{"id":56662,"date":"2024-07-25T13:05:49","date_gmt":"2024-07-25T13:05:49","guid":{"rendered":"https:\/\/packetstormsecurity.com\/news\/view\/36146\/HHS-Audit-Finds-Serious-Gaps-In-Cloud-Security-At-Agency-Office.html"},"modified":"2024-07-25T13:05:49","modified_gmt":"2024-07-25T13:05:49","slug":"hhs-audit-finds-serious-gaps-in-cloud-security-at-agency-office","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/hhs-audit-finds-serious-gaps-in-cloud-security-at-agency-office\/","title":{"rendered":"HHS Audit Finds Serious Gaps In Cloud Security At Agency Office"},"content":{"rendered":"<div><img decoding=\"async\" src=\"https:\/\/files.scmagazine.com\/wp-content\/uploads\/2023\/05\/0516_hhs.jpg\" class=\"ff-og-image-inserted\"><\/div>\n<p>A cybersecurity audit of the Department of Health and Human Services\u2019 Office of the Secretary (HHS OS) revealed several serious gaps in the office\u2019s cloud security practices, giving potential cyber attackers access to sensitive data and unauthorized control.<\/p>\n<p>The audit was conducted in June and July 2022 by the HHS Office of the Inspector General, which partnered with BreakPoint Labs to conduct penetration testing and phishing simulations, putting HHS OS\u2019 cloud defenses to the test.<\/p>\n<p>The audit also included a review of the HHS OS\u2019 cloud system policies, inventories and configuration settings. The office\u2019s cloud environments were tested for vulnerabilities and misconfigurations using network vulnerability scanner and cloud security assessment tools.<\/p>\n<p>At the time of the evaluation, more than 30% of HHS\u2019 1,555 systems were cloud-based, according to the Office of the Inspector General. The audit report was issued last week and <a href=\"https:\/\/oig.hhs.gov\/reports-and-publications\/all-reports-and-publications\/hhs-office-of-the-secretary-needs-to-improve-key-security-controls-to-better-protect-certain-cloud-information-systems\/\" target=\"_blank\" rel=\"noreferrer noopener\">first made public on Monday.<\/a><\/p>\n<h2>HHS OS cloud security flaws exposed sensitive personal data<\/h2>\n<p>The HHS Office of the Secretary is the general manager of the HHS, tasked with administering and overseeing the department\u2019s programs and activities. The HHS OS also serves as the chief policy officer of the department.<\/p>\n<p>HHS OS\u2019 cloud systems host a range of sensitive data, including legal documents and information on healthcare delivery services and emergency response, according to the Office of the Inspector General. The office\u2019s role as both a federal government agency and manager of critical health systems makes it a valuable target for cyber threat actors.<\/p>\n<p>The audit revealed that sensitive data, including personal identifiable information (PII) was exposed due to security flaws in HHS OS\u2019 cloud environment implementations. Penetrations testers, who worked from a \u201cblack box\u201d perspective mimicking a real-life attacker\u2019s limited initial knowledge of the target\u2019s cloud systems, not only gained access to this sensitive information but also managed to gain unauthorized control of the components of two of the office\u2019s cloud systems.<\/p>\n<p>\u201cFailure to effectively implement the required security controls places HHS OS cloud systems at potentially higher risk of malicious attacks by bad actors. The vulnerabilities we found may be leveraged by adversaries who seek to steal or distort sensitive data, disrupt operations, and\/or destroy the HHS OS cloud systems that support critical HHS programs,\u201d the inspector general\u2019s report stated.<\/p>\n<p>A total of 12 specific cloud system security control gaps were identified through the audit. The most severe issue discovered, which was given a risk rating of \u201ccritical,\u201d was the lack of multifactor authentication (MFA) for network access to three privileged accounts on one of HHS OS\u2019 cloud systems.<\/p>\n<p>The office also failed to implement access controls on three cloud storage components to ensure sensitive data was not publicly accessible, did not enforce access control policies on 27 cloud components to ensure users had the least privileges necessary, did not adequately remediate system flaws in a timely manner for 25 cloud components, and did not enforce web traffic encryption on one of its remote servers. These four high-severity issues, along with five medium and two low-severity flaws, plus the failure of the office to accurately identify and inventory 13 of its own cloud systems, undermine the security posture of the federal health agency.<\/p>\n<p>On the bright side, the simulated phishing campaign revealed that security systems blocked access to targeted user accounts even when employees clicked on phishing links and attempted to enter their credentials.<\/p>\n<p>The results of the first phase of the phishing simulation, which targeted 127 HHS OS employees, showed no indication that any of the emails were opened, suggesting that the office\u2019s email filtering or other defenses blocked the delivery of the phishing emails. And while some employees in the second phase, which only targeted 19 workers, did attempt to enter their credentials, the inability to access any affected accounts resulted in no recommendations from the Office of the Inspector General regarding that specific segment of the audit.<\/p>\n<h2>HHS security flaws reflect ongoing risks to healthcare, government systems<\/h2>\n<p>The publication of these audit results come after a period relentless targeting of healthcare and government systems by cyber threat actors, particularly by ransomware groups and foreign state-backed attackers.<\/p>\n<p>The spate of attacks, including the major ransomware supply chain attack on Change Healthcare that is <a href=\"https:\/\/www.scmagazine.com\/news\/hhs-investigating-unprecedented-change-healthcare-ransomware-attack\" target=\"_blank\" rel=\"noreferrer noopener\">currently under investigation by the HHS\u2019 Office of Civil Rights<\/a>, has spurred action by HHS offices to strengthen security measures at healthcare systems across the country.<\/p>\n<p>For example, the department <a href=\"https:\/\/www.scmagazine.com\/brief\/new-50m-hhs-program-seeks-to-bolster-hospital-cybersecurity\" target=\"_blank\" rel=\"noreferrer noopener\">announced its new Universal PatchinG and Remediation for Autonomous Defense program<\/a> (UPGRADE) in May, which will provide $50 million in funding to improve hospital defenses through new vulnerability detection and mitigation systems, and customized automated cyber defenses.<\/p>\n<p>The HHS\u2019 Health Sector Cybersecurity Coordination Center (HC3) <a href=\"https:\/\/www.scmagazine.com\/news\/health-sector-help-desks-duped-by-social-engineering-scams-hhs-warns\" target=\"_blank\" rel=\"noreferrer noopener\">also issued an alert<\/a> in April warning of a social-engineering campaign attempting to bypass MFA protections for hospital employee accounts. &nbsp;<\/p>\n<p><a href=\"https:\/\/www.scmagazine.com\/resource\/ransomware-against-healthcare-and-manufacturing-on-the-rise-what-to-know-how-to-respond\" target=\"_blank\" rel=\"noreferrer noopener\">Sophos State of Ransomware Report 2024<\/a> revealed that healthcare remains one of the most heavily targeted sector for ransomware attacks, with the proportion of affected organizations rising year-over-year from 60% in 2023 to 67% in 2024.<\/p>\n<p>Financially motivated attackers have also launched several attacks against local, state and federal government agencies over the past year, <a href=\"https:\/\/www.scmagazine.com\/brief\/reported-hhs-breach-leading-to-theft-of-7-5m-under-investigation\" target=\"_blank\" rel=\"noreferrer noopener\">including in an email hijacking attack<\/a> against HHS\u2019 Health Resources and Services Administration between March and November 2023 that resulted in the theft of $7.5 million.<\/p>\n<p>A <a href=\"https:\/\/www.scmagazine.com\/news\/ransomware-attack-shuts-down-three-dozen-los-angeles-courts\" target=\"_blank\" rel=\"noreferrer noopener\">major ransomware attack against Los Angeles County last week<\/a>, which resulted in the shutdown of 36 local court offices, is one of the most recent examples of ransomware attacks targeting government systems. And federal agencies are far from immune, with <a href=\"https:\/\/www.scmagazine.com\/brief\/cyberattacks-against-federal-government-on-the-rise\" target=\"_blank\" rel=\"noreferrer noopener\">a White House report published last month<\/a> finding a 9.9% increase in cybersecurity incidence affecting the federal government between 2022 and 2023.<\/p>\n<p>Earlier this month, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) reported the results of a 2023 red-teaming exercise that mimicked the tactics of nation-state threat actors to test the security of a civilian executive branch agency. Like the HHS audit, the exercised revealed numerous security shortcomings that could have devastating impacts on critical government systems.<\/p>\n<p>The HHS Office of the Inspector General made several recommendations to remediate flaws at the HHS OS, which include developing a procedure to improve the accuracy and completion of cloud system inventories, remediating the 12 security control issues identified in the report, leveraging cloud security assessment tools to identify and remediate misconfigurations and implementing policies to ensure that only qualified staff are assigned as cloud system security officers.<\/p>\n<p>READ MORE <a href=\"https:\/\/packetstormsecurity.com\/news\/view\/36146\/HHS-Audit-Finds-Serious-Gaps-In-Cloud-Security-At-Agency-Office.html\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>READ MORE HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":56663,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[60],"tags":[6978],"class_list":["post-56662","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-packet-storm","tag-headlinegovernmentusaflaw"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>HHS Audit Finds Serious Gaps In Cloud Security At Agency Office 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/hhs-audit-finds-serious-gaps-in-cloud-security-at-agency-office\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"HHS Audit Finds Serious Gaps In Cloud Security At Agency Office 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/hhs-audit-finds-serious-gaps-in-cloud-security-at-agency-office\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2024-07-25T13:05:49+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/files.scmagazine.com\/wp-content\/uploads\/2023\/05\/0516_hhs.jpg\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/hhs-audit-finds-serious-gaps-in-cloud-security-at-agency-office\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/hhs-audit-finds-serious-gaps-in-cloud-security-at-agency-office\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"HHS Audit Finds Serious Gaps In Cloud Security At Agency Office\",\"datePublished\":\"2024-07-25T13:05:49+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/hhs-audit-finds-serious-gaps-in-cloud-security-at-agency-office\\\/\"},\"wordCount\":1065,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/hhs-audit-finds-serious-gaps-in-cloud-security-at-agency-office\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2024\\\/07\\\/hhs-audit-finds-serious-gaps-in-cloud-security-at-agency-office.jpg\",\"keywords\":[\"headline,government,usa,flaw\"],\"articleSection\":[\"Packet Storm\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/hhs-audit-finds-serious-gaps-in-cloud-security-at-agency-office\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/hhs-audit-finds-serious-gaps-in-cloud-security-at-agency-office\\\/\",\"name\":\"HHS Audit Finds Serious Gaps In Cloud Security At Agency Office 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/hhs-audit-finds-serious-gaps-in-cloud-security-at-agency-office\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/hhs-audit-finds-serious-gaps-in-cloud-security-at-agency-office\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2024\\\/07\\\/hhs-audit-finds-serious-gaps-in-cloud-security-at-agency-office.jpg\",\"datePublished\":\"2024-07-25T13:05:49+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/hhs-audit-finds-serious-gaps-in-cloud-security-at-agency-office\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/hhs-audit-finds-serious-gaps-in-cloud-security-at-agency-office\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/hhs-audit-finds-serious-gaps-in-cloud-security-at-agency-office\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2024\\\/07\\\/hhs-audit-finds-serious-gaps-in-cloud-security-at-agency-office.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2024\\\/07\\\/hhs-audit-finds-serious-gaps-in-cloud-security-at-agency-office.jpg\",\"width\":1280,\"height\":800},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/hhs-audit-finds-serious-gaps-in-cloud-security-at-agency-office\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"headline,government,usa,flaw\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/tag\\\/headlinegovernmentusaflaw\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"HHS Audit Finds Serious Gaps In Cloud Security At Agency Office\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"HHS Audit Finds Serious Gaps In Cloud Security At Agency Office 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/hhs-audit-finds-serious-gaps-in-cloud-security-at-agency-office\/","og_locale":"en_US","og_type":"article","og_title":"HHS Audit Finds Serious Gaps In Cloud Security At Agency Office 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/hhs-audit-finds-serious-gaps-in-cloud-security-at-agency-office\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2024-07-25T13:05:49+00:00","og_image":[{"url":"https:\/\/files.scmagazine.com\/wp-content\/uploads\/2023\/05\/0516_hhs.jpg","type":"","width":"","height":""}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/hhs-audit-finds-serious-gaps-in-cloud-security-at-agency-office\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/hhs-audit-finds-serious-gaps-in-cloud-security-at-agency-office\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"HHS Audit Finds Serious Gaps In Cloud Security At Agency Office","datePublished":"2024-07-25T13:05:49+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/hhs-audit-finds-serious-gaps-in-cloud-security-at-agency-office\/"},"wordCount":1065,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/hhs-audit-finds-serious-gaps-in-cloud-security-at-agency-office\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2024\/07\/hhs-audit-finds-serious-gaps-in-cloud-security-at-agency-office.jpg","keywords":["headline,government,usa,flaw"],"articleSection":["Packet Storm"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/hhs-audit-finds-serious-gaps-in-cloud-security-at-agency-office\/","url":"https:\/\/www.threatshub.org\/blog\/hhs-audit-finds-serious-gaps-in-cloud-security-at-agency-office\/","name":"HHS Audit Finds Serious Gaps In Cloud Security At Agency Office 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/hhs-audit-finds-serious-gaps-in-cloud-security-at-agency-office\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/hhs-audit-finds-serious-gaps-in-cloud-security-at-agency-office\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2024\/07\/hhs-audit-finds-serious-gaps-in-cloud-security-at-agency-office.jpg","datePublished":"2024-07-25T13:05:49+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/hhs-audit-finds-serious-gaps-in-cloud-security-at-agency-office\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/hhs-audit-finds-serious-gaps-in-cloud-security-at-agency-office\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/hhs-audit-finds-serious-gaps-in-cloud-security-at-agency-office\/#primaryimage","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2024\/07\/hhs-audit-finds-serious-gaps-in-cloud-security-at-agency-office.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2024\/07\/hhs-audit-finds-serious-gaps-in-cloud-security-at-agency-office.jpg","width":1280,"height":800},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/hhs-audit-finds-serious-gaps-in-cloud-security-at-agency-office\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"headline,government,usa,flaw","item":"https:\/\/www.threatshub.org\/blog\/tag\/headlinegovernmentusaflaw\/"},{"@type":"ListItem","position":3,"name":"HHS Audit Finds Serious Gaps In Cloud Security At Agency Office"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/56662","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=56662"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/56662\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media\/56663"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=56662"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=56662"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=56662"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}