Compliance Update: June 27, 2017
HOMELAND SECURITY REPORTS – PETYA RANSOMWARE ATTACKS:
The United States Computer Emergency Readiness Team aka US-CERT is reporting Petya ransomware infections occurring in networks in many countries around the world.
Petya ransomware encrypts the master boot records of infected Windows computers, making affected machines unusable.
Open-source reports indicate that the ransomware exploits vulnerabilities in Server Message Block (SMB). US-CERT encourages users and administrators to review the US-CERT article on the Microsoft SMBv1 Vulnerability and the Microsoft Security Bulletin MS17-010.
For general advice on how to best protect against ransomware infections, review:
US-CERT Alert TA16-091A.
Please report any ransomware incidents to the FBI through the
Internet Crime Complaint Center (IC3).
https://www.ic3.gov/default.aspx
The Office for Civil Rights (OCR), the enforcement agency over HIPAA Security, provides cybersecurity guidance materials including a cybersecurity checklist, ransomware guidance and cyber awareness newsletters at:
https://www.hhs.gov/hipaa/for-professionals/security/guidance/cybersecurity/index.html
https://www.hhs.gov/sites/default/files/cyber-attack-checklist-06-2017.pdf
https://www.hhs.gov/sites/default/files/cyber-attack-quick-response-infographic.gif
Reference:
American Institute of Healthcare Compliance (AIHC)
https://www.hhs.gov/hipaa/for-professionals/security/guidance/cybersecurity/index.html