News

Sen. Peters presses federal agencies to increase cybersecurity for American health care

Citing cases where cyberattacks targeted health care systems in the United States, U.S. Sen. Gary Peters (D-MI) recently wrote to the Department of Health and Human Services (HHS) and the Cybersecurity and Infrastructure Security Agency (CISA) requesting cybersecurity boosts for the sector.

“The recent cyberattack on a UnitedHealth Group subsidiary, Change Healthcare, has disrupted their ability to process medical claims, impacting millions of Americans trying to fill their prescriptions and access health care services,” Peters wrote. “HHS should heavily encourage health care entities impacted by the attack to take advantage of available technical and financial resources and assistance from CISA, CMS, and other organizations.”

A ransomware attack struck Change Healthcare on Feb. 21, 2024, disrupting operations as the organization shut down many of its systems in response. This led to an inability to care for patients, as well as patients being billed for previously covered medication and millions unable to acquire refills.

This is far from the first push for greater cybersecurity in the health care sector that Peters has undertaken as chair of the Homeland Security and Governmental Affairs Committee. Last year, he convened a hearing on this very threat. His Cyber Incident Reporting Act – developed in concert with U.S. Sen. Rob Portman (R-OH) – became law in 2022, requiring critical infrastructure owners and operators to report substantial cyberattacks or ransomware payments.

Now, he wants to see the government take more initiative as well.

“Public outreach and engagement are an important part of increasing cybersecurity across the health care sector,” Peters said. “CISA and HHS in coordination should conduct a campaign to engage and inform health care entities and the public of cybersecurity best practices and resources available to them.”

He requested that HHS and CISA detail their steps to prevent another cyber incident, the nature of how they measure and implement sector-specific cybersecurity performance goals, the assistance offered to impacted entities, information sharing, methods of coordination and more. Without rapid measurable improvements in cybersecurity for the health care sector, Peters added, incidents like the one that hit Change Healthcare will continue to affect patient outcomes and result in significant financial, administrative and logistical issues.

Chris Galford

Recent Posts

Embattled TikTok in jeopardy as President Biden signs legislative ban

The ByteDance-owned TikTok faces an uphill battle in the United States after President Joe Biden…

19 hours ago

Raytheon begins $115M expansion of Alabama missile integration facility

Promising to grow space for integrating and delivering on critical defense programs by more than…

19 hours ago

Reward offered for Iranian nationals charged over multi-year cyber campaign against U.S. companies

In unsealing a 13-page indictment this week, the U.S. Department of Justice (DOJ) revealed charges…

2 days ago

FEND OFF Fentanyl Act included in national security supplemental

A bill targeting the illicit fentanyl supply chain, the Fentanyl Eradication and Narcotics Deterrence (FEND)…

2 days ago

Pennsylvania earns $10M federal grant to improve crime statistics reporting

In order to move the state closer to federal standards and allow reporting of local…

3 days ago

DoD innovative technologies pilot funds 13 additional projects

For the next round of participants in a pilot program to Accelerate the Procurement and…

3 days ago

This website uses cookies.