Search site
Find podcasts, news, articles, webinars, and contributors in one search.
Health IT News
Browse by topic
Most-read stories in the last 7 days
1,000 stories
Aug 21, 2025·GlobeNewswire
CLEAR and Tampa General Hospital (TGH) have formed a partnership to enhance workforce identity security by integrating CLEAR1, a biometric identity verification platform, into TGH's identity access management system. This collaboration aims to automate password resets and minimize manual help desk interventions, thereby improving operational efficiency and security against cyber threats. As a result, TGH has automated 80% of account recovery requests and reduced help desk call resolution times by 99%, while also implementing biometric multi-factor authentication. This initiative not only safeguards patient and staff data but also sets a precedent for innovation in healthcare security practices.
Aug 20, 2025·Business Wire
A recent report by Paubox reveals significant cybersecurity vulnerabilities among small healthcare practices in the U.S., with many mistakenly believing they are HIPAA compliant. The survey found that a majority of these organizations do not utilize adequate email encryption, leaving sensitive patient information at risk. Additionally, widespread misconceptions regarding patient consent and compliance requirements further compound security issues, with 20% of practices lacking essential email archiving or audit trails. As cybercriminals increasingly target small healthcare providers, these vulnerabilities underscore the urgent need for enhanced security awareness and training in the industry.
Aug 20, 2025·CSO Online
A recent Sophos report reveals that one in four Chief Information Security Officers (CISOs) are replaced following ransomware attacks, highlighting a troubling trend driven by board-level frustration over security failures. Experts like Erik Avakian emphasize that such firings can be counterproductive, often occurring without a proper assessment of the CISO's adherence to security protocols. This rapid turnover, coupled with CISOs' limited authority to enforce security policies, underscores the need for organizations to rethink accountability and the decision-making power of their cybersecurity leaders. Consequently, healthcare professionals must recognize the implications of these findings for optimizing their own cybersecurity leadership and resilience strategies.
Aug 20, 2025·The Register
Nuance Communications has reached an $8.5 million settlement regarding a class action lawsuit over a data breach linked to the MOVEit Transfer platform, though it denies any wrongdoing. The breach, exploited by the Clop ransomware gang, compromised the personal information of approximately 1.225 million individuals, raising concerns about the adequacy of Nuance's data security measures. Plaintiffs argued that negligence in securing data contributed to the breach, while Nuance highlighted its reliance on a widely used product and its prompt response to the incident. This case underscores the critical importance of robust cybersecurity practices in healthcare technology, particularly for companies handling sensitive personal information.
Aug 20, 2025·Tripwire
The Indian healthcare sector is experiencing a significant cybersecurity crisis, suffering from an alarming average of 8,614 cyberattacks each week, which is over four times the global average. This vulnerability has led to a 20% increase in cybercrime rates in 2024, with healthcare being one of the most targeted sectors. The rise in incidents, coupled with the critical nature of healthcare operations and the growing use of inadequately secured medical IoT devices, poses serious risks to patient safety and data integrity. As India’s cybersecurity infrastructure remains underdeveloped, healthcare professionals must prioritize enhanced security measures to protect sensitive information and ensure continuity of care.
Aug 19, 2025·BleepingComputer
Workday has experienced a data breach due to a social engineering attack on a third-party customer relationship management (CRM) platform, although the company states that customer data remains unaffected. The breach, part of a broader campaign targeting large organizations, resulted in unauthorized access to business contact information, which attackers might use for further scams. This incident highlights the rising threat of social engineering tactics in the healthcare technology space, emphasizing the need for stronger training and awareness measures among employees to safeguard sensitive information. As attackers continue to exploit vulnerabilities in CRM systems, organizations must enhance their cybersecurity protocols to mitigate such risks.
Aug 19, 2025·Bloomberg
Inotiv Inc., a contract research organization focused on drug discovery, experienced a cybersecurity breach on August 8, disrupting its business operations and compromising sensitive data. The company took immediate action by engaging cybersecurity experts and implementing restrictions to safeguard affected systems. This incident underscores the increasing risk of cyberattacks in the pharmaceutical and research sectors, emphasizing the need for healthcare organizations to adopt stronger cybersecurity protocols to protect client information and ensure the integrity of research processes. As the situation unfolds, Inotiv's response will serve as a crucial case study for the industry.
Aug 18, 2025·NPR
Otter.ai is facing a federal lawsuit for allegedly recording private conversations without proper user consent to improve its AI transcription service. The lawsuit claims that its tool, Otter Notebook, captures meetings on popular platforms like Zoom and Google Meet without notifying participants, breaching privacy and wiretap laws. This case, initiated by a California resident, highlights significant concerns about user awareness and consent in the use of AI-driven technologies in healthcare settings, particularly as the popularity of such tools continues to rise. As healthcare professionals increasingly leverage transcription services, this lawsuit underscores the critical importance of transparent privacy practices in technology adoption.
Aug 18, 2025·The Register
Cisco has issued a critical patch for a high-severity vulnerability (CVE-2025-20265) in its Secure Firewall Management Center (FMC) software, which could enable remote, unauthenticated attackers to execute arbitrary shell commands. The vulnerability stems from improper handling of user input by the RADIUS authentication subsystem when configured for web-based and SSH management. Given the widespread use of the FMC in sectors such as enterprise, government, and education, healthcare professionals should be aware of the potential risks associated with compromised network security systems that could lead to unauthorized access and data breaches. Cisco has advised users to apply the patch promptly, although no known exploits have been reported.
Aug 17, 2025·American Healthcare Leader
Gordon Groschl, the Chief Information Security Officer at Texas Children’s Hospital, plays a crucial role in aligning healthcare technology with the institution's mission to protect and save young lives. His journey from telecom to healthcare has deepened his commitment to the nonprofit's vision, as he oversees a diverse range of biomedical devices while bridging cybersecurity and biomedical engineering. In light of the increasing digitization in healthcare, Groschl's recent focus on the ethical and secure adoption of artificial intelligence highlights the critical need for vigilance in safeguarding patient data and maintaining trust in healthcare technologies. His work stands as a significant reminder of the intersection between technology and patient care, urging healthcare professionals to prioritize security amidst rapid technological advancements.
Aug 17, 2025·Dark Reading
At the Black Hat USA 2025 conference, researchers identified nine zero-day vulnerabilities in HashiCorp Vault and five in CyberArk Conjur, two essential secret management platforms used in enterprise security. These vulnerabilities pose significant risks, as they could allow attackers to compromise entire networks by exploiting flaws in authentication processes and privilege escalation methods. Notably, the weaknesses in CyberArk Conjur include an alarming authentication-less remote code execution exploit, raising urgent concerns about the integrity of sensitive information. Healthcare professionals should recognize the implications of these vulnerabilities, as they highlight critical areas for improving security measures in systems that safeguard patient and organizational data.
Aug 14, 2025·BleepingComputer
Fortinet has alerted users to a critical remote unauthenticated command injection vulnerability (CVE-2025-25256) in its FortiSIEM product, impacting versions 5.4 to 7.3. With a high CVSS score of 9.8, this flaw allows attackers to execute unauthorized commands without authentication, posing a significant risk to organizations such as healthcare providers that rely on FortiSIEM for security operations. The exploitation of this vulnerability is difficult to detect, as it doesn't produce clear indicators of compromise. Healthcare professionals should prioritize patching affected systems to mitigate potential breaches and protect sensitive data.
Aug 14, 2025·Aon
Cyber attacks represent a critical threat to the healthcare industry, which is rich in sensitive data and increasingly reliant on digital technologies. With a growing number of breaches, particularly affecting patient data and medical device safety, the sector faces severe financial and reputational risks. Challenges such as a shortage of IT talent and constrained budgets hinder the implementation of effective cybersecurity strategies, while innovations like cloud technology and telehealth applications expand exposure to potential threats. As cyber attackers increasingly target healthcare organizations, it is essential for these entities to adopt comprehensive cybersecurity measures to protect patient safety and data integrity.
Aug 14, 2025·TechRadar
The Online Safety Act in the UK has intensified discussions around age verification and its implications for privacy and encryption in digital communication. Notably, Section 122 mandates tech companies to conduct client-side scanning of private messages to identify illegal content, raising significant concerns about undermining encryption and user privacy. Messaging platforms like WhatsApp and Signal have threatened to leave the UK market in response, prompting the government to delay this controversial requirement until it is deemed technically feasible. This situation highlights a broader, global debate on balancing public safety with the integrity of secure communication technologies.
Aug 12, 2025·AHA
The Department of Justice's recent actions against the BlackSuit ransomware group, notorious for targeting critical sectors like healthcare, underscore the growing threat cybercriminals pose to patient safety. Disrupting key servers and domains used by the group reflects a significant attempt to mitigate risks associated with ransomware attacks on hospitals and health systems. Experts like John Riggi from the American Hospital Association emphasize that collaboration between public and private sectors is essential for addressing these threats effectively. As healthcare organizations navigate this landscape, they must remain vigilant and proactive to protect against ongoing cyber threats, highlighting the critical need for robust cybersecurity strategies.
Aug 11, 2025·BankInfoSecurity
Alera Group, an Illinois-based insurance brokerage, has notified around 156,000 individuals that their protected health information was compromised in a data breach that occurred between July and August 2024, with notification delays extending into 2025. The unauthorized access to their IT environment exposed sensitive personal and medical data, including Social Security numbers and medical histories, raising concerns about compliance with HIPAA regulations. Regulatory attorney Aleksandra Vold emphasizes that lengthy review processes not only squander organizational resources but also elevate the risk of regulatory penalties and public distrust. This incident underscores the critical need for healthcare organizations to streamline breach response protocols and enhance their cybersecurity measures to protect patient information effectively.
Aug 11, 2025·Cybernews
The cybersecurity industry is witnessing a paradox where financial growth contrasts with a challenging job market for professionals, particularly at junior levels. While companies are increasing investments in technology and AI-driven services, this shift has led to hiring freezes and reduced demand for entry-level roles. As organizations prioritize strategic thinkers over routine task performers, there's a risk that the reliance on automated solutions may not lead to better security outcomes, raising concerns about the effectiveness of growing subscription-based cybersecurity investments. This evolving dynamic is crucial for healthcare technology, as effective cybersecurity is vital in protecting sensitive patient data amidst growing regulatory and operational challenges.
Aug 10, 2025·Cybernews
Cookeville Regional Medical Center (CRMC) in Tennessee is dealing with the repercussions of a ransomware attack by the Rhysida group, which has disrupted its computer systems without significantly impacting patient care. The attackers have demanded a ransom of 10 Bitcoin, while the hospital's IT teams and federal law enforcement are working to resolve the situation. Although CRMC has not confirmed whether patient data was compromised, samples of sensitive information have surfaced on the attackers' leak site. This incident highlights the persistent threat of cyberattacks in healthcare, emphasizing the need for stronger cybersecurity measures and proactive patient data protection strategies.
Aug 10, 2025·SecurityWeek
Microsoft has invested $17 million in bug bounties over the past year, highlighting its commitment to enhancing cybersecurity across its software products, including Windows and Azure. This initiative encourages security researchers worldwide to identify and report vulnerabilities, resulting in improved safety and reliability for users. By fostering collaboration with independent researchers, Microsoft not only strengthens its security measures but also contributes positively to the overall cybersecurity landscape. The success of such programs indicates the critical role of partnerships between technology firms and security experts in safeguarding digital environments.
Aug 10, 2025·Cybersecurity Dive
The U.S. government's ongoing commitment to zero-trust network designs is pivotal for enhancing cybersecurity, particularly as new technologies like artificial intelligence are integrated into operations. This strategy emphasizes isolating network segments and enforcing stringent user authentication to mitigate damage from cyberattacks. Despite delays in initial timelines for adoption, federal agencies are expected to implement zero-trust principles as a critical operational framework to address emerging cyber threats. Justifying this framework, officials stress the necessity for rapid detection and response capabilities, underscoring its importance for healthcare professionals who must safeguard sensitive patient data in an increasingly digital environment.