Search site
Find podcasts, news, articles, webinars, and contributors in one search.
Health IT News
Browse by topic
Most-read stories in the last 7 days
1,000 stories
Sep 8, 2025·SecurityWeek
The United States and its allies are advocating for the adoption of Software Bill of Materials (SBOMs) to enhance cybersecurity in response to rising cyber threats and the complexities of software supply chains. SBOMs provide detailed insights into software components and vulnerabilities, promoting transparency that allows organizations to better manage associated risks. This initiative aims to establish consistent standards and guidelines, enabling software developers to integrate SBOM practices into their processes and fostering a culture of accountability within the software industry. Effective implementation of SBOMs could significantly protect critical infrastructure and reduce the risk of successful cyberattacks across various sectors in healthcare and beyond.
Sep 8, 2025·TechCrunch
X, previously known as Twitter, has launched an encrypted messaging feature named XChat that promises end-to-end encryption, but experts are raising serious security concerns. Cryptography specialists argue that XChat's approach, which involves storing users' private keys on X's servers and requiring a four-digit PIN for encryption, is significantly less secure than established platforms like Signal. Security researcher Matthew Garrett warns that this method could allow X to tamper with or gain access to private messages, particularly in the absence of robust hardware security measures. Consequently, healthcare professionals should remain cautious about adopting XChat for sensitive communications, as it may not provide the necessary security assurances for patient privacy.
Sep 7, 2025·Becker's Hospital Review
A cyberattack on Change Healthcare has delayed the implementation of a new Oracle Health electronic health record (EHR) system at the Captain James A. Lovell Federal Health Care Center, affecting the VA's broader rollout of this technology. Originally scheduled for March 2024, the testing of a critical billing interface was postponed after the ransomware attack for security reasons, necessitating the development of a replacement system that won’t be operational until November 2024. This incident highlights the significant cybersecurity risks facing healthcare organizations and raises concerns about their ability to maintain operational integrity amid increasing cyber threats, which could impact patient care and financial processes.
Sep 7, 2025·PCMag
A recent research initiative at New York University has led to the development of "PromptLock," an AI-powered ransomware that underscores the risks posed by open-source large language models in orchestrating advanced cyberattacks. This project, termed "Ransomware 3.0" by its creators, serves as a proof-of-concept illustrating how AI can automate cybercriminal activities through natural language processing, facilitating tasks such as decision-making and payload generation. Though currently non-functional outside a lab setting, the implications for healthcare technology are significant, as it raises concerns about the vulnerability of sensitive patient data to increasingly sophisticated ransomware strategies. Healthcare professionals must be aware of the potential for such technologies to exploit security weaknesses, emphasizing the urgent need for enhanced cybersecurity measures in medical environments.
Sep 7, 2025·Nextgov
The House Homeland Security Committee has approved a measure to extend the Cybersecurity and Information Sharing Act of 2015, which enables the private sector to share cyber threat intelligence with the U.S. government while providing liability protections. The proposed WIMWIG Act aims to extend the law for another ten years and is poised for consideration by the full House. However, the process has faced criticism for its rushed nature and concerns about potential censorship by the Cybersecurity and Infrastructure Security Agency (CISA). This legislative move highlights the increasing importance of cybersecurity in healthcare and the need for transparent frameworks to protect both patient data and free speech.
Sep 3, 2025·Security Affairs
Palo Alto Networks has reported a data breach linked to a supply-chain attack associated with Salesloft Drift, which compromised their Salesforce account and exposed customer data. Attackers used stolen OAuth tokens, resulting in the mass exfiltration of sensitive information, including accounts and support cases, and potentially facilitating further cyber attacks. This incident highlights the vulnerability of supply-chain systems and underscores the importance of rigorous security measures across vendor relationships in healthcare technology. As organizations like Google and Zscaler have also fallen victim, the breach serves as a critical reminder for healthcare professionals to bolster their cybersecurity protocols to protect patient and operational data.
Sep 3, 2025·StateScoop
As the State and Local Cybersecurity Grant Program approaches its expiration date on September 30, industry groups are advocating for its renewal and an increase in funding from $1 billion to $4.5 billion over two years. They argue that the program has effectively strengthened cybersecurity measures at state and local levels, which are crucial for protecting national security amid rising cyber threats from hostile nations. With significant support from key government officials and agencies, the program is positioned as a vital resource for safeguarding critical infrastructure essential to national defense. The push for expansion reflects a broader recognition of cybersecurity's importance to healthcare and other sectors reliant on secure digital operations.
Sep 2, 2025·Finance Yahoo
The generative AI cybersecurity market is expected to grow significantly from USD 8.65 billion in 2025 to USD 35.50 billion by 2031, reflecting a compound annual growth rate of 26.5%. This surge is largely driven by the increased integration of AI models and automation in various sectors, which complicates digital ecosystems and heightens vulnerability to cyber threats. Particularly within sensitive industries like healthcare, the potential compromise of AI systems poses serious operational and regulatory risks. In response, a convergence of AI and cybersecurity is emerging, with companies developing advanced security platforms that enhance the efficacy and efficiency of threat detection and response.
Sep 2, 2025·Cybersecurity Dive
The U.S. Cyber Trust Mark program, aimed at improving the security of Internet-of-Things (IoT) devices through a government-backed certification, is facing potential setbacks due to an investigation by the Federal Communications Commission (FCC) into UL Solutions, the program's overseeing entity. Concerns about UL's connections to China could delay the program, which was intended to mitigate risks associated with insecure IoT devices and encourage manufacturers to enhance their security measures. Healthcare professionals, who increasingly rely on connected technologies, may find this development concerning as it could slow the adoption of secure devices in clinical settings and compromise patient data protection. Timely implementation of the Cyber Trust Mark is crucial for reinforcing patient safety and trust in health technology.
Sep 2, 2025·uicommunityhomecare.org
On July 3, 2025, UI Community HomeCare experienced a cybersecurity breach, compromising the personal information of approximately 211,000 patients. The organization quickly shut down its servers and engaged cybersecurity experts to address the issue, successfully restoring operations within a day and minimizing disruption to patient care. Although there is currently no evidence of data misuse, UI Community HomeCare has implemented enhanced security measures, including new monitoring tools and password updates, to mitigate future risks. This incident highlights the ongoing threat of cyberattacks in healthcare and underscores the need for continuous improvement in security protocols to protect sensitive patient information.
Sep 2, 2025·Security Magazine
Microsoft's discontinuation of support for Windows 10 on October 14 presents significant challenges for healthcare organizations, as they face potential cyber vulnerabilities during the lengthy transition to Windows 11. This process can take six to nine months and is further complicated by the need to maintain compliance with HIPAA regulations. While Microsoft offers an Extended Security Updates (ESU) program, which provides necessary security patches, it lacks new features, leaving organizations reliant on cost-prohibitive strategies to manage their software environments. Healthcare professionals must act promptly to address these transitions to mitigate risks associated with outdated systems and maintain patient data security.
Sep 1, 2025·Cybersecurity Dive
Hackers targeting Salesforce customers have stolen user credentials via compromised OAuth tokens from Salesloft's Drift AI chat agent, affecting over 700 organizations. The attacks, executed between August 8 and 18, primarily aimed to harvest sensitive credentials such as AWS access keys and Snowflake tokens, without exploiting vulnerabilities in Salesforce itself. In response, Salesforce and Salesloft have acted to revoke access tokens and urged administrators to reauthenticate connections. This incident highlights significant security risks associated with third-party integrations in healthcare technology, emphasizing the need for enhanced vigilance and security protocols among healthcare professionals.
Aug 28, 2025·Healthcare IT News
The Cybersecurity and Infrastructure Security Agency (CISA) has released updated draft guidance aimed at improving Software Bills of Materials (SBOM), which serve as essential tools for software security management. Key additions, including cryptographic hashes and new required elements, enhance the transparency and integrity of SBOMs, allowing organizations to better identify and manage software vulnerabilities. This update addresses existing policy gaps by ensuring the authenticity of software components, thereby supporting more effective risk management in healthcare technology. The public is invited to comment on the guidance until October 3, highlighting the collaborative effort to bolster software security across various sectors.
Aug 28, 2025·Cybersecurity Dive
A ransomware attack in Nevada has compromised vital government services, including phone systems and agency websites, leading to a significant data breach whose specifics are not yet clear. State officials, supported by the Cybersecurity and Infrastructure Security Agency (CISA) and the FBI, are investigating the incident and working to secure and restore affected systems. Nevada's chief information officer has highlighted the importance of thorough analysis before reactivating services to ensure data safety, reflecting a pressing concern shared by many in healthcare regarding the protection of personal data amid increasing cyber threats. This incident underscores the critical need for robust cybersecurity measures in protecting public services, particularly in healthcare sectors where sensitive information is frequently at risk.
Aug 27, 2025·Aspire News and Updates
Aspire Rural Health System has reported a data security incident that may have compromised personal and protected health information of certain individuals between November 4, 2024, and January 6, 2025. While there's no evidence of financial fraud or identity theft linked to the breach, the health system has initiated proactive communication with affected parties, offering guidance on protective measures. The breach highlights the critical need for robust cybersecurity protocols in healthcare, as it involved sensitive information such as Social Security numbers and medical details. As the healthcare sector increasingly relies on digital records, ensuring data security remains a top priority to protect patient privacy and maintain trust.
Aug 26, 2025·Cybersecurity Dive
Chief Information Security Officers (CISOs) are facing heightened anxiety over cyberattack risks, with two-thirds reporting material data losses in the past year, up from 46% the previous year. The "Voice of the CISO" report, surveying 1,600 security leaders, reveals that three-quarters of CISOs fear a significant cyberattack ahead; despite confidence in their cybersecurity culture, many acknowledge their organizations are ill-prepared for such threats. This disconnect between CISOs and corporate boards, along with the willingness to pay ransoms to recover data, highlights critical vulnerabilities in business continuity planning that healthcare professionals must address to enhance organizational security. The findings emphasize the need for improved communication and preparedness as regulatory scrutiny increases in the cybersecurity landscape.
Aug 26, 2025·Cyber Security News
As students transition back to educational environments, cybercriminals are increasingly leveraging artificial intelligence to execute sophisticated scams targeting the sector. These AI-enhanced attacks, which include fake scholarships and deepfake impersonations, pose significant risks by exploiting students, parents, and educational institutions. Healthcare professionals must recognize the implications of this trend, as breaches in student data can have cascading effects on mental health and institutional trust. Consequently, there is a critical need for enhanced cybersecurity measures and education to combat the evolving landscape of AI-driven cyber threats in education.
Aug 26, 2025·Yahoo Finance
The Generative AI Cybersecurity Market is anticipated to grow from $8.65 billion in 2025 to $35.50 billion by 2031, with a compound annual growth rate of 26.5%. This surge is propelled by the widespread adoption of AI models and automation, which are also expanding the attack surface for cyber threats, particularly in sensitive sectors like healthcare. As organizations face increasingly sophisticated cyber threats, the integration of generative AI into cybersecurity measures is becoming critical for enhancing threat detection and response. Consequently, healthcare professionals must prioritize cybersecurity investments to safeguard patient data and comply with regulatory standards in an evolving digital landscape.
Aug 25, 2025·Becker's Hospital Review
Russian cybercriminals, allegedly linked to the Russian Federal Security Service, are targeting vulnerable networking devices in critical infrastructure, notably healthcare, as highlighted by a recent FBI alert. These hackers are exploiting unpatched vulnerabilities, particularly in older Cisco equipment, emphasizing the need for hospitals to prioritize the replacement of outdated technology and strengthen patch management processes. Scott Gee from the American Hospital Association has underscored the critical importance of these measures to protect against evolving cyber threats that have previously disrupted U.S. hospitals. Healthcare organizations can enhance their cybersecurity posture by utilizing resources like the U.S. Cybersecurity Infrastructure and Security Agency's catalog of known exploited vulnerabilities.
Aug 21, 2025·BankInfoSecurity
Federal regulators have repeatedly identified inadequate HIPAA security risk analyses as a major issue among healthcare organizations, often resulting in data breaches and financial penalties. The HHS Office for Civil Rights has conducted audits that reveal many entities fail to conduct thorough analyses, instead relying on outdated information or superficial reviews, leaving them exposed to vulnerabilities. Recent penalties, like a $175,000 settlement against a New York accounting firm for not identifying risks related to a ransomware breach, underscore the need for better compliance. This ongoing negligence highlights the critical importance of comprehensive risk assessments to safeguard protected health information and avoid regulatory repercussions in healthcare.