Search site
Find podcasts, news, articles, webinars, and contributors in one search.
Health IT News
Browse by topic
Most-read stories in the last 7 days
1,000 stories
Feb 12, 2026·Cybersecurity Dive
The Cybersecurity and Infrastructure Security Agency wants critical infrastructure partners’ feedback on the scope of its cyber-incident reporting regulation as the agency homes in on a final version of the long-awaited rule. In a notice set for publication in the Federal Register on Friday, CISA announced a series of town hall meetings where different sectors will be able to share their thoughts about the pending rule, which Congress required in the 2022 Cyber Incident Reporting for Critical Infrastructure Act. A draft version of the CIRCIA rule, published in April 2024, gave covered infrastructure operators 72 hours to report substantial cyber incidents to the government. Business groups and some lawmakers objected to the scope of the information that companies would need to report, as well as to the breadth of companies covered under the regulation.
Feb 10, 2026·Wired
The Mobile Fortify app, launched by the Department of Homeland Security in 2025, has faced significant criticism for its unreliable identity verification capabilities, as detailed in WIRED's investigation. Intended to facilitate federal immigration operations, the app's ineffectiveness raises serious concerns about privacy, particularly because it has been used to identify U.S. citizens and bystanders without consent. The development bypassed essential privacy assessments, suggesting a troubling trend toward increased biometric data collection in law enforcement activities that lacks transparency and accountability. These issues underscore the need for healthcare professionals and technologists to remain vigilant about the ethical implications of emerging surveillance technologies and their potential impact on civil liberties.
Feb 10, 2026·Fortune
Experts in artificial intelligence have raised alarms about Moltbook, a new social media platform for AI agents, citing significant ethical and security risks. Concerns center around the platform's lack of safeguards, which could enable harmful behavior, the spread of misinformation, and the emergence of autonomous systems beyond human oversight. Additionally, privacy risks are heightened, as unrestricted AI interactions could lead to data breaches and unauthorized access, making the platform vulnerable to cyberattacks. This situation underscores the urgent need for stringent regulations and ethical guidelines in the deployment of AI technologies in healthcare and beyond.
Feb 8, 2026·The Record
The Cybersecurity and Infrastructure Security Agency (CISA) has mandated that federal civilian agencies must remove end-of-life devices from their networks within a year due to rising cyber threats from sophisticated attackers targeting unsupported hardware and software. This directive, which applies to vulnerable edge devices like load balancers and IoT devices, aims to proactively mitigate risks associated with devices that no longer receive official updates, thereby enhancing cybersecurity. Agencies are required to inventory and decommission these devices promptly, underscoring the urgent need for healthcare professionals to address similar risks within their own technology infrastructure. The initiative highlights the critical importance of maintaining up-to-date systems to safeguard against growing cyber threats.
Feb 8, 2026·axios.com
Anthropic's AI model, Claude Opus 4.6, has identified over 500 critical security flaws in open-source libraries, marking a significant advancement in AI-driven cybersecurity. Operating with minimal instruction in a controlled setting, the model demonstrated its potential for proactively detecting vulnerabilities that could be targeted by cyber attackers, thus enhancing defenses in an increasingly digital landscape. The variability in severity of the flaws, from system crashes to memory corruption, underscores the urgent need for healthcare professionals to consider such AI tools as essential in safeguarding sensitive data and maintaining system integrity. This development highlights a shift towards leveraging AI in cybersecurity efforts, a vital resource for organizations facing escalating threats.
Feb 8, 2026·SecurityWeek
Zscaler's acquisition of SquareX aims to bolster its browser security capabilities, responding to the growing risk of web-based threats as businesses increasingly adopt cloud services and remote operations. This integration of SquareX’s technology will enhance Zscaler's security offerings, essential for safeguarding users against sophisticated cyber attacks that often originate in web browsers. The acquisition highlights a significant trend in the cybersecurity sector, where firms are strategically expanding their services to address emerging vulnerabilities. For healthcare professionals, this development emphasizes the critical need for robust cybersecurity measures to protect sensitive patient data in an evolving digital landscape.
Feb 5, 2026·Reuters
As the Super Bowl approaches, cybersecurity experts are increasingly concerned about AI-enhanced cyber threats targeting the high-profile event. The integration of advanced AI technologies in cyberattacks complicates detection, underscoring the need for sophisticated security measures. Organizers are proactively implementing AI-driven security systems and fostering collaboration among stakeholders to create a robust defense strategy. This approach emphasizes the importance of adapting to new challenges in cybersecurity, particularly as events like the Super Bowl attract significant digital vulnerabilities.
Feb 5, 2026·BankInfoSecurity
Federal auditors have revealed significant cybersecurity vulnerabilities in a large Southeastern U.S. hospital, underscoring widespread security challenges within the healthcare sector. A report by the U.S. Department of Health and Human Services' Office of Inspector General highlights inadequate cybersecurity measures, such as the absence of multifactor authentication and susceptibility to injection attacks, which threaten sensitive patient data and continuity of care. These findings indicate that many healthcare organizations struggle with effective cybersecurity due to complex IT infrastructures and resource limitations, emphasizing the urgent need for improved security protocols. As healthcare technology rapidly evolves, the need for consistent security oversight becomes increasingly critical to protect patient information effectively.
Feb 4, 2026·WRGB - CBS6 Albany
Governor Kathy Hochul of New York has announced a $9 million federal grant to enhance cybersecurity for local governments and public entities across the state, enabling the distribution of Multi-Factor Authentication (MFA) hard tokens to 161 organizations. This funding, part of the State and Local Cybersecurity Grant Program, seeks to bolster defenses against cyberattacks by requiring multiple verification methods for system access. By prioritizing the protection of critical technology infrastructures, this initiative highlights the growing recognition among state officials of cybersecurity’s essential role in safeguarding public resources and services. Such measures are vital for healthcare professionals, as they underscore the need for robust cybersecurity practices to protect sensitive patient information and maintain trust in healthcare systems.
Feb 3, 2026·arstechnica.com
security professionals in the healthcare sector and beyond, as it emphasizes the importance of clear communication and understanding between security firms and law enforcement. The wrongful arrest of Gary DeMercurio and Justin Wynn during a sanctioned security assessment raises concerns about how such misunderstandings can impact critical cybersecurity efforts. As healthcare organizations increasingly engage in similar security exercises to protect sensitive data, ensuring legal protections and clarity in procedures will be essential to avoid misinterpretations that could disrupt operations and erode trust in security practices. This case serves as a critical reminder for healthcare professionals to align security protocols with legal frameworks to safeguard their teams and technology.
Feb 2, 2026·industrialcyber.co
The Trellix 2025 Healthcare Cybersecurity Threat Intelligence Report underscores the escalating cybersecurity risks in healthcare due to increased digital transformation and cloud adoption, which have expanded vulnerabilities to patient safety. With healthcare experiencing over 54.7 million cyber detections predominantly from email attacks, the sector remains the most costly for data breaches, averaging $10.22 million per incident. The report highlights a concerning trend called the 'Cascading Effect,' where breaches in non-clinical systems disrupt critical clinical workflows, potentially leading to higher mortality rates. Furthermore, the rise of patient extortion through stolen medical records signals a shift in attackers' strategies, emphasizing the urgent need for healthcare executives to prioritize cybersecurity measures.
Feb 2, 2026·Forbes
The recent partial government shutdown that began on January 31, 2026, accentuates the vulnerabilities in federal governance, particularly in cybersecurity. Although a temporary funding agreement has been reached, ongoing political discord risks a prolonged shutdown, which can severely disrupt operational capacity in vital areas like cybersecurity. Historical precedents show that funding lapses force federal agencies to divert resources from long-term capability development to immediate operational needs, hampering research and slowing the deployment of essential defense technologies. For healthcare professionals, this situation highlights the fragility of cybersecurity measures that rely on continuous governmental support and proactive strategies.
Feb 2, 2026·Warontherocks.com
The article reveals significant vulnerabilities within America's telecommunications networks, attributing these issues primarily to preventable security oversights rather than advanced cyber threats from adversaries like China. Basic problems such as outdated equipment, weak passwords, and unpatched software have enabled state-sponsored hackers to exploit existing weaknesses easily. This situation calls for a reevaluation of the strategies employed by U.S. policymakers, who often focus on reactive measures like sanctions instead of addressing fundamental security gaps. With the potential for adversaries to disrupt critical infrastructure during crises, enhancing cybersecurity protocols is essential for healthcare technologies that rely on these networks.
Feb 2, 2026·BankInfoSecurity
Healthcare Interactive (HCIactive) has suffered a major data breach impacting nearly 3.1 million individuals, marking it as one of the largest health information breaches of 2025. Initially underestimated in size, the breach revealed that sensitive data—ranging from medical diagnoses to Social Security numbers—was compromised after unauthorized access occurred in early July 2025. The incident raises concerns about the effectiveness of HCIactive's recent AI-driven security initiatives, launched just months prior, and underscores the urgent need for enhanced cybersecurity measures within healthcare technology to protect sensitive patient information. This breach serves as a stark reminder for healthcare professionals to prioritize robust data protection and compliance strategies in an increasingly digital landscape.
Jan 30, 2026·City of Hope
City of Hope has appointed Gordon Groschl as the new system vice president and chief information security officer, tasked with overseeing Corporate Security, IT Compliance, and Data Privacy. With over 25 years of cybersecurity experience in healthcare, Groschl's leadership is critical for protecting sensitive data and systems as the organization expands its national footprint. His expertise is expected to enhance the resilience of City of Hope’s technological infrastructure and support ongoing innovation in cancer research and patient care. This strategic hire highlights the growing importance of robust cybersecurity measures in healthcare settings, where data protection is essential for patient trust and institutional integrity.
Jan 29, 2026·Ars Technica
Madhu Gottumukkala, acting director of the Cybersecurity and Infrastructure Security Agency (CISA), faced scrutiny after unintentionally uploading sensitive contracting documents labeled "for official use only" to ChatGPT, raising cybersecurity alarms. While the information was not classified, its potential exposure to a broad user base poses risks to government operations, prompting the Department of Homeland Security to investigate the incident. This episode highlights pressing concerns about data security in the context of emerging AI technologies, calling attention to the need for improved protocols in handling sensitive information. As CISA grapples with internal instability and leadership challenges, the incident underscores the critical importance of safeguarding federal cybersecurity measures.
Jan 29, 2026·Cybersecurity Dive
The Trump administration’s recent decision to eliminate the security attestation requirement for federal software vendors marks a significant shift in governmental cybersecurity policy. This move rescinds a Biden-era directive aimed at enhancing security practices among vendors through mandatory compliance measures, raising concerns among cybersecurity experts about potential gaps in oversight. The removal of the attestation process may lead to inconsistent security standards across agencies, undermining efforts to promote robust cybersecurity frameworks. As healthcare technology increasingly relies on secure software solutions, this change could impact the overall safety and integrity of sensitive health data managed by federal systems.
Jan 28, 2026·CSO Online
The widespread practice of always-on privileged access in enterprise IT environments poses significant security risks, with 91% of users operating at their highest privilege levels. This trend indicates weaknesses in IT governance and highlights the challenges posed by complex IT systems marked by mergers, cloud migrations, and insufficient oversight. Experts warn that this lax approach compromises security and can lead to severe consequences from misuse or user errors, while difficulties in using privileged access management tools encourage circumvention of established security measures. As healthcare systems increasingly rely on interconnected technologies, addressing these vulnerabilities is critical to safeguarding sensitive patient data and ensuring compliance with regulatory standards.
Jan 28, 2026·Cybersecurity Dive
A recent report from Zscaler reveals substantial vulnerabilities in enterprise AI tools, thereby stressing the urgent need for enhanced governance and security protocols as these technologies become more integrated into operations. The findings show that AI systems are prone to rapid failures, often within minutes of operation during stress tests, with potential cybersecurity implications including biased outcomes and privacy breaches. For healthcare professionals, these insights serve as a critical reminder that deploying AI without adequate safeguards can expose sensitive patient data and undermine trust in technological solutions. Thus, the report calls for healthcare organizations to implement real-time defenses and stringent governance measures to safeguard against potential cyber threats.
Jan 27, 2026·Network World
Palo Alto Networks has issued critical patches for its PAN-OS firewall after identifying a high-severity denial-of-service vulnerability (CVE-2026-0227) that affects configurations with the GlobalProtect remote access gateway. With a CVSS rating of 7.7, this flaw could allow unauthenticated attackers to disrupt firewall operations, leading to network outages. Although no active exploitations have been reported, the existence of proof of concept code raises alarms about potential future attacks, echoing concerns from a similar incident in 2024. Healthcare professionals using these firewall systems must prioritize updates to mitigate risks to network security and patient data integrity.