The National Security Agency, Cybersecurity and Infrastructure Security Agency and international partners released joint guidance Oct. 30 on best practices for Microsoft Exchange server security. The guidance includes recommendations and prevention measures specifically for on-premises Exchange servers to help mitigate risk of being compromised. The agencies said that Microsoft Exchange Server Subscription Edition is the only supported on-prem version of the product, as Microsoft ended support for previous versions Oct. 14. Older versions are now at a heightened risk of compromise, and the guidance recommended users migrate to Exchange Server SE or an alternative supported email server software or service. 
 
“Previous versions of Exchange have been deprecated,” said Scott Gee, AHA deputy national advisor for cybersecurity and risk. “Hospitals still using these versions of Exchange should pay particular attention to this bulletin and closely monitor security settings in your environment.” 
 
For more information on this or other cyber and risk issues, contact Gee at sgee@aha.org. For the latest cyber and risk resources and threat intelligence, visit aha.org/cybersecurity.

Related News Articles

Headline
The National Institute of Standards and Technology Feb. 2 published details on a critical vulnerability that impacted Notepad++, a free, open-source text and…
Headline
The FBI has launched a two-month campaign, Operation Winter SHIELD (Securing Homeland Infrastructure by Enhancing Layered Defense), highlighting 10 actions…
Headline
Two AHA guides offer strategies for hospitals and health systems in preparing for public health emergencies and disasters and managing cybersecurity incidents…
Headline
Larry Pierce, director of cybersecurity and information security officer for Atlantic Health, unpacks how the growth of artificial intelligence is reshaping…
Headline
U.S. and international agencies Jan. 14 released guidance on secure connectivity for operational technology environments. Examples of OT environments in health…
Headline
The AHA Jan. 14 expressed support for the Rural Hospital Cybersecurity Enhancement Act (S. 2169), legislation that would direct the Department of Health and…