The AHA today hosted a briefing on Capitol Hill to examine cybersecurity threats facing the health care sector, and share how hospitals and health systems are responding. John Riggi, AHA senior advisor for cybersecurity and risk, said hospitals and health systems take seriously the protection of highly-sensitive and valuable information, and employ important security measures to safeguard clinical technologies and information systems, while continuing to enhance their data protection capabilities. “Cybersecurity is not just an information technology issue focused on risk to the security and privacy of patient data, it is an enterprise risk management issue focused on patient safety and delivery of care as a priority,” said Riggi, who joined the AHA in February after spending nearly 30 years with the Federal Bureau of Investigation in a variety of assignments. He explained that many hackers, have moved from hacking credit cards to health records because they can sell the health data for 10 times more than the credit card data on the dark web. Among other key takeaways, Riggi said hospitals and health systems should have good offline backups in case data becomes encrypted from ransomware attacks, and ensure vendors manage cybersecurity risks to their systems, since any potential attack against a vendor could result in harm to a hospital or health system’s information systems.

Headline
An FBI alert released Sept. 1 warns of cyber actors impersonating government officials, media and other public individuals on a commercial messaging app to…
Headline
In this conversation, John Riggi, AHA national advisor for cybersecurity and risk, and Scott Gee, AHA deputy national advisor for cybersecurity and risk, break…
Headline
Boston Scientific announced Sept. 8 that the network disruption to its remote monitoring services following an Aug. 25 cyber incident has been resolved. The…
Headline
The FBI and the Department of Justice Aug. 26 announced the disruption of a China-linked hacking group known as QTFY. The group, which also identifies as QT…
Headline
Boston Scientific, a large supplier of medical devices, said in an Aug. 26 statement posted on its website that on Aug. 25 it “identified a cybersecurity…
Headline
Epic’s MyChart has shared examples from potential phishing schemes observed as recently this month that include email messages linking to a fake MyChart…