The Senate Committee on Homeland Security and Governmental Affairs today voted to advance as amended the Healthcare Cybersecurity Act (S.3904), AHA-supported legislation that would improve collaboration and coordination between the Cybersecurity and Infrastructure Security Agency and Department of Health and Human Services. Developed with input from the AHA, the bill also would authorize cybersecurity training and an analysis of cybersecurity risks for the health care and public health sector, with a focus on impacts to rural hospitals, medical devices and cybersecurity workforce shortages. 

At a House Judiciary Committee hearing yesterday, FBI Cyber Division Assistant Director Bryan Vorndran said disruptive cyber threats have targeted hospitals during the COVID-19 pandemic and credited the agency’s strong relationship with the AHA for helping to disseminate cyber threat intelligence to the field. 

John Riggi, AHA national advisor for cybersecurity and risk and former FBI cyber section chief, stated, “Especially in these times, we truly value the close relationship we have with the FBI. This has contributed to the FBI prioritizing their response to high impact ransomware attacks against hospitals as threat-to-life crimes and facilitated the AHA serving as a highly effective channel to disseminate timely threat information. Our partnership continues to help the hospital and health system field identify and defend against the most significant cyber threats we face.”

Related News Articles

Headline
U.S. and international agencies Jan. 14 released guidance on secure connectivity for operational technology environments. Examples of OT environments in health…
Headline
The AHA Jan. 14 expressed support for the Rural Hospital Cybersecurity Enhancement Act (S. 2169), legislation that would direct the Department of Health and…
Headline
The FBI Jan. 8 released an alert on evolving threat tactics by Kimsuky, a North Korean state-sponsored cyber threat group. As of last year, the group…
Headline
The Cybersecurity and Infrastructure Security Agency Dec. 11 released an update to its voluntary Cybersecurity Performance Goals, which includes measurable…
Headline
U.S. and international agencies are warning of potential cyberattacks on health care and other critical infrastructure from state-sponsored cyber actors in…
Headline
A critical, unauthenticated remote code execution vulnerability known as React2Shell has been added to the Cybersecurity and Infrastructure Security Agency’s…