News: 1704918734

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Uncle Sam tells hospitals: Meet security standards or no federal dollars for you

(2024/01/10)


US hospitals will be required to meet basic cybersecurity standards before receiving federal funding, according to rules the White House is expected to propose in the next few weeks.

This comes as hospitals and health clinics nationwide continue to be menaced by ransomware, and cybercrims resort to [1]diabolical tactics to make victims pay up.

The Centers for Medicare and Medicaid Services (CMS), an arm of the US Department of Health and Human Services, is reportedly drawing up rules connecting hospital IT security with funding, which are set to take effect before the end of the year.

[2]

Citing an unnamed government official, this [3]Messenger report says the proposed rules will focus on "those key cybersecurity practices that we really do believe bring a meaningful impact." And federal funding will hinge on hospitals enacting these basic network defenses.

[4]

[5]

When asked about the draft rules, a CMS spokesperson directed The Register to a concept paper published in December that outlines the Department of Health and Human Services' (HHS) cybersecurity strategy.

According to the HHS paper

[6]PDF

, officials will propose new, enforceable security standards, and will work with Congress to administer financial support and incentives for hospitals to implement "high-impact cybersecurity practices," among other actions.

[7]

"One of the key action areas is increasing accountability and coordination within the health care sector," the spokesperson told The Register . "CMS values feedback from stakeholders and continues to consider how to improve cybersecurity most effectively across the health care sector. CMS does not comment on the substance of policies before they are proposed."

[8]After injecting cancer hospital with ransomware, crims threaten to swat patients

[9]Cancer patient sues hospital after ransomware gang leaks her nude medical photos

[10]Ransomware gang threatens 1m-plus medical record leak

[11]Ransomware payment ban: Wrong idea at the wrong time

Last year alone, at least [12]46 US hospital corporations with a total of 141 facilities between them were hit by ransomware infections, and at least 32 of these networks had protected health information and other patient data stolen during the intrusions, according to Emsisoft.

For comparison: There were 25 of these affected hospital systems in 2022, the infosec biz says.

In addition to stealing hospitals' data, criminals are also using increasingly nasty extortion tactics to put pressure on health care execs to pay ransoms. This includes emailing patients directly and threatening to sell their health records, [13]leaking breast cancer patients' nudes, and even [14]threatening to swat hospital patients.

And while no one is going to argue against improving hospitals' security posture, cutting off their funding may not help the situation, according to some.

[15]

"Denying funding to hospitals doesn't seem like the best way to help them improve their security," Emsisoft Threat Analyst Brett Callow told The Register . "In fact, it may do the exact opposite."

The Register 's journalists [16]debated the issue in this week's Kettle recording. ®

Get our [17]Tech Resources



[1] https://www.theregister.com/2024/01/05/swatting_extorion_tactics/

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZZ8hl2W47fMNOW@9pnQUQQAAAAI&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://themessenger.com/tech/hospital-cybersecurity-rules-hhs-hackers-white-house

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZZ8hl2W47fMNOW@9pnQUQQAAAAI&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZZ8hl2W47fMNOW@9pnQUQQAAAAI&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[6] https://aspr.hhs.gov/cyber/Documents/Health-Care-Sector-Cybersecurity-Dec2023-508.pdf

[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZZ8hl2W47fMNOW@9pnQUQQAAAAI&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[8] https://www.theregister.com/2024/01/05/swatting_extorion_tactics/

[9] https://www.theregister.com/2023/03/15/cancer_lvhn_sues_hospital/

[10] https://www.theregister.com/2022/09/14/ransomware_medical_groups/

[11] https://www.theregister.com/2024/01/06/ransomware_payment_ban_wrong_idea/

[12] https://www.theregister.com/2024/01/03/ban_ransomware_payments/

[13] https://www.theregister.com/2023/03/15/cancer_lvhn_sues_hospital

[14] https://www.theregister.com/2024/01/05/swatting_extorion_tactics/

[15] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZZ8hl2W47fMNOW@9pnQUQQAAAAI&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[16] https://www.theregister.com/2024/01/10/ransomware_kettle/

[17] https://whitepapers.theregister.com/



They knew what they were getting into. I say let them crash!

Throatwarbler Mangrove

"Denying funding to hospitals doesn't seem like the best way to help them improve their security," Emsisoft Threat Analyst Brett Callow told The Register. "In fact, it may do the exact opposite."

Yeah, well, fuck 'em. It's not like they're providing a vital public service during a pandemic and at a time when many medical professionals are actively leaving the field due to over-work. Hospitals are already overfunded and corrupt, and they're just under-spending on IT out of sheer incompetence and penuriousness. If they can't solve their IT problems immediately, then their patients deserve to die!

(Sadly, the arguments above, made here in the spirit of reductio ad absurdum have been made in apparent sincerity by more than one commentard.)

Re: They knew what they were getting into. I say let them crash!

Sora2566

I dunno... making their funding conditional on basic best practice does feel like the only way to convince some boards that yes, they *do* in fact need to take action.

You may be right, I may be crazy,
But it just may be a lunatic you're looking for!
-- Billy Joel