HHS faces flak over new cyber center

The Department of Health and Human Services’ new national cybersecurity intelligence-sharing clearinghouse appears to duplicate the role of similar entities in the federal government and in the private sector, say key lawmakers and some leaders in the health care industry. Critics say the creation of the Healthcare Cybersecurity and Communications Integration Center, or HCCIC, is moving the goalposts for the industry, which was answering the U.S. government’s call to create a private-sector cyberthreat-sharing ecosystem. HCCIC is being modeled after the Department of Homeland Security’s 24-hour watch center, the National Cybersecurity and Communications Integration Center, or NCCIC — and some fret it may duplicate its functions. Defenders of the new clearinghouse are playing down the idea that HCCIC might be redundant. They argue it can provide a depth of specialist knowledge about the health care sector DHS lacks, and that the industry’s own membership-based information sharing organizations cannot match the universal service HCCIC will provide. The health care industry “feels […]

The post HHS faces flak over new cyber center appeared first on Cyberscoop.

Continue reading HHS faces flak over new cyber center

WannaCry outbreak was first big test of HHS’s new cybersecurity center for health sector

When the WannaCry computer worms crippled the British National Health Service last month, the response at the U.S. Department of Health and Human Services was led by a new cybersecurity watch center, lawmakers heard Thursday. The Healthcare Cybersecurity and Communications Integration Center, “coordinated the response to WannaCry,” Steve Curren, director of resilience in the HHS Office of Emergency Management, told a House Energy and Commerce subcommittee. When the WannaCry worm struck, crippling dozens of British hospitals, HHS officials “took immediate action to engage [the] broader U.S. health sector and ensure that IT security specialists had the information they needed to protect against, respond to and report intrusions,” Curren said. The HCCIC, (pronounced “aitch-kick”) came online in May is modeled on the Department of Homeland Security’s National Cybersecurity and Communications Integration Center — a 24-hour watch center that pulls in real-time data from vital national industries like banking and telecommunications and distributes warnings and other information. […]

The post WannaCry outbreak was first big test of HHS’s new cybersecurity center for health sector appeared first on Cyberscoop.

Continue reading WannaCry outbreak was first big test of HHS’s new cybersecurity center for health sector

Federal report: Hospital cybersecurity is in ‘critical condition’

Many American hospitals and health care practices are critically vulnerable to cyberattack and lack the resources to protect against rising threats, according to a long-awaited report issued by the U.S. Department of Health and Human Service’s Health Care Industry Cybersecurity Task Force. The starkly negative report points to problems beyond hardware and software. The task force, established a year go, is made up of 21 security experts, health care professionals and government officials. “Many organizations cannot afford to retain in-house information security personnel, or designate an information technology (IT) staff member with cybersecurity as a collateral duty,” the task force reported. “These organizations often lack the infrastructure to identify and track threats, the capacity to analyze and translate the threat data they receive into actionable information, and the capability to act on that information.” The talent shortage that hampers cybersecurity in all sectors hits health care especially hard so that the industry leans especially hard on part-time positions or […]

The post Federal report: Hospital cybersecurity is in ‘critical condition’ appeared first on Cyberscoop.

Continue reading Federal report: Hospital cybersecurity is in ‘critical condition’

HHS working on cyber guidelines for health industry

The U.S. Department of Health and Human Services, taking a cue from Congress, has begun developing principles and best practices for cybersecurity in health care, officials said Tuesday. “We had an information day … and we are kicking off next week,” said Julie Anne Chua, from the office of the department’s chief information officer. She spoke at a cybersecurity workshop at the National Institute of Standards and Technology. Section 405d of the 2015 Cybersecurity Act — passed as part of the massive omnibus appropriations nearly 18 months ago — is titled “Aligning health care industry security approaches.” It mandates the HHS secretary “to lead a task group to put together a set of voluntary, consensus-based principles and best practices for cybersecurity in the health sector,” explained Chua. As the law requires, it will be consistent with the NIST Cybersecurity Framework and the privacy and security provisions of the Health Insurance Portability and […]

The post HHS working on cyber guidelines for health industry appeared first on Cyberscoop.

Continue reading HHS working on cyber guidelines for health industry

As .gov turns to cloud, agency heads deliberate cyber-defense strategies

Agencies across the U.S. government are increasingly looking to migrate their data into the cloud to cut costs, but doing so has also introduced new cybersecurity challenges, federal executives said Wednesday during Verizon’s Government of the Future conference produced by FedScoop. Each government agency is defined by a very specific mission set, explained Census Bureau […]

The post As .gov turns to cloud, agency heads deliberate cyber-defense strategies appeared first on Cyberscoop.

Continue reading As .gov turns to cloud, agency heads deliberate cyber-defense strategies

Feds move to stop social media mockery of nursing home residents

Workers sharing degrading/intimate/nonconsensual photos and videos may mean facilities get fined, written up or cut from Medicare. Continue reading Feds move to stop social media mockery of nursing home residents