Search site
Find podcasts, news, articles, webinars, and contributors in one search.
Health IT News
Browse by topic
Most-read stories in the last 7 days
1,000 stories
Oct 5, 2025·BankInfoSecurity
Hospital Sisters Health System (HSHS) has settled a class action lawsuit for $7.6 million following a cyberattack that affected the personal health information of nearly 900,000 individuals. The settlement includes financial compensation for those impacted, with affected individuals eligible for up to $5,000 for documented losses and 24 months of free credit monitoring. While HSHS maintains it did not commit any wrongdoing, the lawsuit highlights significant concerns about data security negligence in healthcare systems. This case underscores the ongoing risks of cyber threats to healthcare organizations and the importance of strengthening data protection measures to safeguard patient information.
Oct 5, 2025·Epic.org
The Maryland Online Data Privacy Act (MODPA), effective October 1, 2025, implements stringent restrictions on the collection and misuse of personal data, setting a new standard for state privacy legislation. Championed by Delegate Sara Love and Senator Dawn Gile, this law requires companies to align their data collection practices with consumer expectations and prohibits the sale of sensitive information. The act marks a significant shift away from lax, industry-favorable laws, offering Maryland residents some of the most robust privacy protections in the nation. Its implications could encourage other states to adopt similar measures, enhancing privacy safeguards for individuals nationwide.
Oct 5, 2025·Security Magazine
The increasing adoption of AI technologies by organizations aiming to stay competitive is leading to significant cybersecurity risks due to insufficient risk assessments and rushed deployments. Regulatory bodies globally are responding with new legislation, such as the U.S. Cyber Trust Mark and Europe's Cyber Resilience Act, which impose strict compliance requirements for AI security and aim to set international standards. These measures highlight the urgent need for enhanced cybersecurity practices in healthcare and beyond, as organizations face substantial risks if they do not effectively manage these technologies and their associated third-party vulnerabilities. The ongoing challenges in safeguarding AI systems underscore the critical importance for healthcare professionals to prioritize cybersecurity in their operational strategies.
Oct 5, 2025·CSO Online
Oracle E-Business Suite users are under attack from a spear-phishing extortion campaign linked to the Cl0p ransomware group, with ransom demands reaching as high as $50 million. Researchers have noted that attackers are leveraging previously patched vulnerabilities and sophisticated tactics, including email compromise and password-reset exploitation, targeting executives to pose a significant risk to organizations. Oracle is investigating these incidents, emphasizing the need for enhanced security measures such as multi-factor authentication and restricted access to portals. For healthcare professionals, this underscores the importance of robust cybersecurity practices to protect sensitive data within ERP systems against escalating threats.
Oct 1, 2025·TechRadar
Archer Health, a US provider of in-home and palliative care services, recently suffered a major data breach that exposed about 145,000 sensitive patient records due to an unprotected database. The compromised information included personal identifiers such as Social Security Numbers, medical diagnoses, and contact details, highlighting significant vulnerabilities in data security practices for healthcare providers. This incident underscores the urgent need for enhanced cybersecurity measures in the healthcare sector, particularly for organizations handling sensitive patient data. The breach not only risks patient privacy but also could undermine trust in healthcare systems that rely heavily on data integrity and security.
Oct 1, 2025·Cybersecurity Dive
Nearly 50,000 Cisco firewall devices are at risk due to vulnerabilities disclosed by the Shadowserver Foundation, leading to an emergency patching order from the Cybersecurity and Infrastructure Security Agency (CISA). The discovered flaws, CVE-2025-20362 and CVE-2025-20333, involve improper validation of HTTPS requests, allowing potential unauthorized access to security-critical VPN resources. With the U.S. hosting the majority of unpatched devices, healthcare professionals must address these vulnerabilities swiftly, as exploitation could facilitate severe cyberattacks on sensitive patient data and healthcare infrastructure. CISA has mandated that federal agencies confirm mitigation efforts by the week's end, emphasizing the immediate need for action in the healthcare sector.
Oct 1, 2025·The Hacker News
A recent survey of 282 security leaders reveals that Security Operations Centers (SOCs) are overwhelmed by an unsustainable volume of alerts, averaging 960 daily, with larger enterprises experiencing over 3,000. This alert fatigue is a significant operational risk, resulting in 40% of alerts going uninvestigated and leaving critical threats undetected. As traditional SOCs struggle with staffing shortages and burnout, the study highlights the essential role of AI-powered solutions in managing alert volumes and improving response times in security operations. These findings underscore the urgent need for healthcare professionals to integrate advanced technologies to enhance cybersecurity resilience in a digitally evolving landscape.
Oct 1, 2025·Statescoop
The Cybersecurity and Infrastructure Security Agency (CISA) has concluded its cooperative agreement with the Center for Internet Security, ending a significant partnership that supported state and local government cybersecurity efforts. This shift may indicate a reduction in federal backing for essential cybersecurity resources, following earlier funding cuts to crucial initiatives like the Elections Infrastructure ISAC. Consequently, the Center is altering its membership model to include fees based on operating budgets, potentially limiting access for some agencies. Healthcare professionals should be aware that diminished federal support could impact the cybersecurity landscape, emphasizing the need for local governments to seek alternative resources for protecting sensitive health data.
Sep 29, 2025·BBC
A recent encounter involving BBC cyber correspondent Joe Tidy exposed the alarming risk of insider threats in organizations as he was approached by a criminal gang proposing a partnership to hack the BBC. The criminal group, known as Medusa, demonstrated how they lure insiders by offering financial rewards for access to sensitive systems, highlighting that they have successfully manipulated employees at other entities, including a UK healthcare firm. This incident underscores the urgent need for healthcare professionals to bolster cybersecurity measures and employee training to prevent potential insider collaborations with cybercriminals, particularly as ransomware attacks become increasingly sophisticated and targeted. The implications stress that vigilance against such threats is crucial to safeguard sensitive information in the healthcare sector amidst rising cyber threats.
Sep 29, 2025·Cybersecurity Dive
The Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent directive for U.S. agencies to address serious vulnerabilities in Cisco networking products that are being exploited by sophisticated hackers in a campaign related to the previously identified "ArcaneDoor" operation. This situation highlights the pressing need for healthcare organizations, which often rely on similar technologies, to prioritize cybersecurity measures to protect sensitive data and maintain operational integrity. Cisco has been actively working with federal agencies to address these breaches and urges all customers to update their devices to close gaps that could be exploited. CISA's directive underscores the critical nature of cybersecurity preparedness in the healthcare sector, where delays in action could lead to significant risks.
Sep 29, 2025·Health Exec
A lawsuit against Ascension Health, stemming from a ransomware attack that compromised the personal data of 5.6 million patients, is advancing in court, highlighting the critical importance of robust cybersecurity protocols in healthcare. The U.S. District Court for the Eastern District of Missouri has found enough evidence of potential negligence regarding HIPAA violations, while dismissing claims of contractual breaches. This case underscores the significant legal and financial implications for healthcare organizations failing to adequately protect patient information, bringing attention to the real-world consequences of data breaches on patient safety and privacy. As the legal proceedings continue, healthcare professionals must prioritize data security to mitigate risks associated with cyber threats.
Sep 28, 2025·Forbes
By 2026, cybercrime is expected to become the world's third-largest economy, valued at $20 trillion, fueled by the evolution of AI and quantum computing technologies. These advancements will enable both sophisticated cyber attacks and enhanced defense mechanisms, yet humans will continue to be the weakest link in cybersecurity. The rise of ransomware-as-a-service and deepfake technology will empower even non-technical criminals to exploit vulnerabilities, necessitating a stronger focus on human-centric security training within organizations. Furthermore, the advent of quantum computing threatens existing encryption methods, prompting urgent action to safeguard sensitive information against imminent threats.
Sep 28, 2025·Cybersecurity Dive
Google has revealed that sophisticated hackers affiliated with the Chinese government, identified as the group UNC5221, are targeting technology companies and legal firms with stealthy malware. These attacks focus on infiltrating the networks of service providers to gather sensitive information regarding U.S. national security and trade, marking a troubling evolution in cybersecurity threats that recall the infamous SolarWinds incident. The malware, known as Brickstorm, is notably effective against systems lacking endpoint detection, raising significant concerns about the security of healthcare technology infrastructures. This development underscores the urgent need for healthcare professionals to enhance their cybersecurity measures to protect sensitive patient and institutional data from geopolitical risks.
Sep 25, 2025·Cybersecurity Dive
A recent report by CyberCube highlights the risks facing the cyber insurance market, primarily due to its concentration in the United States, where it could reduce potential losses by 40% through geographic and industry diversification. This heavy reliance on a few dominant players, particularly in the technology sector, poses significant risks, akin to those seen in natural disaster insurance, where localized threats can impact broad swathes of the market. The report underscores the urgency for healthcare professionals and insurers to adopt strategic risk management practices, including robust patch management, to safeguard against escalating cyber threats. This shift is essential to enhance resilience against catastrophic events and ensure stability in an increasingly digital healthcare environment.
Sep 24, 2025·krebsonsecurity.com
U.S. prosecutors have charged 19-year-old Thalha Jubair, a U.K. national, for his role in the Scattered Spider cybercrime group, which is implicated in extorting at least $115 million through ransomware attacks on various sectors, including U.S. healthcare. Alongside 18-year-old Owen Flowers, Jubair faces accusations of hacking multiple large retailers and the London transit system, highlighting the serious threat that cybercrime poses to essential services. His previous associations with other infamous hacking groups, such as LAPSUS$, underscore the increasing sophistication and interconnectedness of cyber threats in healthcare and other critical industries. This case serves as a stark reminder of the ongoing need for robust cybersecurity measures in protecting sensitive data from cybercriminals.
Sep 23, 2025·Infosecurity Magazine
Three major cybersecurity vendors—Microsoft, SentinelOne, and Palo Alto Networks—have withdrawn from the 2025 MITRE Engenuity ATT&CK Evaluations, raising concerns about the program's future impact and credibility. This decision, particularly notable for Microsoft, which previously leveraged its participation as a marketing point, reflects a potential shift in the industry's perception of such evaluations as primarily promotional rather than genuinely improving security efficacy. As the ATT&CK framework continues to evolve since its inception in 2015, MITRE's CTO expressed that the changing nature of the tests should not be viewed as a consistent benchmark. For healthcare professionals, this development signals a critical juncture in assessing cybersecurity product reliability and could influence the adoption strategies for endpoint detection and response solutions.
Sep 23, 2025·Futurism
The emergence of SMS blasters, devices that can send up to 100,000 phishing texts per hour by impersonating legitimate cell towers, represents a troubling advancement in mobile scams. These devices operate by connecting nearby phones to a downgraded 2G network, allowing them to bypass mobile providers' safeguards, which complicates detection and prevention efforts. With scammers increasingly employing these tactics, healthcare professionals must remain vigilant against potential security breaches that can lead to compromised patient data and fraudulent communications. This trend underscores the urgent need for enhanced cybersecurity measures within healthcare technology frameworks to protect sensitive information from evolving threats.
Sep 22, 2025·Cybernews
Goshen Medical Center in eastern North Carolina has reported a significant data breach affecting 456,385 individuals, attributed to a cyberattack on February 15, 2025. The breach involved unauthorized access to sensitive information, including Social Security numbers and medical records, prompting heightened concerns about cybersecurity in the healthcare sector. This incident is notable for being the third-largest ransomware attack on a U.S. healthcare organization, reflecting an alarming trend of increasing attacks targeting sensitive healthcare data. Experts emphasize the urgent need for enhanced cybersecurity measures in healthcare institutions to protect against future threats.
Sep 22, 2025·University of California San Diego
A study involving 19,500 employees at UC San Diego Health found that current cybersecurity training programs are largely ineffective at reducing employee susceptibility to phishing scams. Despite implementing both mandated annual training and embedded phishing training, there was no significant difference in phishing susceptibility between employees who completed the training and those who did not. This highlights a critical challenge in the healthcare sector, where data breaches are on the rise, emphasizing the need for more engaging and effective cybersecurity training strategies to protect sensitive information. With over 725 major incidents reported in 2023 alone, healthcare organizations must re-evaluate their training methods to better defend against this persistent threat.
Sep 21, 2025·DWT Privacy & Security Law Blog
The Cybersecurity & Infrastructure Security Agency (CISA) has delayed the implementation of its cyber incident reporting rule for critical infrastructure operators until May 2026, shifting the timeline from the previously expected October 2025 release. This regulation, mandated by the Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) of 2022, requires timely reporting of cyber incidents to CISA, which is essential for strengthening national cybersecurity. The postponement comes amidst substantial criticism from industry stakeholders and lawmakers who argue that the proposed definitions, particularly regarding "covered entities," may be too broad and potentially exceed the statute's intent. This situation highlights ongoing tensions between regulatory frameworks and industry practices in managing cybersecurity risks effectively within healthcare technology and other critical sectors.