Search site
Find podcasts, news, articles, webinars, and contributors in one search.
Health IT News
Browse by topic
Most-read stories in the last 7 days
1,000 stories
Jul 2, 2025·USA TODAY
The Centers for Medicare & Medicaid Services (CMS) reported a data breach potentially affecting over 100,000 Medicare recipients, exposing sensitive personal and medical information. Discovered on May 2, 2025, the breach involved unauthorized account creations by "malicious actors" over a two-year period, leading CMS to issue new identification numbers and deactivate compromised accounts. While no identity theft cases have been reported, the incident raises significant concerns about data security for healthcare technology systems and the need for robust safeguards to protect patient information. Healthcare professionals must remain vigilant and ensure their practices are compliant with evolving data protection standards to prevent similar breaches.
Jul 2, 2025·mymlc.com
On June 27, 2025, Mosaic Life Care informed patients of a data security breach involving Oracle Health/Cerner, which was discovered after an unknown party claimed to possess stolen patient information. The breach, traced back to compromised credentials during data migration on Oracle Health/Cerner's systems, affected patient data such as Social Security numbers, treatment details, and insurance information. Although Mosaic's own systems remained secure, the incident underscores the vulnerabilities associated with third-party health technology providers and highlights the need for enhanced security measures in healthcare data management. Healthcare professionals must remain vigilant in addressing potential risks associated with data sharing and third-party services to protect patient privacy.
Jul 1, 2025·Infosecurity Magazine
A recent Ernst & Young (EY) survey reveals that cybersecurity teams can generate significant enterprise value, averaging $36 million per initiative, but budgets for these teams have dropped from 1.1% to 0.6% of annual revenue over the past two years. This decline indicates a missed opportunity for organizations to leverage cybersecurity investments as a means of value creation rather than merely viewing them as a risk mitigation expense. Furthermore, only 13% of Chief Information Security Officers (CISOs) are brought into strategic decision-making processes early, highlighting a gap in acknowledging their potential impact on business growth. The study underscores the need for healthcare professionals and executives to reassess how they integrate cybersecurity into broader organizational strategies to optimize both security and business outcomes.
Jul 1, 2025·BankInfoSecurity
Federal authorities, including the FBI and the U.S. Department of Health and Human Services, have warned of a rise in phishing scams targeting healthcare organizations and patients, following recent cyberattacks on major insurers. Criminals are impersonating legitimate health insurers in emails and texts, pressuring recipients to disclose sensitive personal and financial information under false pretenses, such as reimbursement claims for non-covered services. These tactics highlight vulnerabilities in the healthcare sector's communication systems, underscoring the urgent need for greater cybersecurity measures and staff training to protect sensitive information from exploitation. As these scams evolve, healthcare providers must remain vigilant and prioritize the security of their communications to safeguard patient data.
Jun 30, 2025·WGME
Central Maine Healthcare is confronting the repercussions of a significant cyber incident that halted its computer and phone systems for 25 days, leading to widespread disruption of services, including patient care. This has particularly affected cancer patients like Rick McVay, who experienced a nearly month-long delay in essential radiation therapy. The situation highlights the critical reliance of healthcare providers on technology for patient treatment and the potential risks associated with system vulnerabilities. Despite recent progress in restoring services, the incident underscores the urgent need for enhanced cybersecurity measures in the healthcare sector to prevent future interruptions.
Jun 30, 2025·LinkedIn
Zishan Siddiqui, Chief Information Security Officer at Sentara Health, underscores the urgent need for a cybersecurity culture within healthcare, especially as the value of medical records on the dark web surpasses that of credit card information. He emphasizes that while advanced security technologies are vital, fostering a proactive mindset among staff through integrated cybersecurity awareness and open communication is equally essential. Regular training and mock incident response exercises are key strategies for empowering employees to recognize and respond to threats. This cultural shift is critical not only for protecting sensitive patient data but also for ensuring the seamless operation of healthcare services.
Jun 30, 2025·nexusconnect.io
Rural healthcare providers in the U.S. are increasingly vulnerable to cybersecurity threats due to limited funding and a lack of cybersecurity expertise, as emphasized by a report from the Health Sector Coordinating Council. Many facilities, reliant on thin Medicare reimbursements, struggle to implement necessary security measures, risking exposure to high-profile cyberattacks that disrupt operations and affect patient care. The report advocates for significant policy changes, including classifying major cyberattacks as "all hazards" incidents to enable federal resources, promoting participation in information-sharing initiatives, and enhancing financial support for cybersecurity improvements. These recommendations aim to bolster the cyber resilience of resource-constrained healthcare organizations, ensuring better protection for patient data and continuity of care.
Jun 29, 2025·IT Pro
A recent NTT Data survey highlights a notable disparity between CEOs and Chief Information Security Officers (CISOs) regarding generative AI adoption within organizations. While CEOs view AI investment as essential for competitiveness, nearly half of CISOs express concerns about the associated risks, often citing unclear internal guidelines on AI responsibilities. This divide underscores the need for better collaboration between business leaders and cybersecurity professionals, as many CISOs struggle to establish governance protocols that could facilitate safer AI integration. To ensure successful deployment of AI technologies, it is crucial for organizations to develop formal policies that align cybersecurity frameworks with their AI strategies.
Jun 29, 2025·The Hacker News
Citrix has released emergency patches for a critical vulnerability (CVE-2025-6543) in its NetScaler ADC, which has a CVSS score of 9.2 and is actively being exploited. The memory overflow issue can lead to unauthorized control and denial-of-service, particularly impacting NetScaler ADC and Gateway configurations. Healthcare professionals using affected systems are urged to upgrade immediately, as no workarounds exist, and the risk of exploitation in unpatched environments is significant. This announcement follows a recent vulnerability (CVE-2025-5777), underscoring ongoing security challenges that require prompt attention in healthcare technology systems.
Jun 26, 2025·USAToday
As cyber threats evolve, protecting personal data has become increasingly critical, prompting advancements in digital privacy tools. Innovations such as artificial intelligence for real-time threat detection, blockchain for data integrity, and emerging quantum encryption techniques promise enhanced security. Biometric authentication methods are replacing traditional passwords, while multi-factor authentication adds further protection. Consumers now have access to practical privacy tools like VPNs, encrypted messaging apps, and browser extensions, with companies simplifying their use through user-friendly dashboards. Additionally, growing concerns about data collection by large tech firms have led to the development of decentralized platforms that distribute information storage across multiple nodes, addressing issues of autonomy and misuse.
Jun 26, 2025·Cybersecurity Dive
The Trump administration's restructuring of the federal government has weakened vital public-private partnerships essential for safeguarding U.S. critical infrastructure against cyber threats and physical disasters. This decline is linked to workforce reductions, mission ambiguity, and a lack of leadership, causing federal agencies to struggle in effectively collaborating with key sectors like healthcare and energy. The dismantling of the Critical Infrastructure Partnership Advisory Council (CIPAC) has notably disrupted secure cyber discussions, leading industries to halt or alter projects due to fears around sharing sensitive information. The need for a new framework to restore trust and communication between government and industry has become increasingly urgent as a result.
Jun 26, 2025·ABC News
In the wake of U.S. strikes on Iranian nuclear sites, Iranian-backed hackers have initiated cyberattacks against American banks, defense contractors, and oil companies, although no major disruptions have occurred thus far. Experts caution that tensions could escalate if the ceasefire between Iran and Israel falters or if independent hacktivist groups decide to escalate their cyber campaigns. Two pro-Palestinian hacking groups have already claimed responsibility for targeting various aviation and financial sectors, utilizing denial-of-service attacks and encouraging others to join their efforts. Federal authorities are monitoring the situation and have urged critical infrastructure organizations to maintain vigilance amidst these ongoing threats, as Iran, despite its relative technical limitations compared to nations like China and Russia, remains adept at leveraging cyber tactics for disruption and intimidation.
Jun 25, 2025·Cybersecurity Dive
The restructuring of the federal government under the Trump administration has undermined public-private partnerships crucial for protecting U.S. critical infrastructure from cyberattacks and physical threats. Workforce cuts and leadership gaps have disrupted collaboration between federal agencies and private sector entities across healthcare, water, energy, and telecommunications. The dismantling of the Critical Infrastructure Partnership Advisory Council (CIPAC) has particularly hindered sensitive discussions on cybersecurity, leading companies to withhold threat information and resulting in project delays in the telecommunications sector. Federal agencies are now seeking a replacement for CIPAC to restore these essential communications and coordination efforts.
Jun 25, 2025·VentureBeat
Hospital cyberattacks now cost up to $600,000 per hour in operational disruptions, prompting healthcare systems like Alberta Health Services (AHS) to adopt AI-driven cybersecurity solutions. By implementing Securonix's AI-powered threat detection and response platform, AHS has reduced response times to critical incidents by over 30%, decreased false positives by 90%, and saved hundreds of thousands of dollars through improved efficiency. This proactive approach is vital for AHS, which operates 106 hospitals and 800 clinics, all connected to a single Epic electronic health record system—making any downtime potentially life-threatening. AI tools enable AHS to swiftly identify anomalies, deobfuscate malicious payloads, and automate threat responses, effectively performing the work of thousands of security analysts and significantly enhancing patient safety and system resilience.
Jun 25, 2025·The Record
A ransomware attack in June 2024 by the Russian-speaking Qilin group targeted Synnovis, a pathology services provider for several London NHS hospitals, severely disrupting blood testing services and contributing to a patient's death due to delayed results. The cyberattack led to the postponement of over 1,100 operations, including nearly 200 cancer treatments, and compromised sensitive medical data of approximately 900,000 individuals, which was later leaked online. Despite the significant impact, many affected patients have yet to be informed about the breach. The incident underscores the critical need for robust cybersecurity measures within healthcare infrastructure, especially as reliance on digital systems and private providers increases.
Jun 24, 2025·TechCrunch
Iran recently imposed a significant internet blackout, confirmed by the government as a measure to protect against potential Israeli cyberattacks. This decision was tied to national security concerns, particularly following cyber incidents affecting critical infrastructure and financial institutions, attributed to a hacker group linked to Israel. The blackout has severely limited information flow and communication for Iranians both domestically and internationally, impacting everyday life amid ongoing military conflicts. Cybersecurity expert Amir Rashidi highlighted the personal consequences of the shutdown, noting his inability to contact family members who fled Tehran.
Jun 23, 2025·Politico
U.S. critical infrastructure sectors are bracing for potential Iranian cyberattacks amid rising tensions between Iran and Israel, particularly in light of possible U.S. military actions. Despite the heightened alert, there have been no recent reports of specific cyber threats, and the current federal response appears less coordinated than in past crises, lacking proactive communication from agencies like CISA. In previous conflicts, such as with Russia's invasion of Ukraine, CISA had actively warned infrastructure operators of threats, while current assessments underline a gap in government support for enhancing cybersecurity measures. Information Sharing and Analysis Centers (ISACs) are beginning to increase their efforts to provide necessary guidance and resources to critical infrastructure operators during this uncertain period.
Jun 23, 2025·SecurityWeek
professionals, and regulatory bodies is essential to ensure that AI systems are safe and secure. The emergence of this AI jailbreak underscores the need for ongoing vigilance and innovation in cybersecurity practices to prevent misuse and safeguard sensitive data. Ultimately, strengthening AI security will require a concerted effort to balance technological advancement with responsible oversight.
Jun 23, 2025·WTXL
Tallahassee Memorial Healthcare (TMH) has reported a cybersecurity incident from January involving unauthorized access to certain patient data linked to its former vendor, Oracle/Cerner. Although access occurred on January 22 and TMH was notified on March 13, operations and patient care have not been disrupted. Notification letters were sent to affected patients on June 13, offering resources like credit monitoring. TMH reassured that their current electronic health record system remains secure and is committed to protecting patient information amid a broader trend affecting healthcare organizations nationwide.
Jun 22, 2025·CIO Dive
At the AWS re:Inforce conference, AWS CISO Amy Herzog highlighted the critical role of cybersecurity in supporting the adoption of generative AI technologies. She emphasized that organizations with strong security practices can innovate more swiftly, particularly in regulated industries like finance and healthcare. Amid rising concerns about the security of AI solutions, AWS announced enhancements to its security offerings, including a preview of an updated Security Hub featuring advanced threat correlation. Herzog also noted Amazon's use of AI to bolster its security processes, ensuring third-party models align with strict security standards.