Skip to main content

News

By Jeff Lagasse | 04:20 pm | October 15, 2018
CarePort customers can now receive automated medical reviews sent straight to their Care Management workflow, thereby reducing administrative burden.
By Tom Sullivan | 02:54 pm | October 15, 2018
Experts at the HIMSS Healthcare Security Forum said the next phase of infosec should be to secure the human and put safety nets in place to protect them.
By Jessica Davis | 05:56 pm | October 12, 2018
The Food and Drug Administration issued a cybersecurity alert on two Medtronic devices that could allow a hacker to hijack the software update process to change the device’s function. Medtronic disabled the online software update to eliminate the flaw. IMPACT Following a review of potential security vulnerabilities around the internet connection, the FDA found 34,000 CareLink cardiac implantable electronic devices are at risk. If exploited, a hacker could change the programmer’s functionality or the device itself during the implantation or follow-up visits. The flaw is found in the internet connection between the CareLink 2090 and Encore 29901 Programmers, used for downloading software from Medtronic’s Software Distribution Network. The programmers are used by providers to adjust the cardiac device settings and collect locally stored data. While software updates typically include new software for the programmer functionality and updates to the implanted device firmware through a virtual private network, the programmers don’t verify they’re still connect to the VPN before downloading the updates. As a result, attempting to update the program through the internet connection will result in an error message. Medtronic updated its network, which was approved by the FDA on Oct. 5. The fix will intentionally block the currently existing programmer from accessing the Medtronic SDN. The vendor is continuing to implement security updates to further address the flaw. The FDA recommends providers continue to use the programmers, as network connectivity isn’t required for normal CIEF programming. Further, providers should not attempt to update the programmer through the SDN, which is no longer available. Future updates are currently only available through Medtronic with a USB update. THE TREND Medical device vulnerabilities are well-known, and vulnerability reporting by vendors have increased 400 percent per quarter since the FDA released its cybersecurity guidance in 2016. However, the increase in FDA alerts is meant to further improve cybersecurity, rather than to shame the vendor. Medtronic has reported several vulnerabilities in recent years, as has Philips, Abbott and a host of others. .jumbotron{ background-image: url("http://www.healthcareitnews.com/sites/default/files/u2231/cybersecurity-jumbotron-712.jpg"); background-size: cover; color: white; } .jumbotron h2{ color: white; } Focus on Cybersecurity In October, we take a deep dive into security strategy and pressing threats. Twitter: @JF_Davis_ Email the writer: jessica.davis@himssmedia.com
By Bill Siwicki | 03:19 pm | October 12, 2018
This case study shows how UPMC Magee-Womens Hospital accomplished that reduction by sending new mothers home with a free blood pressure cuff and access to a remote monitoring portal.
By Jessica Davis | 03:14 pm | October 12, 2018
For more than a month, two separate employee accounts were compromised by the cyberattacks before the IT department discovered the hack.
By Tom Sullivan | 11:49 am | October 12, 2018
Technology was critical but so, too, were the personal and patient-centric stories shared on Twitter this week.
By Jessica Davis | 11:33 am | October 12, 2018
The two nonprofit health IT groups hope to strengthen public-private partnerships and advance policy, starting by collaborating on the next Health Datapalooza.
By Tom Sullivan | 10:20 am | October 12, 2018
The U.S. Department of Health and Human Services is working with Healthbox, a HIMSS innovation company, to reach out to investors and better understand the barriers to innovation. WHY IT MATTERS "This is going to be the first time we formally engage the investment community," HHS Deputy Secretary Eric Hargan told Healthcare IT News. "We work with providers, payers, pharma, medical device companies all the time – but we never talk to the people who are funding those to understand their challenges." HHS aims to change that with a series of events, dubbed Deputy Secretary's Innovation and Investment Summit, which was first announced in mid-September to bring together federal officials with investors and innovators. "What we're trying to do is open the doors at HHS regarding investment in innovation," Hargan said. "We see the investment community as important to innovation within the sector and that is going to be a major way we solve the bedrock mission of the department to promote the health and wellbeing of American people." Healthbox President Neil Patel said the summits will convene the perspectives across all of healthcare and Healthbox's role will be to bring its innovation expertise. "One of the challenges will be figuring out what we can feasibly tackle," Patel said. THE BIGGER TREND Considerable innovation is happening in healthcare, with an explosion of apps and data on the horizon. But even more is needed in areas such as HIE, interoperability, patient experience and telehealth, for instance – and by many accounts the industry must move faster, because things are something of a mess today. WHAT TO EXPECT FROM HHS DSIIS will consist of quarterly meetings designed to foster innovation in digital health, life sciences, medical devices, IT and payment systems. At those events, federal officials intend to listen to investors and innovators to ideally gain an understanding of which policies and regulations are getting in the way of funding for emerging technologies. The idea is to find places where HHS has put up barriers that are troublesome and unnecessary, as well as "to make our policies more rational, get rid of duplicative and contradictory policies and to help HHS develop policies and regulations that facilitate investment in the healthcare sector." HHS anticipates a yearlong process to get this from beginning to end, starting in December 2018, Hargan said. The department might be able to move on some ideas quickly, while for others, particularly those requiring legislative changes, it's harder to determine how long that could take. "Right now we're approaching this in an open way because the interaction has not happened so we have to look at it from a 30,000-foot level," Hargan said. "We've never engaged in a process like this, but I think there's probably fertile ground." HOW TO APPLY Investors interested in participating can apply until midnight Friday, October 12, 2018. They should send an email to DeputySecretary@HHS.gov with the subject line "DSIIS Recommendation." The department is also looking for subject matter experts, so send suggestions to the same email address with the subject line "Topic and Subject Matter Expert Recommendation." Twitter: SullyHIT Email the writer: tom.sullivan@himssmedia.com