• Our Partners
  • CarePolicy
  • HomeCareConsulting
  • Digit9X
  • Home
  • Assisted Living
  • Elderly
  • Home Care Agency
  • Home Care Worker
  • Home Nursing
Menu
  • Home
  • Assisted Living
  • Elderly
  • Home Care Agency
  • Home Care Worker
  • Home Nursing
Home » GAO highlights HHS struggles with cybersecurity as health sector faces increased attacks
Elderly

GAO highlights HHS struggles with cybersecurity as health sector faces increased attacks

adminBy adminNovember 14, 2024No Comments5 Mins Read
Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Reddit
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link


The U.S. General Accounting Office (GAO) has identified challenges facing the Department of Health and Human Services (HHS) in meeting its cybersecurity responsibilities. Strengthening HHS leadership could be accomplished by implementing previous recommendations. Cyberattacks against the medical and public health sector have increased rapidly in recent years.

As the lead federal agency in the critical infrastructure sector, HHS is struggling with its cybersecurity responsibilities and has not yet implemented all recommendations to address these issues. These responsibilities include coordinating with the Cybersecurity and Infrastructure Security Agency (CISA), the national coordinator for critical infrastructure security and resiliency.

In February of this year, healthcare payment processing company Change Healthcare suffered a ransomware attack that resulted in data theft, losses of US$874 million, and significant disruption to healthcare providers and patient care. I did. The incident highlights the difficulty HHS has in managing the department's cybersecurity. The Department has not yet implemented all recommended measures to address these issues.

HHS has launched an initiative to reduce the risk of ransomware in healthcare and public health. However, GAO's previous findings indicate that the GAO division does not effectively monitor the implementation of these practices. In January of this year, GAO reported that HHS released an analysis of U.S. hospital cybersecurity. The analysis revealed that participating hospitals self-reported adopting 70.7 percent of the key areas of the NIST Cybersecurity Framework: Identify, Detect, Protect, Respond, and Recover.

“However, at the time of our report, HHS had not yet tracked the adoption of the ransomware-specific practices outlined in the framework,” GAO said. “Although HHS officials told us they would be able to assess implementation of key concepts within the framework, the department provided no evidence of efforts to do so. Adoption of Cybersecurity Practices in the Department Without sufficient awareness, HHS risks not putting resources where they need to be.”

GAO recommended that HHS work with CISA and departmental bodies to determine whether the department will adopt advanced cybersecurity practices to help reduce the risk of ransomware.

The watchdog also found that HHS did not assess the effectiveness of the assistance it provided to this area. Specifically, GAO reported that HHS provided various types of support to assist ransomware risk management departments, including guidance documents, training, job assistance, and threat briefings. However, the Department has not demonstrated that it has evaluated which types of support are most effective. As a result, the department was unable to fully address concerns regarding communication, coordination, and timely sharing of threat and incident information.

GAO proposed that HHS work with CISA and sectoral bodies to develop evaluation procedures to measure the effectiveness of support in mitigating ransomware risk.

Regarding assessing the sector's cybersecurity risks, GAO's report notes that apart from IT, the healthcare sector also uses Internet of Things (IoT) and operational technology (OT) devices to provide essential healthcare and public health services. He pointed out that it depends on the system. In December 2022, we reported that HHS continues to conduct risk activities against a specific type of IoT device: medical devices. “It did not conduct a full cybersecurity risk assessment. As a result, the Department did not know what additional security protections were needed to address growing and evolving threats,” GAO said. I pointed it out.

GAO suggested that HHS include IoT and OT devices as part of the department's cyber environment risk assessment.

Regarding departmental cybersecurity coordination and collaboration, GAO assessed that within HHS, the Office of Strategic Preparedness and Response (ASPR) is responsible for leading collaborative efforts to strengthen departmental security and resiliency. “In June 2021, we reported that ASPR is leading or co-leading several working groups focused on supporting this sector. We determined that it demonstrated collaborative practices.”

However, they did not fully or consistently monitor the work group's progress toward achieving defined goals. Regularly update a charter that clarifies responsibilities for carrying out the group's role or describes how the work group will work together. As a result, ASPR could not ensure that we were working together effectively to improve cybersecurity. GAO recommended that ASPR take steps to fully and consistently demonstrate key collaboration practices.

“Until HHS implements its previous recommendations to improve cybersecurity, the Department will not be able to effectively carry out its lead agency responsibilities, resulting in negative health care provider and patient care,” GAO said in its conclusion. There is a possibility.”

In May, GAO added “priority recommendations” to the Environmental Protection Agency (EPA), bringing the total to 12. The recommendations include five areas. Address data and risk communication issues related to drinking water and wastewater infrastructure. EPA works to manage climate risks, protect the nation's air quality, and ensure cybersecurity.

Prior to that, in March, the agency conducted a review of CISA's 13 OT (operational technology) cybersecurity products and services. The review found that while 12 of the 13 non-federal agencies reported positive experiences with CISA's services, it also highlighted challenges with CISA and seven of the agencies.

Anna Ribeiro

Industrial Cyber ​​News Editor. Anna Ribeiro is a freelance journalist with over 14 years of experience in security, data storage, virtualization, and IoT.



Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
admin
  • Website

Related Posts

Two patients faced chemotherapy. Survivors were tested to see if it was safe.

May 21, 2025

Is nutritional taurine really key to healthy aging?

May 21, 2025

Supplements that are wary of severe drug-induced liver injuries in the United States

May 21, 2025
Leave A Reply Cancel Reply

Top Posts

Investment company KKR offloads 16.1m bright stocks in secondary faring

June 10, 2025

How To Unlock A Windows PC Without The Password?

January 14, 2021
7.2

Best Chanel Perfume of 2024 – Top Chanel Fragrance Worth Buying

January 15, 2021

Is It Safe to Use an Old or Used Phone? Report Card

January 14, 2021
Don't Miss

Nurses must have ‘voice’ in pandemic preparedness

By adminJune 10, 2025

Nurses must be involved in pandemic preparedness in all countries across the world, a global…

Nursing associate students excluded from NHS support fund

June 10, 2025

RCN chief ‘ashamed’ by UK international recruitment practices

June 10, 2025

Exclusive: Demand for national action on preceptorship gaps

June 10, 2025

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

About Us
About Us

Welcome to HomeCareNews.us, your trusted source for comprehensive information on home healthcare services. Our mission is to empower individuals and families by providing accurate, up-to-date, and insightful information about essential home care services in USA.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

Investment company KKR offloads 16.1m bright stocks in secondary faring

June 10, 2025

Enhabit advances home health strategy through episode contracts, expanded payer mix

June 10, 2025

Nurses must have ‘voice’ in pandemic preparedness

June 10, 2025
Most Popular

Investment company KKR offloads 16.1m bright stocks in secondary faring

June 10, 2025

How To Unlock A Windows PC Without The Password?

January 14, 2021
7.2

Best Chanel Perfume of 2024 – Top Chanel Fragrance Worth Buying

January 15, 2021
  • Home
  • About Us
  • Advertise with Us
  • Contact us
  • DMCA Policy
  • Privacy Policy
  • Terms & Conditions
© 2025 HomecareNews.US

Type above and press Enter to search. Press Esc to cancel.