Beyond ransomware: 5 healthcare cyber risks to know

Advertisement

Recent cybersecurity warnings and incidents are highlighting risks for healthcare organizations that extend beyond ransomware, including cloud authorization abuse, voice phishing, brand impersonation, third-party access and publicly exposed information.

Here are five recent cybersecurity developments Becker’s has reported on in September:

  1. The FBI warned about “OAuth consent phishing,” which can give attackers account access without stealing a password. Attackers send links that lead victims to permission screens from legitimate cloud providers, such as Microsoft or Google. If permission is granted, a malicious application can receive access to email and other data through an authorization token. The American Hospital Association directed member hospitals to the FBI alert.

  2. Health-ISAC warned healthcare organizations about voice phishing and domain impersonation tied to ShinyHunters. The group said attackers have registered lookalike domains, impersonated internal departments such as IT help desks and pressured victims to approve multifactor authentication requests. Health-ISAC said it had sent targeted alerts to multiple health sector organizations after observing the group bypass multifactor authentication and move from single sign-on platforms into connected software-as-a-service applications.

  3. Dozens of health systems have warned patients about a phishing campaign impersonating MyChart. The messages promote a purported “MyChart Medicare Kit” or “Senior Health Package” and direct recipients to fraudulent sites. The FTC has received 166 complaints over the past five years referencing MyChart, with several related to the current campaign. The campaign does not stem from a breach of MyChart, and Epic has said the platform’s security is unaffected.

  4. EHR vendor Veradigm disclosed a cybersecurity incident involving credentials obtained from a third-party vendor’s environment. An unauthorized party used the credentials to access a Veradigm application programming interface and download personal information tied to a small number of customers, including Social Security numbers in some cases. Veradigm said no clinical or medical data was involved and the incident did not provide access to its broader network, servers or databases or disrupt operations.

  5. Nearly 50 hospitals and health systems had publicly accessible webpages that exposed clinicians’ schedules and, in some cases, cellphone numbers. The information was accessible through pages associated with workforce management platform QGenda. At least 10 hospitals and health systems removed the public links or added password requirements after being contacted by the publication. The report described publicly accessible information, not a cyberattack or breach of QGenda.

At the Becker's 11th Annual IT + Revenue Cycle Conference: The Future of AI & Digital Health, taking place September 14–17 in Chicago, healthcare executives and digital leaders from across the country will come together to explore how AI, interoperability, cybersecurity, and revenue cycle innovation are transforming care delivery, strengthening financial performance, and driving the next era of digital health. Apply for complimentary registration now.

Advertisement

Next Up in Cybersecurity

Advertisement