HHS warns of healthcare cyberattack risk tied to Log4j vulnerability

The HHS Cybersecurity Program has issued a letter warning of a software vulnerability that puts healthcare providers across the country at risk of a cyberattack.

Advertisement

The letter, sent Dec. 10, warns of a vulnerability in Log4j, a highly utilized piece of open-source code. HHS said hackers’ exploitation of the vulnerability can lead to data exfiltration and ransomware.

The Cybersecurity and Infrastructure Security Agency, the operational lead for federal cybersecurity, created a webpage and GitHub repository to provide up-to-date information and advisories on the vulnerability. 

HHS and CISA recommend healthcare organizations upgrade to Log4j version 12.15.0, a version released Dec. 10, to address the vulnerability. 

At the Becker's 11th Annual IT + Revenue Cycle Conference: The Future of AI & Digital Health, taking place September 14–17 in Chicago, healthcare executives and digital leaders from across the country will come together to explore how AI, interoperability, cybersecurity, and revenue cycle innovation are transforming care delivery, strengthening financial performance, and driving the next era of digital health. Apply for complimentary registration now.

Register to Attend Webinar

The hidden cost of lost clinical time and how leading health systems are responding

Friday, August 7
12:00 PM - 1:00 PM CDT

Presenters: Kassaundra McKnight-Young, Zebra TechnologiesGregory Carras, Zebra TechnologiesJennifer Gene, Levata

Advertisement

Next Up in Cybersecurity

Advertisement

Comments are closed.