US cybersecurity agency releases guidance for healthcare, public health orgs

US cybersecurity agency releases guidance for healthcare, public health orgs

The US Cybersecurity and Infrastructure Security Agency (CISA) has released a security guidance for organizations in the healthcare and public health sectors, which is a supplemental companion to the HPH Cyber Risk Summary, published July 19, 2023.

The guide provides defensive mitigation strategy recommendations and best practices to defend against cyber threats affecting the healthcare sector. It also identifies known vulnerabilities for organizations to assess their networks and minimize risks before intrusions occur.

The document emphasizes the importance for organizations to conduct regular vulnerability scans, prioritize assets based on criticality and leverage threat intelligence to address actively exploited vulnerabilities.

CISA also strongly encourages HPH entities to use the threat intelligence information mentioned in the mitigation guide to effectively address and remediate their vulnerability exposure, and to protect their organizations from potential ransomware attacks, data breaches, loss or theft of equipment or data, and attacks against network-connected medical devices.


Back to the list

Latest Posts

Kosovo man extradited to US for running BlackDB.cc criminal marketplace

Kosovo man extradited to US for running BlackDB.cc criminal marketplace

If convicted on all counts, Masurica faces up to 55 years in federal prison.
14 May 2025
Multiple actively exploited zero-days patched in Microsoft, Ivanti, and Fortinet products

Multiple actively exploited zero-days patched in Microsoft, Ivanti, and Fortinet products

Microsoft shipped patches for over 70 flaws, five of which have been flagged as actively exploited zero-day bugs.
14 May 2025
Chinese hackers exploit SAP NetWeaver in cyber campaigns targeting critical infrastructure

Chinese hackers exploit SAP NetWeaver in cyber campaigns targeting critical infrastructure

The flaw was exploited to gain access to enterprise systems globally.
14 May 2025