Fighting Cyber Fires: Cybersecurity Incident Response Checklist for Hospitals

Much like volunteer firefighters, healthcare entities must invest in developing, testing, and updating emergency response plans and procedures to maintain a constant state of readiness for these inevitable attacks. The good news is that the public and private sectors have been releasing industry guidance and tools at an unprecedented pace to support incident response programs for healthcare entities. There is no need for healthcare CISOs to reinvent the wheel with these standards and best practices that are applicable to all cybersecurity programs. Read More

PCI DSS v4.0 Released: Compliance Requirements for Healthcare Organizations

The PCI Security Standards Council has released the much-anticipated PCI DSS version 4.0 this week. The update is several years in the making and includes significant control requirement overhauls. Healthcare organizations must update policies, procedures, and control requirements to maintain compliance with the new PCI v4.0 standard. This blog post provides details about the new requirements for PCI v4.0 and the timing for compliance for healthcare entities. Read More

Shields Up: Russia/Ukraine Cyberwar Preparation & Response for Healthcare

Healthcare organizations are scrambling to adjust their cybersecurity preparation and response capabilities in the wake of potential cyberattacks stemming from the ongoing conflict between Russia and Ukraine. Meditology has been monitoring the situation closely and advising our healthcare clients on the latest threat vectors and response approaches. This blog post provides guidance for US-based healthcare entities for preparing and responding to cyberattacks and cyberwar tactics deployed as part of this ongoing conflict. Read More

Case Study: Ransomware Locks Up 80% of 54-Hospital Health System

The U.S. Department of Health and Human Services (HHS) recently published an insightful ‘lessons learned’ document that chronicles a large-scale ransomware attack on the Health Service Executive (HSE) of Ireland. This blog provides a summary of the ransomware event, insights from HHS, and analysis and recommendations from Meditology based on our experience with helping healthcare organizations prevent and respond to ransomware attacks. Read More

Healthcare SOC 2 FAQs

Cyberattacks against healthcare organizations and their business associate vendors have begun to threaten patient safety and fundamental business operations. As a result, SOC 2 audit reports have become one of the most common and cost-effective vehicles for healthcare organizations to demonstrate adoption of controls relevant to security, availability, confidentiality, processing integrity and privacy. We have compiled these SOC 2 frequently asked questions to support healthcare organizations and vendors supporting the healthcare ecosystem that are looking to pursue SOC 2 examinations. Read More

Urgent Alert: Log4j Java/Apache Logging Vulnerability

A far-spanning zero-day vulnerability was exposed this week for the ubiquitous open-sourced logging utility called Log4j. Meditology is actively working with our clients and the third-party vendor population to understand the extent of deployment of Log4j and the impact and risk exposure it may create for healthcare organizations. This blog provides a short summary of the Log4j vulnerability as well as recommendations for remediation and risk mitigation for organizations and their third-party vendors. Read More

HITRUST is Shaking Things Up: Details for the New HITRUST i1 Certification and bC Assessment

The demand for healthcare organizations to obtain some form of security certification is at an all-time high due to escalations in breaches across the healthcare industry and its supporting supply chain. HITRUST provides the most widely adopted security certification for healthcare entities with its flagship HITRUST CSF Validated certification. However, not all certifications are created equal, and the industry is outgrowing the one-size-fits-all certification model.  Read More