In a statement submitted to the Senate Health, Education, Labor and Pensions Committee for a hearing today on health care cybersecurity and patient privacy, the AHA said the highest cyber risk for patient data is often through third-party service and software providers. The AHA encouraged Congress to use federal agencies and resources to protect hospitals and health systems, and in turn the patients they serve, by combating international cyber threats and supporting funding for cybersecurity training and workforce, especially in rural areas.  

“Hospitals and health systems have invested billions of dollars and taken many steps to protect patients and defend their networks from cyberattacks that can disrupt patient care and erode privacy by the loss of personal health care data,” AHA said in its statement. “Any cyberattack on the health care sector that disrupts or delays patient care creates a risk to patient safety and crosses the line from an economic crime to a threat-of-life crime. These attacks should be aggressively pursued and prosecuted by the federal government.”  

The AHA also recommended reducing administrative burdens, like making the Health Insurance Portability and Accountability Act of 1996 cybersecurity requirements voluntary and strengthening the HIPAA preemption.  

“Rural hospitals are struggling under the crushing weight of these existing policies and thus support efforts to reduce and streamline regulatory burdens,” said hearing witness Linda Stevenson, chief information officer of Fisher-Titus Medical Center, a rural hospital in Ohio. In written testimony, she said, “We must shift away from punitive approaches that penalize providers who are targeted by malicious actors. These only worsen the burden and divert resources away from patient care. Instead, we need supportive policies that empower healthcare providers to strengthen their cyber defenses.” 

Headline
A joint advisory released Oct. 8 by U.S. and international agencies warns of Chinese government-linked cyber threat actors using automated and hands-on hacking…
Headline
The National Security Agency Oct. 8 released guidance for critical infrastructure organizations that recommends adopting high-impact zero trust strategies to…
Headline
The FBI and Secret Service released an advisory Oct. 6 warning of ongoing activities by FortiBleed, a global credential-compromise campaign used by threat…
Headline
In a new blog, John Riggi, AHA national advisor for cybersecurity and risk, and Scott Gee, AHA deputy national advisor for cybersecurity and risk, highlight…
Headline
The Senate passed the Health Care Cybersecurity and Resilience Act on Sept. 30 by unanimous consent. The bipartisan bill seeks to improve coordination between…
Headline
The AHA provided comments Sept. 30 to the Senate Homeland Security and Governmental Affairs Subcommittee on Disaster Management, District of Columbia and…