The Cybersecurity and Infrastructure Security Agency announced Feb. 13 that it will host a series of virtual town hall meetings to gather public input on rulemaking for the Cyber Incident Reporting for Critical Infrastructure Act of 2022. The meetings will begin March 9, according to a Federal Register notice. The proposed rule, issued in March 2024, would require critical infrastructure organizations, including hospitals and health systems, to report a cyber incident to the federal government within 72 hours and ransom payments within 24 hours, among other requirements. The AHA commented on the proposed rule, calling the requirements redundant to those from other federal agencies and that they add unnecessary burden to hospitals working to ensure access to needed services during a cybersecurity incident response.

Related News Articles

Headline
John Riggi, AHA national advisor for cybersecurity and risk, talks with Brett Leatherman, FBI assistant director, Cyber Division, and Gretchen Burrier, FBI…
Headline
The AHA Feb. 9 released a series of behavioral threat assessment and management resources developed in partnership with the FBI’s Behavioral Analysis Unit-1.…
Headline
John Riggi, AHA national advisor for cybersecurity and risk, talks with Brett Leatherman, FBI assistant director, Cyber Division, and Gretchen Burrier, FBI…
Headline
The National Institute of Standards and Technology Feb. 2 published details on a critical vulnerability that impacted Notepad++, a free, open-source text and…
Headline
The FBI has launched a two-month campaign, Operation Winter SHIELD (Securing Homeland Infrastructure by Enhancing Layered Defense), highlighting 10 actions…
Headline
Two AHA guides offer strategies for hospitals and health systems in preparing for public health emergencies and disasters and managing cybersecurity incidents…