Cybersecurity Policy Report, SENATE NEWS: Senate Finance Committee chair urges HHS to ‘take immediate, enforceable steps’ on health cybersecurity, (Jun 6, 2024)
Organizations Mentioned:Change Healthcare | UnitedHealth Group
By Sheila Lynch-Afryl, J.D., M.A.
Senate Finance Committee Chair Ron Wyden (D-Ore.) said that HHS’ current approach of “allowing the health sector to self-regulate cybersecurity” is insufficient.
In the wake of the Change Healthcare cyberattack, Senate Finance Committee Chair Ron Wyden (D-Ore.) criticized HHS’ current approach to health care cybersecurity—which he described as self-regulation and voluntary best practices—as “woefully inadequate,” leaving the health care system “vulnerable to criminals and foreign government hackers.” He took particular issue with the fact that HHS does not require health care organizations to use multi-factor authentication, a “basic cybersecurity defense” required by other industries. He urged HHS to mandate minimum technical cybersecurity standards and resiliency requirements for “systemically important entities.”
At a May 1 Senate Finance Committee hearing, Andrew Witty, CEO of UnitedHealth Group (UHG), testified that the compromised Change Healthcare Citrix portal did not have multi-factor authentication. He said that UHG’s policy is to have multi-factor authentication for externally facing systems, but when it acquired Change 1.5 years ago it had older technology that UHG was in the process of upgrading. In his letter, Wyden argued that the Change ransomware attack could have been prevented with the use of multi-factor authentication.
Wyden recommended that HHS:
require minimum, mandatory technical cybersecurity standards for systemically important entities like large health systems, including as a condition of participation in Medicare;
require systemically important entities to meet resiliency requirements such that they are able to rebuild their information technology infrastructure from scratch and within 48 to 72 hours;
conduct periodic cybersecurity audits of covered entities and business associates as part of the audits required by section 13411 of the HITECH Act, prioritizing audits of systemically important entities; and
provide technical assistance on cybersecurity to health care providers, such as through quality improvement organizations and the Medicare Learning Network.
On May 30 Wyden also requested that the Federal Trade Commission and the Securities and Exchange Commission investigate UHG for its cybersecurity lapses, including its failure to use multi-factor authentication.
HHS has recently increased its scrutiny of cybersecurity issues. For example, earlier this year HHS established voluntary cybersecurity performance goals and indicated that CMS will propose new cybersecurity requirements for hospitals through Medicare and Medicaid. It has also worked to update the HIPAA Security Rule to include cybersecurity requirements.
Companies: UnitedHealth Group; Change Healthcare
IndustryNews: NewsStory SenateNews ComplianceNews BillingNews CMSNews EHRNews HIPAANews HITNews IPPSNews QualityNews CyberPrivacyFeed LegislativeRegulatoryActivity DataPrivacy DataSecurity