Cybersecurity

Cyber Threat Intelligence, Alerts and Reports

As part of the AHA’s commitment to helping hospitals and health systems prepare for and prevent cyber threats, we have gathered the latest government cyber threat intelligence and alerts and Health Information Sharing and Analysis Center (H-ISAC) reports.

You may be asked to enter your AHA member credentials to view certain reports and intelligence alerts.

Cybersecurity & Risk Advisory

Learn how AHA can help hospitals and health systems prepare for and mitigate cyber threats through the expertise of John Riggi, AHA’s National Advisor for Cybersecurity and Risk.

Learn More

This joint Cybersecurity Advisory (CSA)—authored by the Cybersecurity and Infrastructure Security Agency (CISA), Federal Bureau of Investigation (FBI), and National Security Agency (NSA)—provides an overview of Russian state-sponsored cyber operations; commonly observed tactics, techniques, and…
H-ISAC TLP Green Ransomware Data Leak Sites Report, Dec. 16, 2021
H-ISAC TLP Green Daily Cyber Headlines, December 16, 2021
This week, Hacking Healthcare begins by breaking down the issue of cyber incident reporting timelines and makes the case for engagement with regulators and legislators.
Health-ISAC and Microsoft have partnered together to deliver a new medium to discuss notable vulnerabilities patched in the recent Patch Tuesday update.
Today’s Headlines: Leading Story Microsoft December 2021 Patch Tuesday Fixes 6 Zero-Days, 67 Flaws Data Breaches & Data Leaks Nothing to Report Cyber Crimes & Incidents Cyberattack on BHG Opioid Treatment Network Disrupts Patient Care Vulnerabilities & Exploits
A valued colleague is providing this daily ransomware tracker as TLP:GREEN  for purposes of increasing ransomware threat awareness. The body of the email contains newly added victims since the last update.
Apache has released a security update to address a second severe vulnerability affecting its Log4j software library, which a remote attacker could exploit to cause a denial-of-service condition, the Cybersecurity and Infrastructure Security Agency announced.
In this podcast, John Riggi, highly decorated veteran of the FBI and Senior Advisor for Cybersecurity and Risk at the American Hospital Association talks to two leading experts and colleagues in the field of cybersecurity from the Cybersecurity and Infrastructure Agency (CISA) / U.S. Department of…
The Cybersecurity and Infrastructure Security Agency has created a webpage to provide the latest public information and vendor-supplied advisories on a critical remote code execution vulnerability affecting Apache Log4j software library versions 2.0-beta9 to 2.14.1.