Search site
Find podcasts, news, articles, webinars, and contributors in one search.
Health IT News
Browse by topic
Most-read stories in the last 7 days
1,000 stories
Aug 7, 2025·BleepingComputer
In Summer 2025, healthcare facilities faced a dramatic surge in cyberattacks, particularly ransomware assaults, which exploited their reliance on operational continuity and valuable patient data. The rise of sophisticated threats, such as the Interlock group's "FileFix" launcher and tactics from groups like Rhysida and Qilin, illustrated vulnerabilities in healthcare cybersecurity, emphasizing the urgent need for enhanced protective measures. As cybercriminals expanded their focus beyond healthcare to include major retail and insurance firms, the evolving tactics showcased the broader implications of cyber threats for all sectors, thereby underscoring the necessity for healthcare professionals to prioritize cybersecurity. Amidst this turmoil, the involvement of nation-state actors further complicated the landscape, signaling a critical moment for healthcare technology stakeholders to reassess their defense strategies against increasingly coordinated digital threats.
Aug 7, 2025·HIPAA Journal
Dental Group of Amarillo in Texas and Heart South Cardiovascular Group in Alabama recently agreed to settle class action lawsuits over data breaches: Dental Group of Amarillo will pay $1 million, and Heart South will pay $500,000 to resolve claims. The breach at Dental Group of Amarillo involved unauthorized access in October 2023 that potentially exposed protected health information of 3,821 patients, and delays in breach notification prompted legal action. Under the settlement, Dental Group of Amarillo will fund reimbursements - up to $5,000 per claimant for documented losses or pro rata cash payments (~$125 each) - alongside three years of credit and identity monitoring; deadlines include objections by September 29, 2025 and claims by October 13, 2025. Heart South Cardiovascular Group’s settlement covers up to $5,000 in documented out‑of‑pocket losses per claimant, two years of identity protection services, and pro rata cash payments (around $50 each), with objection/opt‑out and claim deadlines set for September 9 and October 9, respectively.
Aug 7, 2025·statescoop.com
The Department of Homeland Security's final year notice of funding for the $1 billion State and Local Cybersecurity Grant Program includes a controversial ban on using grant funds for services provided by the Multi-State Information Sharing and Analysis Center (MS-ISAC), which has historically offered critical cybersecurity resources. This restriction emerges as MS-ISAC faces potential funding cuts and aims to implement a subscription model to sustain its operations. As state and local governments grapple with escalating cyber threats, the shift away from MS-ISAC may impact their access to essential cybersecurity intelligence and support, raising concerns about overall readiness and resilience in responding to cyber incidents. The situation underscores the need for effective funding strategies and public-private partnerships in enhancing cybersecurity frameworks at all levels of government.
Aug 6, 2025·cleveland.com
Ohio has implemented new cybersecurity regulations for local governments aimed at enhancing defenses against rising cyberattacks, including ransomware incidents affecting cities like Cleveland. The regulations require local authorities to establish cybersecurity policies and mandate public approval for any ransom payments, promoting transparency and accountability in financial dealings with cybercriminals. This approach is designed to deter hasty decisions regarding ransom payments and to encourage local governments to invest in robust cybersecurity measures, contributing to broader efforts to combat cybercrime. As attacks on government entities continue to grow in frequency and complexity, these regulations represent a critical step in strengthening the resilience of municipal operations against cyber threats.
Aug 5, 2025·Ars Technica
AI search engine Perplexity is facing accusations of violating web norms by using stealth tactics to bypass restrictions set by websites through robots.txt files and firewalls. Cloudflare's investigation revealed that when Perplexity was blocked, it deployed a stealth bot employing various methods, including rotating IP addresses, to continue scraping content from tens of thousands of domains. This behavior raises significant concerns regarding adherence to the Robots Exclusion Protocol, which is designed to protect website owners' rights and data integrity. For healthcare technology professionals, this situation underscores the importance of robust data governance and the potential vulnerabilities associated with automated content scraping.
Aug 5, 2025·arstechnica.com
Microsoft's recent decision to extend free security updates for Windows 10 until 2026 is contingent on users having a Microsoft Account, a strategy designed to facilitate a smoother transition to Windows 11. This initiative not only reinforces Microsoft's ecosystem but also promotes the Windows Backup feature, which simplifies data and settings migration for users upgrading to the newer operating system. As healthcare professionals increasingly rely on secure technologies, the implications are significant; organizations must consider the necessity of updating their systems and transitioning to newer platforms to ensure ongoing security and functionality. The shift emphasizes the importance of digital adaptation in healthcare environments, where data protection and system integrity are paramount.
Aug 5, 2025·Axios
Recent research by Microsoft and OpenAI reveals that hackers associated with China, Iran, North Korea, and Russia are increasingly using AI chatbots to enhance their cyber operations, such as crafting phishing emails and researching potential targets. This marks a notable evolution in cyber threat tactics, with implications for healthcare professionals who must be vigilant against more sophisticated attacks. Specific examples include Russian and North Korean groups leveraging large-language models (LLMs) for military research and targeted phishing, highlighting the pressing need for healthcare organizations to bolster their cybersecurity measures. The findings underscore ongoing concerns among experts regarding the intersection of AI technology and cybercrime, necessitating a proactive response in the healthcare sector to protect sensitive data.
Aug 4, 2025·cybersecuritydive.com
Unmonitored artificial intelligence (AI) tools, commonly known as "shadow AI," are increasing the financial impact of data breaches in organizations, as detailed in a recent IBM report. One in five companies experienced a cyberattack linked to shadow AI, with breaches costing an average of $670,000 more than those with minimal AI involvement. The report highlights a critical gap in security practices, noting that 97% of organizations facing AI-related breaches lacked adequate access controls, thus emphasizing the urgent need for improved governance and security measures, such as zero-trust frameworks, to protect healthcare technology. As AI tools become more integrated into healthcare systems, addressing these vulnerabilities is essential to safeguard patient data and organizational integrity.
Aug 3, 2025·Help Net Security
Rural hospitals and clinics are increasingly at risk of cyber threats due to tight budgets, limited IT staff, and outdated technology, leaving them vulnerable to sophisticated attacks. A recent report indicates that 73 percent of rural healthcare leaders struggle with maintaining HIPAA compliance, while 88 percent lack confidence in the compliance capabilities of their email platforms. Moreover, rural providers are 22 percent behind their urban counterparts in adopting AI-based threat detection technologies, underscoring a critical need for improved cybersecurity measures. Addressing these vulnerabilities is vital, as these institutions serve approximately 60 million Americans and face significant challenges in delivering efficient care.
Aug 3, 2025·Saanya Ojha's Newsletter
In the evolving landscape of enterprise AI adoption, Chief Information Security Officers (CISOs) are increasingly managing AI technologies that often infiltrate organizations informally through various channels. This shift has led to a more proactive approach in policy-making, requiring CISOs to adapt existing data classification frameworks to accommodate AI, while also grappling with the risks of scope creep as these tools expand beyond their intended uses. The discussion among security leaders reflects a broader debate about balancing tight monitoring with a strategic approach to inevitable technology growth, similar to early cloud adoption experiences. To navigate this complexity, forward-thinking companies are creating AI sandboxes to safely experiment with new tools, highlighting the need for clear guidelines as they transition from experimentation to full deployment.
Jul 31, 2025·CNET
Microsoft is discontinuing password management in its Authenticator app and transitioning users to passkeys, which will take effect starting Friday. This move shifts the authentication landscape towards biometric data and device-specific PINs, offering a more secure alternative to traditional passwords. The use of passkeys, which employs public key cryptography, significantly mitigates risks associated with hacking, including phishing and brute-force attacks, as they are not stored on servers. This transition underscores the growing emphasis on security in healthcare technology, as providers seek to protect sensitive patient data and streamline user authentication processes.
Jul 31, 2025·cybersecuritydive.com
The Cybersecurity and Infrastructure Security Agency's Joint Cyber Defense Collaborative (JCDC) faces a significant operational setback following the termination of a key contract with ICF, resulting in a drastic reduction of its contractor workforce. This loss jeopardizes the JCDC's capacity to coordinate responses to increasing cyber threats, especially from state-sponsored actors like China, as it relies heavily on contractors for essential functions. The situation underscores the vulnerabilities in the U.S. cybersecurity infrastructure, particularly in light of rising cyberattacks. CISA is responding to the challenge by accessing emergency funds to retain some contractors temporarily, but the long-term implications for cybersecurity preparedness remain concerning for healthcare professionals and other sectors reliant on robust defense mechanisms.
Jul 31, 2025·BankInfoSecurity
Two Florida law firms, Zumpano Patricios PA and LaBovick Law Group, have reported significant data breaches affecting over 282,000 individuals, highlighting urgent cybersecurity concerns in healthcare-related legal practices. ZP Law's breach potentially compromised the health information of nearly 280,000 people, while LaBovick's incident involved the ransomware exfiltration of data from 2,825 individuals. These breaches underline the critical need for robust cybersecurity measures in law firms managing sensitive healthcare data, as such vulnerabilities can lead to severe consequences for both individuals and the healthcare system. Healthcare professionals must recognize the importance of partnering with law firms that prioritize data security to protect patient information effectively.
Jul 31, 2025·Becker's Hospital Review
Oracle Health, formerly Cerner, has reported significant data breaches affecting health systems in Texas, South Carolina, and California, revealing vulnerabilities in legacy electronic health record (EHR) systems. Over 4,000 individuals in Texas and nearly 3,000 in South Carolina had their sensitive information compromised, including names, Social Security numbers, and medical records. Discovered in March, the breach allowed unauthorized access dating back to January, with notifications to affected patients delayed due to an ongoing federal investigation. This incident underscores the critical need for healthcare organizations to strengthen their cybersecurity measures, particularly for outdated systems that may lack robust protections against data breaches.
Jul 30, 2025·SecurityWeek
The latest IBM report reveals that the average cost of data breaches in the U.S. has surged to $10.22 million, underscoring the escalating financial impact of cyberattacks on organizations. Rising expenses are attributed to increasingly sophisticated attacks and the need for compliance with a growing regulatory framework, emphasizing the critical need for enhanced cybersecurity measures. The report highlights that rapid breach identification and response can significantly reduce costs, pointing to the importance of efficient incident management. Additionally, it notes that while emerging technologies pose new risks, they also present vital opportunities for organizations to bolster their defenses and lower breach costs.
Jul 30, 2025·LinkedIn
The role of the Chief Information Security Officer (CISO) is evolving from a governance-centric function to one that emphasizes proactive leadership in cybersecurity. Modern CISOs are now expected to integrate security into business operations, driving transformation and ensuring that organizations can adapt to a constantly changing threat landscape. This shift necessitates a focus on resilience and recovery, urging CISOs to prepare for unexpected challenges with flexible strategies. For healthcare professionals, this underscores the critical importance of a security-first mindset that not only protects patient data but also supports overall organizational effectiveness.
Jul 29, 2025·Beckers Hospital Review
The Health Information Sharing and Analysis Center (Health-ISAC) has issued a warning regarding potential cyberattacks on U.S. and NATO infrastructure, triggered by escalating geopolitical tensions following U.S. weapons support to Ukraine. With the risk of retaliatory actions from Russia-aligned groups, the healthcare sector, while not directly part of the defense infrastructure, is highlighted as a critical component that could be affected by spillover attacks. The alert underscores the need for healthcare organizations to bolster their cybersecurity measures, as these attacks may involve sophisticated tactics such as data wiping rather than conventional denial-of-service strategies. This situation emphasizes the interconnectedness of geopolitical events and cybersecurity risks within the healthcare landscape, urging professionals to remain vigilant.
Jul 29, 2025·Cybersecurity Dive
Carnegie Mellon University and the AI firm Anthropic have revealed that large language models (LLMs) can autonomously conduct complex cyberattacks, as demonstrated through a simulated version of the 2017 Equifax breach. Their toolkit, Incalmo, successfully translated strategic elements of this breach into actionable system commands in various test environments, achieving complete compromise in half of the scenarios tested. The findings raise significant concerns for healthcare professionals about the emerging capabilities of AI in cybersecurity, highlighting the urgent need for robust protective measures to safeguard sensitive patient data against potential autonomous attacks. As LLMs demonstrate their ability to execute and manage cyberattacks without human input, the healthcare sector must prioritize the integration of advanced cybersecurity technologies and strategies.
Jul 29, 2025·SecurityWeek
NASCAR recently experienced a ransomware attack that compromised personal information, underscoring the escalating threat of cybercrime in high-profile organizations. While the specific details of the stolen data remain undisclosed, the event highlights the critical need for enhanced cybersecurity measures across all industries to protect sensitive information. As companies deal with sophisticated cyber threats, this incident serves as a cautionary tale, urging organizations to regularly evaluate and strengthen their security protocols. The ramifications of such breaches extend beyond the immediate target, raising concerns about the overarching security of personal data held by large entities.
Jul 28, 2025·cbsnews.com
A recent cybersecurity breach involving multiple U.S. federal agencies, including the Department of Homeland Security and the Department of Health and Human Services, has been linked to vulnerabilities in Microsoft's SharePoint platform and attributed to Chinese nation-state actors. The attack, which included ransomware deployment, disrupted operations at key agencies like the National Institutes of Health, underscoring the potential risks to sensitive biomedical research. In response, the White House and the Cybersecurity and Infrastructure Security Agency (CISA) are actively addressing the breach by coordinating efforts to patch vulnerabilities and enhance protective measures. This incident highlights the urgent need for healthcare technology professionals to prioritize cybersecurity in safeguarding critical health information and infrastructure.