{"id":22729,"date":"2023-08-17T10:45:37","date_gmt":"2023-08-17T18:45:37","guid":{"rendered":"https:\/\/www.palada.net\/index.php\/2023\/08\/17\/news-16459\/"},"modified":"2023-08-17T10:45:37","modified_gmt":"2023-08-17T18:45:37","slug":"news-16459","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2023\/08\/17\/news-16459\/","title":{"rendered":"HHS Launches &#8216;Digiheals&#8217; Project to Better Protect US Hospitals From Ransomware"},"content":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/media.wired.com\/photos\/64dd23880124a91cee27dc20\/master\/pass\/White-House-Initiative-Seeks-to-Defend-Digital-Systems-in-US-Healthcare-Security-GettyImages-674506032.png\"\/><\/p>\n<p><strong>Credit to Author: Lily Hay Newman| Date: Thu, 17 Aug 2023 10:00:00 +0000<\/strong><\/p>\n<p class=\"BylineWrapper-jWHrLH hAfVoD byline bylines__byline\" data-testid=\"BylineWrapper\" itemprop=\"author\" itemtype=\"http:\/\/schema.org\/Person\"><span itemprop=\"name\" class=\"BylineNamesWrapper-jbHncj fuDQVo\"><span data-testid=\"BylineName\" class=\"BylineName-kwmrLn cVPPwi byline__name\"><a class=\"BaseWrap-sc-gjQpdd BaseText-ewhhUZ BaseLink-eNWuiM BylineLink-gEnFiw iUEiRd kZoQA-D ecbzIP BDKtv byline__name-link button\" href=\"\/author\/lily-hay-newman\">Lily Hay Newman<\/a><\/span><\/span><\/p>\n<p><span class=\"lead-in-text-callout\">The Advanced Research<\/span> Projects Agency for Health (Arpa-H), a research support agency within the United States Department of Health and Human Services, said today that it is launching an initiative to find and help fund the development of cybersecurity technologies that can specifically improve defenses for digital infrastructure in US health care. Dubbed the Digital Health Security project, also known as Digiheals, the effort will allow researchers and technologists to submit proposals beginning today through September 7 for cybersecurity tools geared specifically to health care systems, hospitals and clinics, and health-related devices.<\/p>\n<p class=\"paywall\">For more than a decade, health care providers in the United States and around the world have been <a href=\"https:\/\/www.wired.com\/story\/universal-health-services-ransomware-attack\/\">plagued<\/a> by criminal cyberattacks, particularly <a href=\"https:\/\/www.wired.com\/2016\/03\/ransomware-why-hospitals-are-the-perfect-targets\/\">ransomware attacks<\/a>, that take advantage of medical facilities\u2019 high-stakes work to attempt to extort big payouts. Efforts in recent years to <a href=\"https:\/\/www.wired.com\/story\/ransomware-task-force-proposal\/\">crack down on and deter<\/a> cybercriminal actors have made some limited progress, but health care attacks still <a href=\"https:\/\/www.wired.com\/story\/ransomware-tactics-cancer-photos-student-records\/\">occur regularly<\/a>, disrupting vital services and endangering patients.<\/p>\n<p class=\"paywall\">Health and Human Service\u2019s research agency Arpa-H doesn\u2019t specifically focus on cybersecurity innovation. The agency has programs running, for example, to spur advances in osteoarthritis treatment and medical imaging for cancer removal. But Digiheals program manager and longtime security researcher Andrew Carney says there is a dire need to make progress on digital defense tools for health care that are both effective and usable for medical facilities in practice.<\/p>\n<p class=\"paywall\">\u201cWe\u2019re looking for rapid and stupendous progress,\u201d Carney told WIRED ahead of the announcement. \u201cWe want to ensure that the impact we have is significant but also equitably distributed. It doesn\u2019t matter if we develop a perfect cure that makes a network completely impenetrable if a rural hospital can\u2019t adopt it because of light IT staff or minimal or no security budget.\u201d<\/p>\n<p class=\"paywall\">Digiheals is seeking broad and diverse submissions related to vulnerability detection, software hardening, and system patching, as well as the expansion or development of security protocols. The initiative will accept submissions from anyone, including academic and nonprofit researchers or commercial industry. Carney emphasizes that, ultimately, the goal is to foster novel and inventive solutions regardless of where they come from or what category they fit into.<\/p>\n<p class=\"paywall\">\u201cWe are looking to very rapidly cast a wide net,\u201d he says. \u201cI\u2019d encourage folks even if they have ideas that don\u2019t fit cleanly or won\u2019t fit the timeline of the solicitation to come talk to us. We will make the process fit the ideas we receive as best we can.\u201d<\/p>\n<p class=\"paywall\">Carney points out that it is particularly difficult to study the real-world conditions of cybersecurity in health care, because each medical provider\u2019s network is made up of a vast patchwork of systems, services, and <a href=\"https:\/\/www.wired.com\/story\/defcon-medical-device-village-hacking-hospital\/\">devices that vary widely<\/a>. And there is no margin for error in probing individual institutions\u2019 systems or attempting to attack them intentionally to discover weaknesses. So Digiheals is also encouraging researchers to make submissions related to the types of security tools that are not working in health care settings and the reasons for these failings.<\/p>\n<p class=\"paywall\">\u201cCurrently, off-the-shelf software tools fall short in detecting emerging cyber threats and protecting our medical facilities, resulting in a technical gap we seek to bridge with this initiative,\u201d Arpa-H director Renee Wegrzyn said in a statement. \u201cThe Digiheals project comes when the US health care system urgently requires rigorous cybersecurity capabilities to protect patient privacy, safety, and lives.\u201d<\/p>\n<p class=\"paywall\">After years of damaging cyberattacks on hospitals and disruptions to patient care, the Digiheals initiative may feel like too little, too late. Earlier this month, a <a href=\"https:\/\/www.nytimes.com\/2023\/08\/05\/us\/cyberattack-hospitals-california.html\">ransomware attack on the medical group<\/a> Prospect Medical Holdings, which operates in Connecticut, Pennsylvania, Rhode Island and Southern California, caused disruptions at multiple hospitals and clinics in the network. The recovery process is <a data-offer-url=\"https:\/\/therecord.media\/prospect-hospitals-still-recovering\" class=\"external-link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/therecord.media\/prospect-hospitals-still-recovering&quot;}\" href=\"https:\/\/therecord.media\/prospect-hospitals-still-recovering\" rel=\"nofollow noopener\" target=\"_blank\">ongoing<\/a>. But Arpa-H is a <a href=\"https:\/\/www.hhs.gov\/about\/news\/2022\/05\/25\/hhs-secretary-becerra-establishes-arpa-h-within-nih-names-adam-h-russell-phil-acting-deputy-director.html\">new agency<\/a> launched by the Biden administration last year to help address a number of issues in US health care that are massively overdue for investment.<\/p>\n<p class=\"paywall\">\u201cHealth care gets the most difficult of the challenges from every angle,\u201d Carney says. \u201cWe\u2019re constantly working at near or above capacity, and any reduction in service can have real harm very quickly. But we have an ability to move very fast on new digital defenses, and it behooves us to do so. It would be irresponsible of us not to move fast.\u201d<\/p>\n<p><a href=\"https:\/\/www.wired.com\/story\/hospital-ransomware-hhs-digiheals\/\" target=\"bwo\" >https:\/\/www.wired.com\/category\/security\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/media.wired.com\/photos\/64dd23880124a91cee27dc20\/master\/pass\/White-House-Initiative-Seeks-to-Defend-Digital-Systems-in-US-Healthcare-Security-GettyImages-674506032.png\"\/><\/p>\n<p><strong>Credit to Author: Lily Hay Newman| Date: Thu, 17 Aug 2023 10:00:00 +0000<\/strong><\/p>\n<p>An innovation agency within the US Department of Health and Human Services will fund research into better defenses for the US health care system\u2019s digital infrastructure.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10378,10607],"tags":[714,21358],"class_list":["post-22729","post","type-post","status-publish","format-standard","hentry","category-security","category-wired","tag-security","tag-security-cyberattacks-and-hacks"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/22729","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=22729"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/22729\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=22729"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=22729"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=22729"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}