Healthcare groups in the US believe insurers and third-party vendors should be included in cybersecurity reporting proposals. The proposed rule, released by the Cybersecurity and Infrastructure Security Agency (CISA), does not specifically cover insurers, health IT providers and diagnostic services, something industry groups and the American Hospital Association (AHA) oppose. They argue that an attack on one company could have widespread implications for the sector. Some groups have called for greater flexibility on reporting times due to the potential need for resources elsewhere in a crisis.

The True Cost of Focusing on Cost Instead of Cost-Effectiveness
When payors consider only the cost of the medication and not the cost and risk to the patient, doctor, and healthcare system, the irony is


