Search site
Find podcasts, news, articles, webinars, and contributors in one search.
Health IT News
Browse by topic
Most-read stories in the last 7 days
1,000 stories
Sep 21, 2025·Cybersecurity Dive
A recent report by Netwrix reveals that healthcare organizations are facing a dramatic rise in costly cyberattacks, with incidents resulting in losses over $500,000 quadrupling since last year. Nearly half of healthcare entities reported at least one intrusion, highlighting the sector's vulnerability due to the high value of patient records and the critical need for uninterrupted operations. Additionally, the report identifies AI-powered cyberattacks as an emerging threat, emphasizing the urgent need for enhanced security measures. These findings signal a pressing challenge for healthcare professionals to prioritize cybersecurity to protect sensitive data and maintain operational integrity.
Sep 21, 2025·Wired
A recent discovery by security researcher Dirk-jan Mollema revealed two critical vulnerabilities in Microsoft Azure's identity and access management system, Entra ID, which could have allowed attackers to gain global administrator access to nearly all Azure customer accounts. These flaws were linked to Azure authentication tokens and an outdated API, posing a significant risk of impersonation and unauthorized modifications across different user environments. Microsoft acted quickly, addressing the vulnerabilities and deploying a fix within days of notification. This incident underscores the importance of robust security protocols in cloud services, highlighting the potential repercussions for healthcare organizations reliant on these technologies for patient data management and compliance.
By 2030, preemptive cybersecurity solutions are projected to account for half of all IT security spending, a significant increase from just 5% in 2024, according to Gartner. This shift is driven by advancements in artificial intelligence and machine learning, which enhance the ability to predict and neutralize cyber threats before they escalate. The anticipated rise in software vulnerabilities, from approximately 277,000 in 2025 to about one million by 2030, emphasizes the urgency for healthcare professionals to adopt proactive security measures tailored to their specific needs. As traditional detection methods become obsolete, integrating preemptive cybersecurity will be crucial for safeguarding sensitive healthcare data and ensuring operational continuity.
Sep 21, 2025·The Register
Google recently issued an emergency patch for a critical vulnerability in its Chrome browser, identified as CVE-2025-10585, which is currently being exploited. The flaw relates to a type confusion in the V8 JavaScript engine, potentially allowing attackers to execute arbitrary code or compromise systems. Discovered by Google's Threat Analysis Group, the vulnerability poses a threat from nation-state actors and spyware vendors targeting sensitive data. Healthcare professionals should prioritize updating their browsers to protect patient information and safeguard against unauthorized access, as such vulnerabilities could compromise the integrity of health-related data systems.
Sep 18, 2025·eff.org
The Ninth Circuit Court of Appeals has clarified that abandoning a smartphone does not relinquish Fourth Amendment protections regarding the data it contains, as established in the case of United States v. Hunt. The ruling emphasizes the need for courts to assess both the intent to abandon the physical device and any intentional relinquishment of privacy rights over stored data. This decision reinforces the argument made by civil liberties organizations that individuals retain significant privacy interests in their smartphones, which serve as multifaceted repositories of personal information. For healthcare professionals, this ruling underscores the importance of safeguarding patient data and understanding the legal implications of digital privacy in an era where electronic health records are increasingly vulnerable to unauthorized access.
Sep 17, 2025·health-isac.org
Microsoft's Digital Crimes Unit has seized 338 websites associated with the RaccoonO365 phishing service, a rapidly growing tool for stealing Microsoft 365 credentials, particularly affecting the healthcare industry. This disruption, authorized by a court order, cuts off cybercriminals from their victims and aims to protect sensitive data in a sector already vulnerable to cyberattacks. Notably, at least 20 U.S. healthcare organizations have been compromised, threatening patient safety and service continuity. The case underscores the urgent need for enhanced cybersecurity measures in healthcare to safeguard against such prevalent threats.
Sep 16, 2025·WSJ
The Wall Street Journal has instituted a verification process to differentiate between human users and automated bots, activated by unusual browsing patterns. Users may need to complete tasks such as visual puzzles or audio clips to gain access, with both options available to accommodate varying user needs, particularly for those with visual impairments. This measure addresses security concerns stemming from automated activity and potential technical issues, and highlights the necessity for healthcare technology platforms to ensure secure user interactions while maintaining accessibility. The implementation serves as a reminder for healthcare professionals to prioritize data integrity and user experience in their digital offerings.
Sep 16, 2025·Cybersecurity Dive
An audit by the Department of Homeland Security's inspector general has raised serious concerns about the Cybersecurity and Infrastructure Security Agency's (CISA) management of $1.4 million in retention incentives awarded to 348 employees who did not meet qualification criteria. These findings highlight the potential misallocation of resources within a critical agency, prompting discussions about the need for stricter eligibility criteria and the future of the incentive program, which staff view as vital for talent retention in cybersecurity roles. The report underscores the importance of cybersecurity knowledge across various functions, suggesting that even non-technical personnel contribute significantly to the agency's mission and public engagement. As this controversy unfolds, it could influence how healthcare organizations and other sectors implement and manage incentive programs, particularly in positions related to cybersecurity.
Sep 15, 2025·aha.org
The FBI has issued an alert regarding the growing threat from cybercriminal groups UNC6040 and UNC6395, which are targeting Salesforce platforms for data theft and extortion. UNC6040 uses voice phishing to gain access, while UNC6395 exploited compromised access tokens linked to an AI chatbot for successful breaches. The FBI recommends that organizations adhere to specific cybersecurity guidelines to protect their digital assets against these threats. This alert underscores the urgent need for healthcare professionals to reinforce their cybersecurity measures, as the potential for data compromise could have significant repercussions for patient privacy and organizational integrity.
Sep 14, 2025·FastCompany
The article discusses the far-reaching implications of cyber-disruptions, illustrated by a cyberattack on a small HVAC parts distribution company that hampered surgery operations at a local hospital. This incident emphasizes the interconnectedness of businesses and showcases how a cyber threat to one entity can cascade into a broader crisis, affecting healthcare and community services. The financial toll of these disruptions—ranging from ransom to lost business—highlights the necessity for enhanced cybersecurity measures, not just as a risk management issue but as a civic responsibility. For healthcare professionals, understanding these risks is crucial, as they underscore the importance of robust cybersecurity frameworks to ensure operational continuity and patient safety.
Sep 14, 2025·BankInfoSecurity
Federal regulators have released version 3.6 of the HIPAA Security Risk Assessment (SRA) tool, specifically designed to aid small and midsized healthcare providers in improving their risk analysis processes. This updated version incorporates recent cybersecurity guidance and user feedback, enhancing the tool's effectiveness in navigating the risk assessment workflow. As risk analysis has become a critical enforcement priority for the U.S. Department of Health and Human Services due to its role in HIPAA breaches, this tool aims to address prevalent deficiencies, ultimately strengthening the protection of patients' health information. The introduction of features like a "reviewed-by" confirmation button further underscores the tool's utility in solidifying compliance and mitigating potential vulnerabilities.
Sep 14, 2025·CyberPress
Workday has confirmed a data breach linked to the compromise of Salesloft's Drift application, resulting in unauthorized access to customer data within its Salesforce environment. Following the breach, which stemmed from anomalous activity related to the Drift integration, Workday took swift containment actions, including disabling the Drift connector and revoking OAuth tokens. An independent forensic investigation revealed that while the threat actor accessed some non-sensitive metadata, critical documents and sensitive information remained secure. This incident underscores the importance of robust security measures for third-party integrations in healthcare technology systems, as they can pose significant risks to patient and organizational data integrity.
Sep 11, 2025·CFODive
A recent report by Resilience highlights a troubling rise in the financial impact of ransomware attacks, with costs increasing by 17% in the first half of 2025, as these incidents now account for a staggering 76% of losses, up from 46% the previous year. Despite a decrease in cyber insurance claims, the average ransom demand from retail organizations has surged to $2 million, reflecting the growing sophistication of cybercriminal tactics. Conversely, recovery costs for these attacks have decreased by 40%, indicating that companies are enhancing their resilience and negotiation capabilities. For healthcare professionals, these trends underscore the urgent need for improved cybersecurity measures and response strategies to safeguard patient data and organizational assets.
Sep 11, 2025·Becker's Hospital Review
Geisinger and Microsoft's Nuance Communications have settled for $5 million following a 2023 data breach that compromised the personal information of 1.2 million patients. The breach originated from a former Nuance employee's mishandling of data on a personal laptop, prompting a class-action lawsuit. This settlement underscores the significant legal and reputational risks healthcare organizations face regarding data security, emphasizing the need for enhanced cybersecurity protocols and accountability measures to protect sensitive patient information. As the broader cybersecurity landscape continues to evolve, such incidents stress the urgency for healthcare professionals to prioritize safeguarding patient data.
Sep 11, 2025·linkedin.com
By 2025, cybersecurity is becoming a vital business function rather than merely a technical concern, as Chief Information Security Officers (CISOs) now engage directly with CEOs and boards in risk management discussions. This evolution illustrates a recognition of cybersecurity as a key component of enterprise strategy, prompting organizations to quantify cyber threats in financial terms to better justify investments. As organizations integrate cybersecurity within broader business objectives, they can enhance operational continuity and stakeholder trust. Moreover, the focus on AI governance amid the growing reliance on digital tools emphasizes the need for proactive risk management, particularly concerning supply chain and third-party vulnerabilities.
Sep 10, 2025·Beckers Hospital Review
U.S. Senator Ron Wyden has urged the Federal Trade Commission (FTC) to investigate Microsoft for alleged cybersecurity negligence linked to a ransomware attack on Ascension hospitals, resulting in disrupted surgeries and compromised data of over 5 million patients. The incident was triggered when a contractor inadvertently downloaded malware through a malicious link, exploiting a weak encryption protocol, RC4, which Microsoft still allows by default on its systems. Wyden's accusations highlight broader concerns about the adequacy of cybersecurity measures in protecting critical healthcare infrastructure. Microsoft's response, while highlighting its intent to phase out the vulnerable protocol, raises questions about current practices and their implications for safeguarding sensitive patient information.
Sep 9, 2025·Cyberscoop
National Cyber Director Sean Cairncross called for a coordinated U.S. cybersecurity strategy to alleviate cyber risks faced by Americans, moving the burden instead to potential adversaries. Speaking at the Billington Cybersecurity Summit, he noted the existing progress but underscored the necessity for decisive, strategic action rather than mere acknowledgment of the issues. The Biden administration's 2023 cybersecurity plan aims to leverage the country’s innovative capabilities—both in the private sector and academia—to not only protect domestic interests but also assist international allies against threats like China's extensive surveillance activities. This approach marks a significant shift in how cybersecurity risks are managed, emphasizing the importance of institutional responsibility over individual vulnerability in the evolving digital landscape.
Sep 9, 2025·Healthcare IT News
Rural hospitals, like Nathan Littauer Hospital in New York, face formidable cybersecurity challenges due to limited funding and small IT teams, often relying on third-party vendors that heighten their security risks. To mitigate these threats, some hospitals are forming strategic partnerships with cybersecurity firms, allowing them to implement proactive defense strategies and comply with state regulations despite financial constraints. This collaboration not only helps enhance security resilience but also ensures that hospitals can better navigate the complexities of evolving cyber threats. Effective communication about these changes is essential to avoid operational disruptions and ensure successful adoption among staff.
Sep 8, 2025·Cybernews
A reported data breach impacting 24 million AT&T users reveals alarming vulnerabilities in the company's infrastructure, with attackers claiming unauthorized access that could undermine two-factor authentication systems. This situation raises significant security concerns for healthcare technology, where safeguarding personal data is critical amidst increasing cyber threats. The breach highlights the potential for SIM-swapping attacks that could allow malicious actors to manipulate sensitive customer information, thereby posing risks not only to AT&T but also to industries handling similar data. Healthcare professionals must remain vigilant as such breaches could undermine patient trust and compromise the integrity of healthcare systems.
HexStrike AI is a sophisticated artificial intelligence framework that has been repurposed by cybercriminals to conduct rapid and efficient cyberattacks using over 150 specialized tools. Initially designed for defensive cybersecurity, it has raised alarms due to its ability to automate complex tasks, allowing attackers to exploit vulnerabilities, including zero-day flaws, in record time. Experts caution that this development poses a significant challenge for healthcare technology and security professionals, who must focus on urgent patching and system hardening to protect sensitive data. The emergence of HexStrike AI underscores the evolving threat landscape and the need for stronger cybersecurity measures in healthcare.