Cybersecurity starts with you: Recognizing National Cybersecurity Awareness Month
Cyberattacks can threaten more than data. They can disrupt clinical operations and put patient safety at risk. During National Cybersecurity Awareness Month, the AMA is highlighting resources that can help physicians and other healthcare professionals strengthen their cybersecurity knowledge and better protect their organizations and patients.
A good place to start is the AMA Ed Hub’s “Cybersecurity for the Clinician” training series. Designed for clinicians and medical students, the eight-part series organizes key cybersecurity concepts into clear, nontechnical terms and explores the connection between cyber threats, clinical care and patient safety.
The series opens with “Cyber Safety Is Patient Safety,” which examines how cyberattacks can compromise patient information, interrupt clinical operations, and ultimately affect patient care. Other episodes cover topics including social engineering, medical device cybersecurity and the teams responsible for responding to cyber incidents.
Hosted by Christian Dameff, MD, an emergency medicine physician and medical director for cybersecurity, the series was produced by the Healthcare and Public Health Sector Coordinating Council Cybersecurity Working Group.
Additional tools are available through the Department of Health and Human Services’ 405(d) Program, which provides cybersecurity resources for the healthcare and public health sector. Physicians and their staff can also visit the AMA’s Physician Cybersecurity resource center for information and tips on safeguarding patient health records and other sensitive information.
Together, these resources offer physicians and healthcare organizations practical opportunities to strengthen cybersecurity awareness and reinforce protections for patients, practices and health information.
Senate passes bipartisan Health Care Cybersecurity and Resiliency Act
On Sept. 30, the Senate passed S. 3315, the Health Care Cybersecurity and Resiliency Act, which is led by the Senate Health, Education, Labor and Pensions Committee Chairman Bill Cassidy (R-LA), with Sens. Maggie Hassan (D-NH), John Cornyn (R-TX) and Mark Warner (D-VA). The AMA supported the intentions of the legislation, which would update cybersecurity standards, recognize security investments, strengthen federal coordination, provide rural cybersecurity guidance and technical assistance, and improve reporting standards.
While the bill passed the Senate by Unanimous Consent, the legislation will still need action in the House of Representatives before being sent to the president to be signed into law. The AMA is continuing to work with congressional leaders to make potential changes to the legislation to ensure that it is strengthened and in line with the AMA's policy.
Deadline approaching for alternative payment model participant billing information
Physicians who reached Qualified Participant (QP) status through participation in alternative payment models (APMs) in 2024 should have received their APM incentive payments last summer. Those who did not receive their payments need to provide their current billing information to Medicare no later than Oct. 13, 2026. CMS has posted a zip folder online, the 2026 QP Notice for APM Incentive Payment (ZIP), that contains an Excel spreadsheet where physicians who think they have missed this payment can find their name and NPI, and a PDF document explaining how to obtain the missing payment. Most importantly, page 4 of the PDF contains a brief form, the 2026 APM Incentive Payment Billing Collection Form, where physicians can provide information about their current Medicare billing entity.