, warning of Russian cyber…