The audit found HHS continues to implement changes to improve its information security program. The audit also identified opportunities for HHS to strengthen its security program.
Currently, HHS is inching toward implementing a department-wide continuous diagnostics and mitigation program with the Department of Homeland Security, which the auditor predicts will improve HHS’ information security maturity.
Weaknesses were found in the agency’s risk management, configuration management, identity and access management, data protections and privacy, security training, information security continuous monitoring, incident response, and contingency planning.
More articles about cybersecurity:
EmCare says February email breach exposed some patient, contractor and employee data
Maine hospital breaches HIPAA by emailing the names of 300 patients taking Suboxone to newspaper
Scammers pay for DNA swabs, health insurance information to defraud CMS
At the Becker's 11th Annual IT + Revenue Cycle Conference: The Future of AI & Digital Health, taking place September 14–17 in Chicago, healthcare executives and digital leaders from across the country will come together to explore how AI, interoperability, cybersecurity, and revenue cycle innovation are transforming care delivery, strengthening financial performance, and driving the next era of digital health. Apply for complimentary registration now.