The Department of Health and Human Services recently released an advisory to help health care organizations protect their systems and networks from 8Base, a ransomware and data extortion gang targeting small- and medium-sized organizations in health care and other sectors. Recommendations include prioritizing cybersecurity best practices, from regularly updating and patching systems to educating employees to avoid and report phishing emails and malicious attachments. 
  
鈥淭his emerging ransomware group appears primarily focused on data extortion rather than data encryption at this point,鈥 said John Riggi, AHA鈥檚 national advisor for cybersecurity and risk. 鈥淭heir rapid rise and large number of attacks indicates this group may be a rebranding of a former group or contain elements of a former ransomware group. I have observed a general trend in which ransomware attackers claim to be 鈥榩enetration testers鈥 performing a 鈥榮ervice鈥 and discussion of 鈥榲ulnerability reports鈥 for the victim, raising the possibility that these hackers may be affiliated with 鈥榣egitimate鈥 cybersecurity firms in non-cooperative foreign jurisdictions or have formal cybersecurity training. These data extortion attacks highlight the need to ensure that protected health information (PHI) within our networks, especially PHI outside the electronic medical record, is fully mapped and encrypted at rest and in transit.鈥 
  
For more information on this or other cyber and risk issues, contact Riggi at鈥. For the latest cyber and risk resources and threat intelligence, visit鈥. 

Related News Articles

Headline
The National Security Agency April 23 released a report on operational technology systems that includes recommendations for security policies and technical鈥
Chairperson's File
Public
Cybersecurity and physical threats are unfortunately significant enterprise risks for health care, regardless of size or location. Every hospital, physician鈥
Headline
The Cybersecurity and Infrastructure Security Agency April 17 released guidance to reduce risks associated with a reported breach of Oracle cloud services.鈥
Headline
The National Counterintelligence and Security Center, the FBI, and the Defense Counterintelligence and Security Center yesterday released guidance on鈥
AHA Cyber Intel
While the rate of cyberattacks on hospitals has risen dramatically, the severity of the impacts has also grown exponentially. Let鈥檚 look at the state of cyber鈥
Headline
The House Energy and Commerce Oversight and Investigations Subcommittee April 1 discussed cybersecurity threats in legacy medical devices during a hearing. The鈥