sábado, 1 de julio de 2017

HHS ASPR/CIP HPH Cyber Notice: International Ransomware Campaign UPDATE #2

HealthIT.gov Banner

HHS ASPR/CIP HPH Cyber Notice: International Ransomware Campaign UPDATE #2

DISCLAIMER: This product is provided “as is” for informational purposes only. The Department of Health and Human Services (HHS) does not provide warranties of any kind regarding any information contained within. HHS does not endorse any commercial product or service referenced in this product or otherwise. You may forward this message widely with no restrictions.


Dear HPH Sector Colleagues,
HHS continues to monitor on-going impacts to the HPH Sector from Petya/notPetya ransomware. At this time there is no new information to share about the threat vector. We are tracking the resolution of port closures, medical data software availability, and impacts to pharmaceutical companies and will report to you if we become aware of any long-term impacts to the HPH Sector.
HHHS/ASPR CIP will continue to monitor the situation but will no longer provide daily updates unless the situation warrants. We encourage you to connect with relevant trade associations, ISAO/ISACs, and government partners to discuss any long-term concerns related to this ransomware event.
Please review the information below. You may share this message freely with no restrictions. We will update you as more information becomes available.
Thank you-
HHS/ASPR Critical Infrastructure Protection Program
National Health Information Sharing and Analysis Center (NH-ISAC) in collaboration with ONC and ASPR disseminates cyber alerts and threat updates. To sign up to receive these alerts, go to https://nhisac.org/outreach/, on the left, you’ll see a box to enter your email information to subscribe.
If you are the victim of a ransomware attack
If your organization is the victim of a ransomware attack, HHS recommends the following steps:
  1. Please contact your FBI Field Office Cyber Task Force (www.fbi.gov/contact-us/field/field-offices) or US Secret Service Electronic Crimes Task Force (www.secretservice.gov/investigation/#field) immediately to report a ransomware event and request assistance. These professionals work with state and local law enforcement and other federal and international partners to pursue cyber criminals globally and to assist victims of cyber-crime.
  2. Please report cyber incidents to the US-CERT (www.us-cert.gov/ncas) and FBI’s Internet Crime Complaint Center (www.ic3.gov).
  3. If your facility experiences a suspected cyberattack affecting medical devices, you may contact FDA’s 24/7 emergency line at 1-866-300-4374. Reports of impact on multiple devices should be aggregated on a system/facility level.
  4. For further analysis and healthcare-specific indicator sharing, please also share these indicators with HHS’ Healthcare Cybersecurity and Communications Integration Center (HCCIC) at HCCIC@hhs.gov
Mitigating against this threat *updated*
  • *updated* Our partners at NH-ISAC have tested a "vaccine" that has been reported as potentially helpful for systems that have not been impacted. The "vaccine" may also help spread of infection. Use of this "vaccine" should not preclude proper patching as it only prevents harm from one specific strain of malware. When using this vaccine, consider any potential business impact. The "vaccine" is the creation of a file C:\Windows\perfc and setting the permissions to READ ONLY. As with any patch/update, this modification should be evaluated before implementation by appropriate system security personnel. For further information on this "vaccine" please visit https://nhisac.org/nhisac-alerts/petya-ransomware-updates/
  • Educate users on common Phishing tactics to entice users to open malicious attachments or to click links to malicious sites
  • Patch vulnerable systems with the latest Microsoft security patches: https://technet.microsoft.com/en-us/security/bulletins.aspx
  • Verify perimeter tools are blocking Tor .Onion sites
  • Use a reputable anti-virus (AV) product whose definitions are up-to-date to scan all devices in your environment in order to determine if any of them have malware on them that has not yet been identified. Many AV products will automatically clean up infections or potential infections when they are identified.
  • Monitor US-CERT for the latest updates from the U.S. government
  • Utilize HPH Sector ISAC and ISAO resources.

Product Identifier Requirements Under the Drug Supply Chain Security Act – Compliance Policy - New FDA Guidance Document

FDA/CDER's Small Business and Industry Assistance (CDER SBIA)

The FDA recently published a draft guidance, Product Identifier Requirements Under the Drug Supply Chain Security Act – Compliance Policy.

This draft guidance describes FDA’s compliance policy on enforcing requirements related to product identifiers under the DSCSA. Specifically, this compliance policy addresses manufacturers’ product identifier and verification requirements, which begin November 27, 2017. This compliance policy also addresses certain requirements for repackagers, wholesale distributors, and dispensers to only engage in transactions involving products with product identifiers and to verify the product identifier when investigating suspect product, in addition to repackager and wholesale distributor requirements related to saleable returned product.

New Director's Corner Podcast: Antibiotic Misuse and Resistance- Drug Information Update

FDA Logo, hands holding pills
The Division of Drug Information (DDI)- serving the public by providing information on human drug products and drug product regulation by FDA.
FDA has released the latest edition of the Director's Corner podcast.
Listen to Dr. Woodcock discuss the issues surrounding the use and misuse of antibiotic medicines, as well as the emergence of antibiotic-resistant bacteria and how the issues are related.
Click on the following links to read a transcript and listen to the podcast.
  • Antibiotic Misuse and ResistanceListen iconRead Transcript Icon

What's New at CBER Update

What's New at CBER Update

New FDA Logo Blue

This page has been updated recently.

New Spotlight on CDER Science: Lab Tests in Rodents Suggest Potential New Biomarker for Acute Pancreatic Injury- Drug Information Update

FDA Logo, hands holding pills
The Division of Drug Information (DDI)- serving the public by providing information on human drug products and drug product regulation by FDA.

A new Spotlight on CDER Science has been posted. The topic is: "Lab Tests in Rodents Suggest Potential New Biomarker for Acute Pancreatic Injury.”

This spotlight is by Rodney Rouse, DVM, MBA, PhD, Research Veterinary Medical Officer and Acting Associate Director, Division of Applied Regulatory Science, Office of Translational Sciences, Center for Drug Evaluation and Research.

Biomarkers are measurable indicators in the body that can signify the presence of disease or disease severity.  The identification of new, reliable and sensitive biomarkers remains a priority for the FDA.  In addition to measuring disease presence and severity, a biomarker may detect early tissue injury caused by a drug. These types of biomarkers may be used in safety studies to better characterize a drug’s risk profile during drug development.

One injury requiring more sensitive biomarkers is acute pancreatic injury.

For more information, please visit: Biomarker for Acute Pancreatic Injury.

Recently posted guidance documents on Product Identifier Requirements Under the Drug Supply Chain Security Act, CGMP for Medical Gases, and Clinical Trials of Cellular and Gene Therapy Products

New FDA Logo Blue

Recently Posted Guidance Documents

Drugs


Cellular & Gene Therapy


Guidance Document Search

New Draft Guidance: Product Identifier Requirements Under the Drug Supply Chain Security Act – Compliance Policy- Drug Information Update

Product Identifier Requirements Under the Drug Supply Chain Security Act – Compliance Policy Guidance for Industry

FDA Logo, hands holding pills
The Division of Drug Information (DDI)- serving the public by providing information on human drug products and drug product regulation by FDA.
The FDA recently published a draft guidance, Product Identifier Requirements Under the Drug Supply Chain Security Act – Compliance Policy.
This draft guidance describes FDA’s compliance policy on enforcing requirements related to product identifiers under the DSCSA. Specifically, this compliance policy addresses manufacturers’ product identifier and verification requirements, which begin November 27, 2017. This compliance policy also addresses certain requirements for repackagers, wholesale distributors, and dispensers to only engage in transactions involving products with product identifiers and to verify the product identifier when investigating suspect product, in addition to repackager and wholesale distributor requirements related to saleable returned product.