The U.S. Department of Human Services has released new guidance for health care organizations that focuses on the growing threat of ransomware, stresses the need for better education and regular backups, and confirms that a ransomware attack against plain-text health information is, in fact, a breach that must be disclosed.
The guidance recommends that organizations identify the risks facing their patient information, create a plan to address those links, set up procedures to protect systems from malware, train users to spot malware, limit access to sensitive information to just the people who need it most, and have a disaster recovery plan that includes frequent data backups.
To read this article in full or to leave a comment, please click here