Search site
Find podcasts, news, articles, webinars, and contributors in one search.
Health IT News
Browse by topic
Most-read stories in the last 7 days
1,000 stories
Jul 15, 2025·Help Net Security
A critical SQL command injection vulnerability, CVE-2025-25257, has been identified in Fortinet’s FortiWeb web application firewall, specifically impacting the Fabric Connector. The flaw allows unauthenticated attackers to execute remote code with root privileges by exploiting improperly sanitized SQL commands within HTTP or HTTPS requests. The risk is heightened by the disclosure of proof-of-concept exploits, which could lead to widespread attacks if not addressed promptly. Healthcare professionals using this technology need to prioritize applying the issued patch and enhancing security protocols to mitigate the potential for data breaches and system compromises.
Jul 14, 2025·BankInfoSecurity
As healthcare providers increasingly adopt agentic artificial intelligence (AI) tools, understanding data privacy risks under HIPAA and related laws is essential to prevent breaches of protected health information. Attorney Jordan Cohen emphasizes that many required practices for implementing AI, such as maintaining a comprehensive data flow inventory, are not new but critical for compliance and security. The complexity of handling diverse data types in AI applications highlights the importance of legal and regulatory considerations, especially with potential updates to the HIPAA Security Rule and state privacy laws. Healthcare professionals must prioritize transparency, technical safeguards, and incident response to ensure safe and responsible use of AI technologies.
Jul 13, 2025·CyberScoop
During a recent Senate hearing on healthcare cybersecurity, Senator Bill Cassidy highlighted the need to prioritize cybersecurity amid discussions on significant funding cuts proposed in the One Big Beautiful Bill. Witnesses, including healthcare executives, warned that reduced federal support and cuts to programs like Medicaid could jeopardize the cybersecurity capabilities of already vulnerable rural and community hospitals. They emphasized that tighter budgets typically lead to diminished investment in cybersecurity, leaving healthcare providers ill-equipped to handle rising digital threats. The American Hospital Association echoed these concerns, suggesting that the cuts could result in increased uncompensated care and a deterioration in staffing and services.
Jul 10, 2025·TechTarget
In the first half of 2025, healthcare data breaches have compromised nearly 30 million records, highlighting a significant and ongoing risk to healthcare organizations and their business associates. The HHS Office for Civil Rights reported that the trend is heavily driven by hacking incidents, which accounted for nine out of the ten largest breaches, indicating a troubling shift in the cyber threat landscape. A notable breach at Yale New Haven Health System impacted over 5.5 million individuals, but thankfully did not compromise electronic medical records or patient care. This situation underscores the urgent need for healthcare professionals to enhance cybersecurity measures and protect sensitive data against increasingly sophisticated threats.
Jul 10, 2025·SecurityWeek
Yanjun Xu, a Chinese national and alleged state-sponsored hacker, was arrested in Italy at the request of the U.S. for his role in cyber-espionage targeting American aviation firms. Charged with economic espionage, Xu is accused of attempting to steal trade secrets to benefit Chinese state-owned enterprises, reflecting the escalating sophistication of state-sponsored cyber threats. His arrest highlights the necessity for international cooperation in addressing cybersecurity risks, which are becoming increasingly global in nature. This case underscores the complexities of prosecuting cyber crimes and may further strain U.S.-China diplomatic relations.
Jul 9, 2025·infosecurity-magazine.com
Ingram Micro, a prominent IT distributor, is responding to a significant ransomware attack that has disrupted its operations, affecting its website and ordering systems. The company confirmed the detection of ransomware on its internal systems and has engaged cybersecurity experts while notifying law enforcement. This incident underscores the vulnerability of supply chain technology in the healthcare sector, as disruptions may impede the timely delivery of essential medical supplies. Healthcare professionals must remain vigilant about such threats, as reliance on IT distributors like Ingram Micro can directly impact patient care and operational efficiency.
Jul 8, 2025·Healthcare IT News
Hospitals are facing a significant rise in sophisticated phishing attacks, with a reported 700% increase in incidents related to credential phishing due to generative AI tools. These AI-driven attacks produce highly convincing emails and fake login pages, effectively circumventing traditional security defenses and jeopardizing patient data and healthcare operations. As the healthcare sector's reliance on trust and information accessibility intensifies, professionals must prioritize advanced identity security measures and stringent access controls to mitigate threats. The reliance on decentralized systems and numerous third-party vendors further complicates the security landscape, necessitating a re-evaluation of existing cybersecurity strategies.
Jul 8, 2025·Financial Times
A turf war among cybercriminals associated with Marks & Spencer has highlighted the competitive and distrustful dynamics within the hacking community. This internal strife not only poses risks for the perpetrators, increasing their vulnerability to law enforcement, but also disrupts their operations, potentially benefiting cybersecurity efforts. As these rival groups focus on their own conflicts, their ability to coordinate large-scale attacks diminishes, offering a glimmer of hope for healthcare technology professionals facing persistent cybersecurity threats. The situation underscores the complex interplay between criminal competition and technological security measures in the ongoing battle against cybercrime.
Jul 7, 2025·TechCrunch
The U.S. Department of Justice has initiated a major crackdown on North Korea's covert operations infiltrating American tech companies, aimed at funding its nuclear program and committing cybercrimes. Central to these efforts is the indictment of Zhenxing “Danny” Wang, who allegedly executed a scheme that redirected over $5 million to North Korea. The indictment underscores the need for heightened vigilance in the healthcare technology sector, where data security and integrity are paramount, as foreign actors increasingly exploit vulnerabilities within the global digital workforce. Healthcare professionals must be aware of these threats to safeguard sensitive information and maintain compliance with regulatory frameworks.
Jul 7, 2025·CSO Online
In response to the escalating threat of financially motivated cyberattacks, particularly within healthcare and other critical sectors, Chief Information Security Officers (CISOs) are urged to fundamentally reassess their cybersecurity strategies. The dominance of ransomware incidents is revealing the limitations of traditional defense methods, prompting a need for more adaptive and responsive security measures. Key to this evolution is the implementation of advanced visibility tools and behavioral tracking, enabling organizations to swiftly identify anomalies that may indicate a breach before significant damage occurs. This shift underscores the urgency for healthcare professionals to prioritize cybersecurity as an integral part of their operational strategy to safeguard sensitive patient data.
Jul 6, 2025·cisa.gov
A recent joint advisory from U.S. cybersecurity agencies warns of potential cyber threats from Iranian actors targeting critical infrastructure in the United States, particularly within the Defense Industrial Base. The alert highlights the need for organizations, especially those associated with Israeli defense firms, to enhance their cybersecurity measures and remain vigilant against possible attacks. While there is no current evidence of coordinated cyber campaigns linked to Iran, the advisory encourages critical infrastructure stakeholders to understand the threat landscape and adopt proactive defenses. This proactive approach is essential for safeguarding national security and ensuring the integrity of operational systems amid evolving cyber threats.
Jul 6, 2025·The Record
Surmodics, a leading provider of hydrophilic coatings for intravascular medical devices, suffered a significant cyberattack on June 5, prompting a partial shutdown of its IT systems. This incident is notable as it marks Surmodics as the third publicly traded medical device company to report a cyberattack to the SEC in recent months, indicating a troubling trend in the industry. While the company has started to recover with the help of cybersecurity experts, the ongoing investigation highlights potential risks such as litigation, regulatory scrutiny, and shifts in customer confidence. As healthcare technology increasingly integrates digital systems, these incidents underscore the need for robust cybersecurity measures to protect sensitive information and maintain operational continuity.
Jul 6, 2025·Cybersecurity Dive
Senator Ron Wyden has raised alarms over the FBI's inadequate cybersecurity guidance for lawmakers, particularly regarding threats from foreign adversaries like Russia and China. In a recent letter to FBI Director Kash Patel, Wyden criticized the basic advice provided, asserting that it fails to address the increasingly sophisticated commercial spyware that can compromise devices without user interaction. His call for enhanced protective measures includes specific practices such as enabling anti-spyware defenses and blocking malware-laden ads, highlighting the urgent need for improved cybersecurity protocols in government to safeguard officials and sensitive information. This situation underscores a wider challenge in healthcare technology, where similar vulnerabilities could jeopardize patient data and institutional security, necessitating more robust preventive strategies.
Jul 6, 2025·venturebeat.com
The article discusses the overlooked security costs related to AI at the inference layer, which poses significant risks for businesses actively deploying AI technologies. As organizations prioritize operationalizing AI, they often underestimate the financial burden associated with maintaining security, particularly in terms of breach containment and compliance efforts. This negligence may not only compromise regulatory adherence and customer trust but also jeopardize the overall return on investment for AI initiatives. Ultimately, the implication for healthcare professionals is clear: ensuring robust security measures at the inference stage is critical to safeguard both financial stability and patient trust in technology-driven healthcare environments.
Jul 6, 2025·Access Newswire
A recent survey by Black Book Research reveals a significant cybersecurity crisis among small and rural hospitals in the U.S., with 73% lacking adequate cybersecurity infrastructure and over half not conducting recent risk assessments. The findings indicate that these facilities face challenges such as workforce shortages, reliance on outdated technology, and limited investment in cybersecurity, with budgets often below 4% of total IT spending. Many hospitals are also outsourcing cybersecurity functions without proper oversight, resulting in increased vulnerability to cyber threats. This situation poses serious implications for patient safety and the integrity of healthcare delivery, particularly as Medicaid funding cuts loom.
Jul 3, 2025·Becker's Hospital Review
Healthcare systems are being urged to enhance cybersecurity measures ahead of the Fourth of July holiday due to a heightened risk of cyberattacks from various adversaries, including nation-states. John Riggi from the American Hospital Association warns that attackers often target hospitals during holiday periods when staffing is lower and vigilance decreases. With recent geopolitical tensions raising the stakes, and increased phishing tactics during such times, healthcare professionals must remain vigilant to protect not only their networks but also critical third-party providers. This call to action underscores the persistent and evolving nature of cyber threats, highlighting the need for robust defense strategies in the healthcare sector.
Jul 3, 2025·Claim Depot
On June 13, 2025, Myrtue Medical Center experienced a significant data breach after unauthorized access to its network was identified. The incident, claimed by the threat actor "Worldleaks," resulted in the exfiltration of 1.2 terabytes of data, signaling serious implications for patient privacy and data security. While the hospital has commenced an investigation and is working to assess the impact on affected individuals, specific details about the types of compromised information remain undisclosed. This incident underscores the increasing vulnerability of healthcare organizations to cyber threats and the urgent need for enhanced cybersecurity measures within the industry.
Jul 3, 2025·Radiology Business
Pinehurst Radiology Center, a key healthcare provider in south-central North Carolina, has ceased operations after a cyberattack earlier this year compromised patient data. The closure has significant implications for healthcare technology as it highlights vulnerabilities in data security within medical practices, prompting a reassessment of cybersecurity protocols in the industry. Patients were advised to seek alternative care from local hospitals, and the transfer of medical records to a third-party management company raises further concerns about data integrity and accessibility. This incident underscores the urgent need for healthcare facilities to strengthen their defenses against cyber threats to protect patient information and ensure continuity of care.
Jul 3, 2025·BankInfoSecurity
Horizon Healthcare RCM recently faced a ransomware attack that compromised health data and hinted at the possibility of paying a ransom to mitigate the fallout. Although the incident directly affected six individuals, the full scope of the breach remains unclear, especially given the company's client base that includes significant healthcare systems. Importantly, none of these clients have reported the breach to regulatory authorities, raising concerns about compliance and accountability in health data management. The compromised data, which includes sensitive personal information, underscores the critical need for robust cybersecurity measures in healthcare technology.
Jul 3, 2025·BleepingComputer
Kelly & Associates Insurance Group, operating as Kelly Benefits, has experienced a significant data breach affecting over 550,000 individuals due to unauthorized access to its IT systems last December. Initially estimated to impact about 32,000 people, the number was revised after further investigation, revealing the breach's extensive reach across 46 entities, including prominent healthcare providers like United Healthcare and Aetna. The compromised data encompasses highly sensitive information such as Social Security numbers and health insurance details, raising serious concerns about potential phishing and social engineering threats. This incident highlights the vulnerabilities in healthcare technology systems and the imperative for enhanced security measures to protect patient data across interconnected service providers.