The AHA June 6 participated in a Wall Street Journal Tech Live Cybersecurity event to discuss the historic Feb. 21 cyberattack on Change Healthcare. Stacey Hughes, AHA executive vice president of government relations and public policy, spoke about the impact on hospitals and health systems, the government response to the attack, how UnitedHealth Group’s size was a factor in the incident and what’s next in federal cybersecurity policy in a discussion with Erik Decker, vice president and chief information security officer for Intermountain Health, and WSJ Reporter James Rundle. 

When asked about the response of government, Hughes said, “It took a while for some people to recognize the severity of this incident. One of the reasons for that was because there was a significant minimization of the impact from UnitedHealth Group early on. That minimization led policymakers to not react as quickly. There is room for improvement in how our government responded and in understanding how government steps in and what they can do when something like this happens.” 

Last week, the Department of Health and Human Services announced that hospitals and health systems could require UHG to notify patients if their data was stolen during the cyberattack.

Headline
Microsoft Threat Intelligence is warning of a large scale, multistage phishing campaign that disproportionately targeted the health care sector, sending “code…
Headline
The Cybersecurity and Infrastructure Security Agency has launched a new initiative for critical infrastructure to defend against cyberattacks through proactive…
Headline
John Riggi, AHA national advisor for cybersecurity and risk, will moderate a webinar May 5 at 1 p.m. ET that will explore how bad actors are leveraging…
Headline
The AHA and Joint Commission May 4 announced the launch of the Cyber Resilience Readiness program, an initiative to help hospitals and health systems assess…
Headline
The Cybersecurity and Infrastructure Security Agency, National Security Agency and international partners have released guidance on adopting agentic artificial…
Headline
A joint advisory released April 23 from U.S. and international cybersecurity agencies, including the Cybersecurity and Infrastructure Security Agency, FBI,…