Skip to content Accessibility tools

HHS Issues Important Cybersecurity Notice for Health Care Operators

Important alert: The US Department of Health and Human Services (HHS) Health Sector Cybersecurity Coordination Center released a notice strongly encouraging health care organizations to upgrade their devices due to a vulnerability known as “Citrix Bleed.” 

Why it matters: This vulnerability has been ongoing since August 2023 and could allow hackers to access private health care information by bypassing passwords and multifactor authentication.  

About the patch: Citrix released a patch for this vulnerability in early October, but these compromised sessions will still be active after a patch has been implemented.

  • Administrators should follow Citrix’s guidance to upgrade their devices and remove any active or persistent sessions. The HHS alert includes the relevant commands.

 

As a reminder, everyone must remain vigilant.

  • Do not click on suspicious emails, especially over the holidays.