HHS Alerts Health Sector to Monkeypox-Themed Phishing Campaign – HomeCare

WASHINGTON, D.C. (September 27, 2022)The Department of Health and Human Services (HHS) Health Sector Cybersecurity Coordination Center (HC3) has alerted the health care industry to a monkeypox-themed phishing campaign targeting health care providers, including home health agencies. Health care companies that fail to adequately protect their patient's private health information and violate the Health Insurance Portability and Accountability Act (HIPAA) could face fines from the Office of Civil Rights and/or prosecution from their state attorney general's office.

In the alert, HC3 said the phishing attempt carried a subject ofData from (Victim Organization Abbreviation): "Important read about -Monkey Pox (Victim Organization) (Reference Number)." If someone tries to download the attached pdf, it launches a program that tries to harvestOutlook, O365 or other mail credentials.

The alert recommends organizations implement certain protective actions such as:

This alert reminds us that our cyber adversaries, foreign-based criminal gangs and hostile nation-state intelligence services, continue to prey on our culture of care by sending phishing emails based upon current urgent health care issues, said John Riggi, the American Hospital Associations national advisor for cybersecurity and risk. These insidious emails targeting well-intentioned health care workers lure the recipients to click on malicious links, download malware and provide credentials, ultimately leading to the theft of patient data or hospital funds.

Last week, the FBI issued an alert identifying a scheme in which stolen employee credentials were being used to divert and steal millions of dollars in hospital funds, Riggi continued. In this multi-faceted and complex cyber threat environment, multi-factor authentication, phishing tests and verbal authentication for payment instruction changes are essential.

Read more about protecting your business from cyber threats here.

See the original post:

HHS Alerts Health Sector to Monkeypox-Themed Phishing Campaign - HomeCare

Related Posts
Tags: