Representatives from critical infrastructure hammered at two key differences between the House and Senate versions of the bill: the amount of time that entities would have to report a cyber incident, and the level of certainly that would need to be present before doing so.
A roundup of notable health care data breaches this week is led by a cyberattack and network outage at DuPage Medical Group that compromised the data of 600,000 patients. Beaumont Health, San Andreas Regional, and other providers reported incidents this week, as well.
Unlike the majority of cloud breaches, this one was not caused by customer misconfiguration, but rather an oversight by the provider – Microsoft Azure. Said one CISO, a fundamental shift in how software is developed requires more "accountability for configuring and automating the build process to enhance resiliency for the entire attack surface."
Critical Insight examined health care data breaches reported to HHS, finding outpatient facilities and specialists were exploited at nearly the same rate as hospitals. The biggest culprit? Cyberattacks.
Prior to the ransomware attack and subsequent EHR downtime procedures, officials confirm that threat actors stole some patient-related information from Eskenazi Health. The weekly breach roundup also includes some dubious delays in patient notifications.
In the last week, multiple ransomware incidents have spurred massive breach notices, care disruptions, and for Memorial Health, EHR downtime procedures. The health care sector should adopt a heightened state of awareness based on DHS CISA ransomware recommendations.
This week’s breach roundup is led by a two-month network hack of UNM Health, which led to the exfiltration of data tied to 637,252 patients. Memorial Health, St. Joseph’s Candler, Electromed, and other providers also recently reported security incidents tied to patient data compromise.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.