Search site
Find podcasts, news, articles, webinars, and contributors in one search.
Health IT News
Browse by topic
Most-read stories in the last 7 days
1,000 stories
Jun 20, 2025·Forbes
Researchers have confirmed the exposure of 16 billion login credentials, the largest password leak in history, attributed to various infostealers and affecting major tech companies like Apple, Facebook, and Google. This breach includes 30 datasets containing extensive records, offering new, actionable intelligence that could enable phishing attacks and account takeovers. CEO Darren Guccione of Keeper Security has highlighted the risks associated with poorly configured cloud environments and suggests that individuals and organizations adopt password management solutions and dark web monitoring tools to mitigate these threats.
Jun 19, 2025·LinkedIn
In this article, Christopher Plummer, Senior Cybersecurity Architect at Dartmouth Health, emphasizes the pressing need for healthcare organizations to enhance their cybersecurity strategies against the backdrop of escalating geopolitical tensions. He advocates for key practices such as robust infrastructure patching, reassessing geographic restrictions, and enforcing multi-factor authentication to protect sensitive data. Additionally, joining Information Sharing and Analysis Centers is recommended to gain access to crucial cybersecurity intelligence. While acknowledging some existing measures among professionals, Plummer calls for a reevaluation of strategies and highlights the gap in cohesive cyber defense within the sector, particularly in light of threats posed by potential military conflicts.
Jun 18, 2025·The Register
Freedman HealthCare, a data and analytics firm that supports state agencies and healthcare providers, is facing a potential data breach by the cyber extortion group World Leaks, which claims to have stolen 52.4 GB of sensitive information. The data includes healthcare claims and payment details, affecting its extensive database projects for multiple states, including California and Rhode Island. If the claims are validated, this breach could have serious ramifications for millions of residents’ private information in the healthcare system. World Leaks, known for targeting significant organizations, has moved towards data theft and extortion instead of traditional ransomware tactics.
Jun 17, 2025·BankInfoSecurity
Ocuco and Episource have reported significant data breaches in the health sector, affecting hundreds of thousands of individuals. Ocuco's breach involved unauthorized access to its network server, impacting nearly 241,000 people due to a vulnerability in third-party software, with a ransomware group claiming to have stolen over 340 gigabytes of data. The company is conducting a review to identify affected individuals and plans to notify them accordingly. Meanwhile, Episource faced a ransomware incident affecting thousands, including 24,259 individuals in Texas, with unauthorized access occurring between late January and early February. Although the breach hasn't been reported to the HHS Office for Civil Rights, many of Episource’s healthcare clients are issuing public notices about the compromised personal and health information.
Jun 17, 2025·VUMC Reporter
Microsoft Teams is facing an uptick in caller ID spoofing scams where attackers impersonate trusted colleagues by changing their display names during calls. The VUMC Enterprise Cybersecurity (VEC) has reported instances where users received calls appearing to come from their supervisors, only for the display name or number to shift after answering. This manipulation often leads recipients to comply with suspicious requests, such as software installations or financial transactions, under the pretense of urgency. To mitigate these risks, individuals are advised to verify caller identities through independent means and to avoid engaging with unsolicited calls.
Jun 16, 2025·Dark Reading
The FBI has issued a warning regarding the BADBOX 2.0 botnet, a significant threat that targets Internet of Things (IoT) devices, particularly connected TV (CTV) devices. Following the disruption of the original BADBOX campaign in 2024, this new iteration has been identified as the largest botnet of its kind, with extensive reach and complexity. Despite intervention from various cybersecurity organizations, BADBOX 2.0 persists, continuing a trend of compromising Android devices through preinstalled firmware malware and malicious apps from unofficial marketplaces. Most affected devices are linked to the Android Open Source Project and are primarily manufactured in China.
Jun 16, 2025·chiefhealthcareexecutive.com
focus on developing comprehensive cybersecurity strategies that address staffing shortages and budget limitations. As evidenced by recent breaches, including the significant Change Healthcare incident, healthcare systems must prioritize the implementation of existing cybersecurity technologies and tools. Organizations should consider investing in training for current staff, outsourcing certain cybersecurity functions, and adopting proactive measures to defend against evolving threats like AI-driven attacks. By reassessing their cybersecurity frameworks and enhancing resource allocation, healthcare providers can improve their defenses against the increasing sophistication and frequency of cybercrime.
Jun 12, 2025·News Center Maine
Covenant Health is facing a class-action lawsuit after a cyberattack disrupted its operations in Maine. Filed by Michael McClain, the lawsuit claims that the organization failed to adequately protect patient data following the detection of unusual network activity on May 25, prompting Covenant Health to take its hospital data systems offline. The complaint accuses Covenant of using ineffective security measures, raising concerns about healthcare cybersecurity practices. Although the company has not confirmed if any patient data was compromised and has refrained from commenting on the lawsuit, the breach coincides with a similar cyber incident at Central Maine Healthcare. In response, MaineHealth has cut digital ties with both organizations.
Jun 12, 2025·Cybersecurity Dive
Artificial intelligence is poised to enhance the functionality of security operations centers (SOCs) by automating repetitive tasks and supporting incident management; however, human oversight remains essential due to AI's inability to fully understand nuanced cybersecurity challenges. Presentations from the Gartner Security and Risk Management Summit outlined how AI can streamline processes, such as incident reporting and alert analysis, but also highlighted the risks of AI-generated misinformation if not adequately checked. The need for additional AI systems to monitor these automated agents may arise as their role expands, especially in more complex scenarios like strategic risk assessment and crisis communications, which still require human expertise.
Jun 12, 2025·Becker's Hospital Review
Edmund Siy, the new chief information and technology officer at Bon Secours Mercy Health, is prioritizing the alignment of technology initiatives with the organization's mission since his appointment in May. His focus includes building a secure digital infrastructure, enhancing support for clinicians, and guiding the ethical adoption of artificial intelligence. Siy emphasizes cybersecurity to protect patient data and plans to develop three-year roadmaps to strategically guide the IT department. He also highlights the importance of integrating AI responsibly within healthcare workflows, urging collaboration with providers to ensure ethical implementation.
Jun 11, 2025·BankInfoSecurity
The NHS in England is grappling with a serious blood supply shortage following a June 2024 ransomware attack on Synnovis, a key pathology laboratory provider. This incident disrupted essential testing services across several hospitals, leading to a critical deficit in type O-negative blood, vital for transfusions. In response, NHS Blood and Transplant is calling on one million individuals to donate blood to stabilize supplies, as the risk of reaching a "Red Alert" status looms due to increasing demand. The cyberattack, linked to the Russian-speaking group Qilin, also canceled over 10,000 outpatient appointments and elective procedures in London, highlighting a worrying trend of cyber threats to blood supply organizations.
Jun 11, 2025·Industrial Cyber
The First Quarter 2025 Health-ISAC Heartbeat report indicates a rise in cybersecurity incidents in the healthcare sector, with ransomware attacks increasing to 158 in January-March 2025, up from 154 in the previous quarter. The report notes that the healthcare sector has accounted for 5.8 percent of the 23,606 recorded breaches since 2021. To assist member organizations in addressing vulnerabilities, Health-ISAC issued 220 Targeted Alerts focusing on issues such as open databases and compromised credentials, particularly concerning BeyondTrust and Next.js software. Additionally, the report highlights the activities of cybercriminals selling stolen data and access to compromised systems, including an individual identified as MIYAK000 who attempted to market compromised VPN access.
Jun 10, 2025·Cybersecurity Dive
President Donald Trump has signed an executive order that revises or eliminates key cybersecurity initiatives established by the Biden administration, which the White House criticized as "problematic." The order removes Biden's software security requirements for federal contractors, aimed at enhancing security post-cyberattacks, and dismantles efforts related to artificial intelligence in cybersecurity and post-quantum cryptography. These changes reflect a shift towards what the Trump administration considers a less burdensome approach to cybersecurity, focusing on compliance over substantive improvements in security practices.
Jun 9, 2025·The Register
During a Senate homeland security committee hearing, Sean Cairncross, nominated for the role of national cyber director, advocated for offensive cyber strategies against foreign threats amid criticism regarding proposed budget cuts to the Cybersecurity and Infrastructure Security Agency (CISA). Despite his limited experience in cybersecurity, he argued for a more aggressive U.S. stance against adversaries, particularly following recent sophisticated cyberattacks. However, Senator Elissa Slotkin raised concerns about the administration's Fiscal Year 2026 budget, which proposed a nearly $495 million reduction for CISA and the loss of over 1,000 jobs, warning that such cuts could leave key sectors vulnerable to cyber threats and likening the situation to pre-9/11 security shortcomings. Cairncross struggled to defend the budget proposal amid alarms raised by lawmakers over the increasing risks of cyber incidents.
Jun 9, 2025·WGME
Cyber incidents have disrupted operations at four hospitals in central and western Maine, including Central Maine Medical Center and St. Mary's Hospital. While phone systems have been partially restored and most clinics are operational, patient communication through online portals is still affected. The IT team is investigating the underlying cause of the disruptions, which have led to significant delays in patient services, as exemplified by a local resident whose scheduled surgery was impacted. Although emergency services continue to function, elective surgeries are being postponed as hospitals work to resolve the issues.
Jun 8, 2025·Medical Economics
A report from Omega Systems outlines significant cybersecurity challenges in healthcare, revealing that 20% of leaders reported patient care disruptions due to cyberattacks. The 2025 Healthcare IT Landscape Report emphasizes a growing concern among executives, with over half fearing a fatal cyber incident within five years, highlighting a disparity between rapid digital advancement and cybersecurity readiness. While 80% of executives are confident in combating AI-driven threats, gaps in practices remain, with one-third lacking regular cybersecurity training and 20% without an effective incident response plan. Additionally, outdated infrastructure poses risks, with 56% of leaders acknowledging its impact on breach recovery and 36% finding current cybersecurity tools insufficient for protecting cloud-based patient data.
Jun 8, 2025·BankInfoSecurity
identity management in healthcare. Lai noted that enhancing security measures, including adopting a zero trust framework, could help organizations address the rising threat of identity-related cyberattacks, particularly as traditional tactics like phishing become more prevalent. Emphasizing the need for investment in robust identity verification processes, he pointed out recent breaches that exploited weaknesses in employee identity management. Strengthening these processes is crucial for safeguarding sensitive healthcare information and ensuring overall system integrity.
Jun 8, 2025·HackRead
Hackers associated with the ShinyHunters group have leaked over 86 million records from AT&T, including sensitive personal information like full names, phone numbers, email addresses, and about 44 million decrypted Social Security Numbers (SSNs). The data was first shared on a Russian cybercrime forum in May 2025 after vulnerabilities in the Snowflake cloud data platform were exploited. This leak raises significant privacy concerns, especially since many SSNs were already compromised in a previous breach involving 3.2 billion records in August 2024. AT&T's history of data breaches adds to the urgency of the situation for affected customers.
Jun 8, 2025·Newsweek
Cybercriminals are increasingly using residential proxy services to conceal their online activities, allowing them to route traffic through legitimate-looking residential IP addresses. This method complicates detection by security systems and facilitates various illegal actions, including data scraping and DDoS attacks. The prevalence of these proxies is rising as they help attackers mimic normal user behavior, making it difficult to identify malicious traffic. Security experts highlight that the use of residential proxies poses significant risks to organizations and the broader internet landscape, emphasizing the need for advanced detection and response strategies to combat this evolving threat.
Jun 8, 2025·Cybersecurity Dive
President Donald Trump's Fiscal Year 2026 budget proposal includes significant funding cuts to the Cybersecurity and Infrastructure Security Agency (CISA), aiming to reduce its budget by $495 million and eliminate nearly 30% of its workforce. The plan will result in an 18% cut for the Cybersecurity Division, alongside severe reductions of up to 73% for the National Risk Management Center and 62% for the Stakeholder Engagement Division, potentially limiting CISA's ability to protect critical infrastructure and support local governments. Overall, the proposal seeks to reduce CISA's personnel by over 1,000 positions, leaving the agency with approximately 2,649 employees.