The FBI and the Cybersecurity and Infrastructure Security Agency have released a fact sheet for critical infrastructure organizations on ways to reduce risk and minimize vulnerabilities when working with third-party hardware and software networks designed to monitor and automate physical processes for control systems and devices, such as pumps, sensors and industrial computers for operating essential equipment.
Cybersecurity News
Latest
The AHA will host a webinar Sept. 30 at 1 p.m. ET on ways healthcare organizations can build an effective, closed-loop cybersecurity program designed specifically for medical device environments.
New guidance from the Cybersecurity and Infrastructure Security Agency encourages healthcare organizations to consider internal network and internet facing cyber decoys [cisa.gov] as a practical way to strengthen cyber defenses and improve early threat detection.
The National Institute of Standards and Technology and the Cybersecurity and Infrastructure and Security Agency have released guidelines to protect authentication tools including access tokens and identity assertions from cyber criminals.
The House Energy and Commerce Subcommittee on Health held a hearing Sept. 15 to discuss more than a dozen legislative proposals regarding Medicare provider payment and healthcare cybersecurity.
The National Security Agency has released a best practices guide on effective cyber hygiene for defending against advanced cyber threats, including those leveraging artificial intelligence for exploitation.
An FBI alert released Sept.
In this conversation, John Riggi, AHA national advisor for cybersecurity and risk, and Scott Gee, AHA deputy national advisor for cybersecurity and risk, break down the three biggest cyber threats facing healthcare organizations in 2026: geopolitical cyber activity, third-party and supply chain vulnerabilities, and the rapidly evolving risks of artificial intelligence.
Boston Scientific announced Sept. 8 that the network disruption to its remote monitoring services following an Aug. 25 cyber incident has been resolved.
The FBI and the Department of Justice Aug. 26 announced the disruption of a China-linked hacking group known as QTFY. The group, which also identifies as QT and QTCYBER, has targeted hospitals and health systems, as well as government services and facilities, communications, energy, information technology, and water and wastewater systems.
Boston Scientific, a large supplier of medical devices, said in an Aug. 26 statement posted on its website that on Aug. 25 it “identified a cybersecurity incident affecting certain information technology systems that resulted in a network outage and disruption to the company’s operations.”
Epic’s MyChart has shared examples from potential phishing schemes observed as recently this month that include email messages linking to a fake MyChart website displaying erroneous medical records and others notifying of a free “2026 Medicare Health Kit.”
The National Security Agency and other federal agencies released a joint advisory Aug. 18 warning of active cyber threats to Siemens S7 Series programmable logic controllers, which are industrial computers used to monitor essential equipment.
A joint advisory released Aug. 19 by the FBI, Cybersecurity and Infrastructure Security Agency, and the Department of Health and Human Services provides updates on activity by Medusa, a foreign ransomware-as-a-service variant first identified in 2021.
The Department of Health and Human Services Aug. 14 released a request for comments through the Office of the National Coordinator for Health IT on a proposed three-year generic clearance to collect routine customer feedback on service delivery and performance related to the Trusted Exchange Framework and Common Agreement.
Cyberattacks against healthcare continue to grow in frequency, sophistication and impact. They have increased their targeting of healthcare third-party vendors, conducted ransomware attacks and led data-theft extortion campaigns.
U.S. and international agencies released a joint cybersecurity advisory Aug. 10 warning of actions by Gunra ransomware.
The Cybersecurity and Infrastructure Security Agency and other U.S. and international agencies July 29 released joint guidance outlining minimum elements for a “software bill of materials” for organizations to better understand and improve their cybersecurity efforts.
John Riggi, AHA national advisor for cybersecurity and risk, shares insights from a conversation with two FBI leaders about the surge of cyberattacks on the U.S.
What can we learn from the FBI about the surge of cyberattacks on U.S. healthcare and its recommended top 10 defensive best practices? Learn more.