Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Vulnerabilities / Threats

7/15/2016
03:45 PM
Connect Directly
Google+
Twitter
RSS
E-Mail
50%
50%

New HIPAA Guidance Tackles Ransomware Epidemic In Healthcare

HHS addresses ransomware infections in wake of healthcare attacks.

It took ransomware infections that brought two major hospital systems to their knees earlier this year to demonstrate how dangerous malware can be for healthcare organizations. Now the federal government has issued new guidance via the Healthcare Insurance Portability and Accountability Act (HIPAA) to address ransomware attacks.

The US Health and Human Services Office for Civil Rights this week issued guidelines for helping healthcare organizations understand, prevent, and prepare for ransomware attacks. It provides information on what ransomware is, how attacks work, how to spot it, how to quell damage, and of course how to protect data with regular backups. The guidance notes that existing HIPAA requirements basically cover ransomware attacks, and explains how a ransomware attack maps to those rules.

“The new guidance reinforces activities required by HIPAA that can help organizations prevent, detect, contain, and respond to threats,” Jocelyn Samuels, director of the Office of Civil Rights, wrote in a blog post. Among those practices: running a risk analysis of threats to electronic health information; training users to detect malware; limiting user access to electronic health records; and establishing a contingency plan including regular data backups, test restoration, and emergency operations.

“Organizations need to take steps to safeguard their data from ransomware attacks. HIPAA covered entities and business associates are required to develop and implement security incident procedures and response and reporting processes that are reasonable and appropriate to respond to malware and other security incidents,” Samuels said.

While having HIPAA address ransomware makes sense, some security experts say it’s no guarantee users won’t still fall for a phish or link in an email.  “Any new guidance that can help healthcare organizations prevent, detect, contain, and respond to threats (especially ransomware) is obviously good guidance. However, will guidance solve the bigger problem of the unsuspecting click?” says Stephen Gates, chief research intelligence analyst at NSFOCUS.

“Ransomware," he says, "is not an exploit that takes advantage of a vulnerable application or operating system. Ransomware is a payload that takes advantage of vulnerable people and their clicks. Even the best guidelines can’t solve that problem.” 

HIPAA’s guidance on ransomware is here.

Kelly Jackson Higgins is the Executive Editor of Dark Reading. She is an award-winning veteran technology and business journalist with more than two decades of experience in reporting and editing for various publications, including Network Computing, Secure Enterprise ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
mtscompany
50%
50%
mtscompany,
User Rank: Apprentice
8/8/2016 | 5:50:31 AM
HIPAA
HIPAA compliant services helps healthcare experts to gain from organized services that ensure greater security and confidentiality for patient medical records.
Navigating Security in the Cloud
Diya Jolly, Chief Product Officer, Okta,  12/4/2019
US Sets $5 Million Bounty For Russian Hacker Behind Zeus Banking Thefts
Jai Vijayan, Contributing Writer,  12/5/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: Our Endpoint Protection system is a little outdated... 
Current Issue
Navigating the Deluge of Security Data
In this Tech Digest, Dark Reading shares the experiences of some top security practitioners as they navigate volumes of security data. We examine some examples of how enterprises can cull this data to find the clues they need.
Flash Poll
Rethinking Enterprise Data Defense
Rethinking Enterprise Data Defense
Frustrated with recurring intrusions and breaches, cybersecurity professionals are questioning some of the industrys conventional wisdom. Heres a look at what theyre thinking about.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-19719
PUBLISHED: 2019-12-11
Tableau Server 10.3 through 2019.4 on Windows and Linux allows XSS via the embeddedAuthRedirect page.
CVE-2019-19720
PUBLISHED: 2019-12-11
Yabasic 2.86.1 has a heap-based buffer overflow in the yylex() function in flex.c via a crafted BASIC source file.
CVE-2019-19707
PUBLISHED: 2019-12-11
On Moxa EDS-G508E, EDS-G512E, and EDS-G516E devices (with firmware through 6.0), denial of service can occur via PROFINET DCE-RPC endpoint discovery packets.
CVE-2019-19708
PUBLISHED: 2019-12-11
The VisualEditor extension through 1.34 for MediaWiki allows XSS via pasted content containing an element with a data-ve-clipboard-key attribute.
CVE-2019-19709
PUBLISHED: 2019-12-11
MediaWiki through 1.33.1 allows attackers to bypass the Title_blacklist protection mechanism by starting with an arbitrary title, establishing a non-resolvable redirect for the associated page, and using redirect=1 in the action API when editing that page.