Preparing for HIPAA security updates
At the recent joint HHS and National Institute of Standards and Technology security conference, HHS OCR senior advisor for health information...
The U.S. Department of Health and Human Services’ Office for Civil Rights has published a video to help healthcare organizations prevent ransomware attacks by adhering to HIPAA Security Rule standards and improving cybersecurity practices.
The U.S. Department of Health and Human Services’ Office for Civil Rights (OCR) has released a video guiding HIPAA-regulated entities on ransomware prevention and compliance with the HIPAA Security Rule. The video, published as part of National Cybersecurity Awareness Month, seeks to raise awareness about ransomware threats and emphasize how adhering to HIPAA’s security provisions can significantly help mitigate the risks and impact of such attacks.
See also: HIPAA Compliant Email: The Definitive Guide
Ransomware attacks have surged dramatically in recent years. According to Nick Heesters, OCR’s senior advisor for cybersecurity, there has been a 102% increase in ransomware incidents targeting HIPAA-regulated entities from 2019 to 2023. OCR has identified numerous trends related to these attacks, partly through its investigations into large data breaches:
Access control failures: Weak access controls combined with poor authentication can lead to breaches. Common issues include excessive admin privileges and weak authentication practices.
Read also: Access control systems in healthcare for comprehensive security
Read also: Cybersecurity insights and trends for 2024
The release of this guidance by the U.S. Department of Health and Human Services' Office for Civil Rights (OCR) acts as a measure to help HIPAA-regulated entities understand the growing threat of ransomware and demonstrate how compliance with the HIPAA Security Rule can mitigate risks.
With ransomware attacks increasing dramatically in the healthcare sector, this guidance educates organizations on preventing, detecting, and responding to attacks, emphasizing the need for strong cybersecurity measures to protect patient data and avoid breaches that could lead to financial penalties and reputational damage.
Ransomware is a type of malicious software that encrypts an organization’s data, making it inaccessible until a ransom is paid to the attackers. It often targets critical systems, such as those in healthcare, to cause disruption and extract payments.
Healthcare organizations store sensitive patient information, making them attractive targets for ransomware attacks. A successful attack can lead to operational disruptions, data breaches, and significant financial and reputational harm.
The Health Insurance Portability and Accountability Act (HIPAA) is a U.S. law that sets national standards for the protection of sensitive patient information, specifically addressing how healthcare entities must secure health data.
Go deeper: What is HIPAA?
At the recent joint HHS and National Institute of Standards and Technology security conference, HHS OCR senior advisor for health information...
The healthcare industry is more digitally connected than ever, handling vast amounts of sensitive patient data while relying on complex systems to...
The U.S. Department of Health and Human Services has reached a $350,000 settlement with Northeast Radiology over HIPAA Security Rule violations...