In a statement submitted to the Senate Health, Education, Labor and Pensions Committee for a hearing today on health care cybersecurity and patient privacy, the AHA said the highest cyber risk for patient data is often through third-party service and software providers. The AHA encouraged Congress to use federal agencies and resources to protect hospitals and health systems, and in turn the patients they serve, by combating international cyber threats and supporting funding for cybersecurity training and workforce, especially in rural areas.  

“Hospitals and health systems have invested billions of dollars and taken many steps to protect patients and defend their networks from cyberattacks that can disrupt patient care and erode privacy by the loss of personal health care data,” AHA said in its statement. “Any cyberattack on the health care sector that disrupts or delays patient care creates a risk to patient safety and crosses the line from an economic crime to a threat-of-life crime. These attacks should be aggressively pursued and prosecuted by the federal government.”  

The AHA also recommended reducing administrative burdens, like making the Health Insurance Portability and Accountability Act of 1996 cybersecurity requirements voluntary and strengthening the HIPAA preemption.  

“Rural hospitals are struggling under the crushing weight of these existing policies and thus support efforts to reduce and streamline regulatory burdens,” said hearing witness Linda Stevenson, chief information officer of Fisher-Titus Medical Center, a rural hospital in Ohio. In written testimony, she said, “We must shift away from punitive approaches that penalize providers who are targeted by malicious actors. These only worsen the burden and divert resources away from patient care. Instead, we need supportive policies that empower healthcare providers to strengthen their cyber defenses.” 

Headline
John Riggi, AHA national advisor for cybersecurity and risk, shares insights from a conversation with two FBI leaders about the surge of cyberattacks on the U.…
AHA Cyber Intel
Earlier this year, the FBI launched a two-month national campaign, Operation Winter SHIELD (Securing Homeland Infrastructure by Enhancing Layered Defense),…
Headline
The Cybersecurity and Infrastructure Security Agency and other U.S. and international partners July 22 released an updated advisory on Iranian-affiliated cyber…
Headline
Edward You, former FBI Supervisory Special Agent and founder of EHY Consulting, explains why healthcare organizations must look beyond artificial intelligence…
Headline
The Cybersecurity and Infrastructure Security Agency has issued an alert warning of four Microsoft SharePoint vulnerabilities being exploited by cyber threat…
Headline
The White House July 14 announced the establishment of Gold Eagle, a clearinghouse to enhance cybersecurity for critical infrastructure entities that will…