The Cybersecurity and Infrastructure Security Agency recently required federal agencies to take emergency action to protect against actively exploited vulnerabilities in the Ivanti Connect Secure and Ivanti Policy Secure remote access gateways.

In addition, CISA, the FBI and Environmental Protection Agency recently published a best practices guide for water and wastewater system incident response.

“These alerts primarily address the government and water and waste water sectors,” said John Riggi, AHA’s national advisor for cybersecurity and risk. “However, they identify cyber vulnerabilities and defensive measures that have relevance for the health care sector. Although the CISA emergency directive does not apply to private sector organizations, it would be prudent for hospitals and health systems to identify instances of Ivanti present in their networks or those of business associates that have network or data access, to ensure the remediation steps in the alert are followed promptly. The water and wastewater guide provides practical incident response guidance for operational technology and for hospitals and health systems that operate their own water and wastewater treatment facilities and will help them in assessing the cyber readiness of their external water and waste water treatment facilities for emergency preparedness planning purposes.” 

For more information on this or cyber and risk matters contact Riggi at jriggi@aha.org. For the latest cyber and risk threat information and resources visit www.aha.org/cybersecurity
 

Headline
An FBI alert released Sept. 1 warns of cyber actors impersonating government officials, media and other public individuals on a commercial messaging app to…
Headline
In this conversation, John Riggi, AHA national advisor for cybersecurity and risk, and Scott Gee, AHA deputy national advisor for cybersecurity and risk, break…
Headline
Boston Scientific announced Sept. 8 that the network disruption to its remote monitoring services following an Aug. 25 cyber incident has been resolved. The…
Headline
The FBI and the Department of Justice Aug. 26 announced the disruption of a China-linked hacking group known as QTFY. The group, which also identifies as QT…
Headline
Boston Scientific, a large supplier of medical devices, said in an Aug. 26 statement posted on its website that on Aug. 25 it “identified a cybersecurity…
Headline
Epic’s MyChart has shared examples from potential phishing schemes observed as recently this month that include email messages linking to a fake MyChart…