Search site
Find podcasts, news, articles, webinars, and contributors in one search.
Health IT News
Browse by topic
Most-read stories in the last 7 days
1,000 stories
Jul 27, 2025·The Record
The FBI has raised alarms about a cybercriminal organization called The Com, primarily composed of English-speaking minors involved in various illegal activities, including ransomware and swatting. With a membership that has rapidly expanded, this group has developed sophisticated methods to conceal operations and launder money, posing a significant threat to corporations and critical infrastructure. Notably, subgroups like Scattered Spider have executed high-profile attacks against major companies, illustrating the evolving complexity and reach of cybercrime. Healthcare professionals must be aware of these threats as the industry increasingly relies on digital systems, making it a target for similar cybercriminal exploits.
Jul 27, 2025·Cybersecurity Dive
Clorox is suing Cognizant for $380 million following a significant cyberattack in 2023, attributed to the hacking group Scattered Spider, that disrupted its production and distribution operations. The lawsuit claims Cognizant's negligence in IT security protocols and improper handling of security credentials allowed the breach to occur, which Clorox argues extended their recovery time. This case highlights the critical importance of robust cybersecurity measures and protocols in IT service management, particularly for companies in the consumer goods sector. Healthcare professionals should take note of the implications for vendor accountability in cybersecurity, as breaches can severely affect operations and public trust.
The U.S. Department of the Treasury has sanctioned three North Koreans and their company, Korea Sobaeksu Trading Co., due to their role in remote IT worker scams that fund the country's nuclear program. The targeted individuals are accused of raising money through schemes that exploit vulnerabilities in U.S. companies, potentially compromising sensitive data and proprietary information. This crackdown highlights the growing threat posed by North Korean IT professionals infiltrating global markets and has prompted U.S. officials to enhance their efforts to thwart such operations. For healthcare technology professionals, this situation underlines the critical need for robust cybersecurity measures to protect against foreign threats and ensure the integrity of sensitive health data.
Jul 24, 2025·Healthcare IT News
Healthcare organizations are being warned to strengthen their cybersecurity measures against Interlock, a ransomware group known for targeting critical infrastructure via sophisticated phishing schemes. A joint advisory from multiple federal agencies underscores the urgency of this threat, as Interlock utilizes advanced tactics, such as the ClickFix technique, to deploy remote access trojans and execute double extortion strategies. The group’s evolving methods, which include disguising malware as security updates, have already led to significant service disruptions in North America and Europe. This highlights the imperative for healthcare professionals to prioritize cybersecurity protocols to protect sensitive patient data and maintain operational integrity.
Jul 24, 2025·Bloomberg
A recent cyberattack on Microsoft SharePoint has resulted in a breach of the US National Nuclear Security Administration (NNSA), indicating vulnerabilities in commonly used software systems within government agencies. Although no sensitive or classified information was reportedly compromised, the incident raises significant concerns regarding cybersecurity in critical sectors, particularly national security. This breach underscores the urgent need for enhanced cybersecurity protocols to safeguard vital information and protect against the evolving landscape of cyber threats. Healthcare professionals, working with sensitive patient data and similar technologies, should take heed of these lessons to bolster their own data protection strategies.
Jul 24, 2025·Cybersecurity Dive
The Trump administration's newly unveiled "AI action plan" focuses on enhancing cybersecurity measures against emerging threats associated with artificial intelligence. The initiative aims to support critical infrastructure operators in protecting their AI systems from potential adversarial attacks as AI integration increases. Key aspects include the establishment of an information sharing and analysis center (ISAC) dedicated to AI and a directive for the Department of Homeland Security to create guidance on mitigating AI vulnerabilities. This action plan underscores the urgency for healthcare professionals and other sectors to adapt their security protocols in response to the evolving risk landscape posed by advanced AI technologies.
Jul 24, 2025·Cyberscoop
Data from cybersecurity sensors monitoring critical infrastructure is currently unanalyzed due to an expired government contract, raising concerns over vulnerabilities in operational technology (OT). During a recent House Homeland Security hearing, Lawrence Livermore National Laboratory's program manager emphasized the necessity of the CyberSentry program for detecting hidden threats, underscoring its integration of research with practical application. Although confirmed as operational by CISA, the lack of government funding has severely restricted the analysis of threat data, potentially compromising national security. This situation highlights the critical need for timely funding and support for cybersecurity initiatives in healthcare and other essential sectors.
Jul 23, 2025·404 Media
A recent security breach involving Amazon's AI assistant 'Q' for VS Code has highlighted significant vulnerabilities in AI-driven tools. A hacker inserted damaging commands into the AI's code, which were unfortunately distributed to users, raising concerns about the reliance on automated updates and the security measures of major tech companies. This incident emphasizes the urgent need for enhanced security protocols in the development and deployment of AI technologies, as even industry leaders like Amazon can fall victim to breaches. The situation also prompts important discussions about tech company accountability and user trust in the safety of their products.
Jul 23, 2025·Secure World
Artificial intelligence (AI) and machine learning (ML) are increasingly used in critical systems but introduce new risks through adversarial AI, which manipulates AI models to produce incorrect outputs. These attacks exploit the decision-making processes of AI, leading to serious implications such as failures in self-driving technology and biases in fraud detection. The various types of adversarial attacks—including prompt injection and data poisoning—highlight the complexity of safeguarding AI systems against such threats. Healthcare professionals must be aware of these risks as they adopt AI technologies, ensuring robust cybersecurity measures to protect sensitive data and maintain the integrity of AI-driven decisions.
Jul 22, 2025·paulconnelly.substack.com
Cybersecurity is evolving beyond traditional methods of user awareness training to address the growing complexities of cyber threats, particularly those driven by AI. The Human Risk Management (HRM) approach captures a holistic view of individual employee behaviors by integrating diverse data sources and creating tailored risk profiles. This allows organizations to implement risk-informed training and controls that are adaptive to both the individual and the continuously changing threat landscape. For healthcare professionals, embracing HRM can enhance cybersecurity maturity and significantly reduce human-related risks, promoting a culture of safety and proactive response within their organizations.
Jul 22, 2025·Becker's Hospital Review
In July 2024, a software failure of CrowdStrike's Falcon cybersecurity system caused significant technology disruptions across over 750 U.S. hospitals, revealing vulnerabilities in healthcare IT infrastructure. A study from the University of California San Diego found that 34% of hospitals experienced a loss of responsiveness in internet-connected services, impacting crucial patient care functions, including access to health records and imaging. With median downtime of about five hours and some outages lasting over 48 hours, the incident underscores the pressing need for robust cybersecurity measures and contingency planning in healthcare technology. This disruption highlights the potential consequences of IT failures on patient safety and operational efficiency, urging healthcare professionals to prioritize resilience in digital systems.
Jul 21, 2025·BankInfoSecurity
In 2025, two major data breaches at healthcare organizations exposed the protected health information (PHI) of over 3.3 million patients, raising alarms about data security in the healthcare sector. Anne Arundel Dermatology and Radiology Associates of Richmond reported breaches affecting 1.9 million and 1.42 million individuals, respectively, with serious concerns about unauthorized access to sensitive patient information. These incidents, among the largest of the year according to the HIPAA Breach Reporting Tool, highlight the ongoing vulnerabilities in healthcare data protection and have led to multiple proposed class action lawsuits against the affected providers. The breaches underscore the urgent need for improved cybersecurity measures within healthcare systems to safeguard patient information and maintain public trust.
Jul 21, 2025·Reuters
Microsoft has issued a warning about a significant cyberattack targeting its server software, which exploits vulnerabilities that could lead to unauthorized access to sensitive data. The attack is believed to be the work of a sophisticated group, prompting Microsoft to urge affected organizations to apply available patches and updates immediately to protect against potential data breaches. This incident highlights the increasing threat of cyberattacks on critical infrastructure, emphasizing the necessity for healthcare professionals and organizations to implement robust cybersecurity measures and maintain regular software updates to safeguard sensitive information. As reliance on digital systems grows, the implications for healthcare technology are substantial, necessitating a proactive approach to cybersecurity to prevent future incidents.
Jul 21, 2025·Security Affairs
Anne Arundel Dermatology, a major dermatology group in Maryland, reported a data breach that potentially affected the personal and health information of 1.9 million individuals over a three-month period. Upon discovery of the intrusion, the organization promptly secured its systems and began an investigation, revealing that sensitive data files had been accessed. While there is currently no evidence of data misuse, the incident highlights significant vulnerabilities in healthcare data security protocols and underscores the need for enhanced protective measures to safeguard patient information. Healthcare professionals must remain vigilant and proactive in managing data breaches to protect patient privacy and trust.
Jul 20, 2025·Health Exec
A report from Fortified Health Security reveals that 92% of healthcare organizations faced cyberattacks last year, with 70% of these incidents resulting in delayed patient care. The study notes that legacy technology continues to pose significant risks, as many organizations still rely on outdated systems despite increased attention and funding for cybersecurity. Additionally, ineffective risk management strategies, including poor supply chain monitoring and insufficient staff training, exacerbate vulnerabilities. The findings highlight the urgent need for healthcare professionals to prioritize robust cybersecurity measures, including the decommissioning of obsolete technologies and adherence to established frameworks like NIST.
Jul 20, 2025·KWCH
Susan B. Allen Memorial Hospital in El Dorado is investigating a potential cyberattack that disrupted patient scheduling due to unusual network activity, prompting the engagement of a third-party cybersecurity team. This incident underscores a growing trend of cyberattacks affecting healthcare institutions nationally, posing risks not only to operational efficiency but also to patient data security. Experts highlight that healthcare providers are increasingly targeted for their financial vulnerability, particularly those holding cybersecurity insurance. As the investigation proceeds, the hospital has committed to informing patients if their personal information has been compromised.
Jul 17, 2025·GovTech
The Multi-State Information Sharing and Analysis Center (MS-ISAC), crucial for bolstering cybersecurity among state and local governments, faces potential defunding due to recent legislative changes which could end its federally supported free services. Established in 2003 and strengthened by federal support, MS-ISAC's role is particularly significant as it transitions to state-level cybersecurity leadership, encouraged by an executive order from President Trump. While states like Texas, Nevada, and New Jersey are stepping up to develop their own cybersecurity strategies, the removal of federal funding raises concerns about the sustainability and effectiveness of these initiatives. Healthcare professionals must consider the implications of this shift, as robust cybersecurity measures are essential for protecting sensitive patient data in an increasingly digital health landscape.
Jul 17, 2025·Becker's Hospital Review
Cookeville Regional Medical Center in Tennessee is currently facing a suspected ransomware attack that has led to a network outage, impacting their IT systems since July 13. Although patient care remains unaffected, there have been scheduling delays, highlighting the challenges healthcare facilities face in maintaining operations during cybersecurity incidents. The hospital's Chief Information Officer stated that they are thoroughly investigating the breach and working with external experts to assess potential data compromise, underscoring the critical need for robust cybersecurity measures in the healthcare sector. This incident serves as a reminder for healthcare professionals to prioritize cybersecurity protocols to protect sensitive patient information.
Jul 16, 2025·scworld.com
The Q3 2025 "CISO Top 10" rankings from CyberRisk Collaborative reveal a significant shift in the role of Chief Information Security Officers (CISOs) from merely overseeing technical operations to a broader focus on enterprise risk governance. Key priorities have emerged, including Business Continuity, Crisis Management, and real-time Governance, Risk, and Compliance (GRC), driven by rising geopolitical tensions and the demand for effective data privacy measures. This evolution underscores the need for CISOs to translate technical risks into business value and collaborate closely with various departments, particularly in the face of complex regulatory environments. For healthcare professionals, these insights stress the critical integration of cybersecurity into organizational governance, particularly as digital transformation accelerates.
Jul 16, 2025·BleepingComputer
Google recently released a security update for its Chrome browser to address several vulnerabilities, including a critical zero-day flaw, CVE-2025-6558, which has been actively exploited. This high-severity vulnerability poses significant risks by allowing attackers to bypass Chrome's sandbox security, potentially leading to arbitrary code execution in the browser's GPU process. The issue stems from inadequate validation of untrusted input in ANGLE, an open-source graphics component, highlighting the potential dangers of integrating third-party technologies in browser environments. Healthcare professionals and organizations should prioritize keeping their browser software up-to-date to mitigate such security threats that can jeopardize sensitive data.