Search site
Find podcasts, news, articles, webinars, and contributors in one search.
Health IT News
Browse by topic
Most-read stories in the last 7 days
1,000 stories
Jun 5, 2025·SC World
In light of the increasing sophistication of cyber threats, particularly from state actors like China, the United States must prioritize cybersecurity as a key component of national security. Historical patterns reveal a correlation between economic tensions and heightened cyber aggression, highlighting the urgent need for effective legislative measures to protect sensitive data and infrastructure. Transitioning from a purely defensive approach to one that emphasizes resilience and recovery will be essential in mitigating the impact of potential cyber disruptions.
Jun 5, 2025·The Hacker News
Google has released emergency patches for its Chrome browser to fix three security vulnerabilities, including a critical flaw (CVE-2025-5419) that is being actively exploited. This high-severity vulnerability, with a CVSS score of 8.8, allows remote attackers to potentially exploit heap corruption via a malicious HTML page. Discovered by Google's Threat Analysis Group on May 27, 2025, the issue was quickly addressed with a configuration update the next day. Google has provided minimal information about the ongoing attacks and the threat actors to ensure users can update their browsers before further exploitation occurs. This is the second zero-day vulnerability the company has patched this year.
Jun 5, 2025·SecurityWeek
Microsoft and CrowdStrike have launched a collaborative initiative to standardize the identification of cybercriminals and state-sponsored actors within the cybersecurity landscape. This effort aims to address the confusion stemming from inconsistent naming conventions used by different organizations, thereby improving communication and intelligence sharing among cybersecurity professionals. By creating a unified framework for threat actor identification, the initiative seeks to bolster collaboration between private sector companies and government agencies, enhancing the overall effectiveness in responding to increasing cyber threats. The project emphasizes the need for collective action in addressing the complexities of modern cyber threats.
Jun 5, 2025·TechCrunch
The ransomware group Interlock has claimed responsibility for a cyberattack on Kettering Health, disrupting operations across the healthcare network and forcing a complete shutdown of computer systems. The attack, which occurred two weeks ago, involved the theft of over 940 gigabytes of sensitive data, including patient health records and employee information. Although initially unconfirmed, the attack's connection to Interlock was later established, and the group's acknowledgment of responsibility may indicate stalled negotiations regarding ransom demands, which Kettering Health has publicly stated it did not meet. Some of the compromised files contain particularly sensitive information, including details related to police officers affiliated with the organization.
Jun 4, 2025·TechTarget
Under-resourced healthcare providers, particularly in rural and critical access settings, are grappling with cybersecurity challenges similar to larger institutions but often lack the necessary funding and staffing to manage these risks effectively. Increased scrutiny from policymakers underscores the urgency for improved cybersecurity, yet many small providers prioritize patient care over cybersecurity investments, leading to vulnerabilities. Interviews conducted by the Health Sector Coordinating Council reveal that while these organizations understand the importance of cybersecurity, limited resources and competing priorities are significant obstacles. Key challenges identified include insufficient funding, outdated technology, and difficulties in attracting cybersecurity talent, resulting in a struggle to balance operational needs with the protection against cyber threats.
Jun 4, 2025·Tampa Bay Times
Recent hacking incidents in Florida have exposed vulnerabilities in healthcare organizations, with DermCare Management and Apollo Medical Supply among those reporting breaches affecting over 4,000 patients. Since July 2023, 33 healthcare firms in the state have experienced data breaches, impacting more than 6.7 million patients. A notable case involved Tampa General Hospital, which faced a significant breach and settled a class action lawsuit for $6.7 million. In a different incident, Central Florida Cares Health System lost $3.6 million due to a cyber theft caused by an employee mistakenly entering banking credentials on a fraudulent site; while $1.9 million was recovered through insurance, the organization implemented stricter security protocols. Additionally, Thriving Mind South Florida reported similar risks to patient information security.
Jun 3, 2025·SecurityWeek
The recent identification of the leader of the Conti and TrickBot cybercrime gangs represents a significant advancement in addressing organized cybercrime. This individual has been linked to multiple high-profile ransomware attacks and various cybercriminal activities, affecting sectors such as business, healthcare, and government. The unmasking is expected to facilitate law enforcement efforts to dismantle these networks and hold perpetrators accountable. This development also emphasizes the need for international collaboration to enhance cybersecurity strategies and protect critical infrastructure from future threats.
Jun 2, 2025·The Record
Senate Democrats have called on Homeland Security Secretary Kristi Noem to reinstate the Cyber Safety Review Board (CSRB), which was disbanded earlier this year by the Trump administration during investigations into the Salt Typhoon cyberattacks linked to Chinese hackers. Senators Mark Warner, Ron Wyden, Richard Blumenthal, and Elissa Slotkin highlighted the board's role in providing vital insights into cyber threats, especially following significant breaches affecting major U.S. telecommunications companies. Established in 2021 to analyze major cyber incidents, the CSRB had previously investigated critical vulnerabilities and was poised to assess the Salt Typhoon campaign, which has raised national security concerns.
Jun 2, 2025·BleepingComputer
A critical vulnerability in Cisco's IOS XE software, known as CVE-2025-20188, has been disclosed, raising security concerns. This flaw enables unauthorized remote attackers to upload files and execute commands, particularly when the 'Out-of-Band AP Image Download' feature is active. Identified through hard-coded JSON Web Token issues and insufficient path validation, the vulnerability affects various Catalyst 9800 series wireless controllers. Researchers from Horizon3 demonstrated how attackers could exploit the flaw to bypass authentication and execute code remotely, potentially compromising device security.
Jun 2, 2025·The Register
Fred Hutchinson Cancer Center has reached a settlement of approximately $52.5 million following a cyberattack during Thanksgiving 2023, which compromised sensitive patient information, including health insurance and treatment details. The settlement includes $11.5 million for affected individuals, with claims available for up to $599 or $5,000 for those suffering material losses. Additionally, funds will be directed toward infrastructure improvements and medical fraud monitoring. Although the attack involved threats of swatting, Fred Hutch has asserted that no patient data has been sold and that it did not pay any ransom to the attackers, known as Hunters International.
Jun 1, 2025·BankInfoSecurity
Covenant Health is currently responding to a cyber incident that has affected IT services at several of its facilities in New England and Pennsylvania, beginning with the discovery of connectivity issues on May 26. The health system has secured its data by taking affected systems offline, and while two hospitals in Maine and one in New Hampshire have been impacted, essential healthcare services continue to operate normally. Covenant Health has issued alerts on its websites regarding temporary disruptions in phone and internet access, and has specifically noted that outpatient laboratory services are limited to the main hospital campus at St. Joseph Hospital, with patient notices acknowledging the inconvenience and promising swift resolution of the issues.
Jun 1, 2025·Apple News
A recent scheme involving impersonators posing as Mark Meadows, former White House Chief of Staff, has highlighted significant vulnerabilities in security protocols for government officials. The impersonators sought to manipulate individuals and organizations by leveraging Meadows' former position to gain access to sensitive information and restricted areas. Authorities are investigating the incident to assess the extent of the impersonation and its implications for governmental security. This situation underscores the necessity for improved verification processes to safeguard against unauthorized access and protect the integrity of governmental operations.
May 29, 2025·MobiHealthNews
Cooper Health System in Camden, New Jersey, has announced a data security breach that could affect the personal information of certain current and former patients. The breach was detected on March 26, 2025, following abnormal network activity linked to unauthorized access to sensitive data, including names, Social Security numbers, and medical history, occurring around May 2024. The health system has since collaborated with cybersecurity experts, reported the incident to the FBI, and implemented enhanced security measures. Although Cooper has not identified any misuse of the compromised information, it is advising those affected on steps to protect their personal data.
May 29, 2025·AHA
On May 22, the NSA and CISA, in collaboration with international partners, issued guidance aimed at securing data in AI and machine learning systems, highlighting the importance of data integrity. The guidance outlines potential risks at various stages of AI use, focusing on three main data security concerns: the data supply chain, maliciously modified data, and data drift. John Riggi from the AHA emphasized the guidance's significance for healthcare leaders, detailing methodologies for ensuring data security, such as sourcing reliable datasets and utilizing tools like encryption and digital signatures. This resource aims to help organizations address vulnerabilities and enhance AI data security protocols.
May 29, 2025·ABC7 Chicago
UChicago Medicine has reported a data breach affecting around 38,000 patients due to a cybersecurity incident linked to Nationwide Recovery Services, Inc., a now-defunct vendor. The breach, which occurred between July 5 and July 11 of the previous year, compromised sensitive personal information, including Social Security numbers and medical data. Although the vendor claims there is no evidence of misuse, the risks to affected individuals are considerable. UChicago Medicine will notify impacted patients through written communication about the breach and protective measures. This incident underscores the ongoing data security vulnerabilities within the healthcare industry, particularly concerning third-party vendors.
May 29, 2025·SecurityWeek
Zscaler has announced its plan to acquire Red Canary, a specialist in managed detection and response (MDR) services, with the aim of enhancing its cybersecurity solutions. This acquisition will integrate Red Canary's advanced threat detection capabilities into Zscaler's platform, improving real-time threat detection and response for clients. The move comes as organizations are increasingly focused on cybersecurity due to rising cyberattacks, positioning Zscaler to offer a more comprehensive approach to threat management and align with industry trends of consolidating resources to address complex security challenges.
May 28, 2025·Federal News Network
The Defense Department (DoD) is facing significant cuts to its cyber workforce due to a hiring freeze and initiatives to decrease civilian personnel, while managing about 225,000 workers in cybersecurity, AI, and IT roles. Current vacancy rates in cyber positions have improved to around 15%, but future impacts remain unclear as some employees may choose to resign or retire early. Monthly new hires in the cyber sector have plummeted from approximately 1,500 to under 200 recently. Patrick Johnson, the DoD's workforce innovation director, acknowledged the need for strategic cuts and estimates that some agencies, including the Defense Information Systems Agency, may lose nearly 10% of their workforce in the process.
May 28, 2025·CSO Online
CISOs are advised to enhance their defenses against the Scattered Spider ransomware group, which has targeted major UK retailers and is now shifting focus to the US. Known for utilizing social engineering tactics, Scattered Spider has showcased a growing sophistication in its attacks, prompting experts to recommend proactive measures such as improving help desk protocols and intrusion detection systems. Training all staff, particularly help desk employees, to recognize and respond to these threats, along with implementing clear reporting procedures for suspicious activity, is crucial for organizations to reduce their vulnerability to such cyber threats.
May 28, 2025·Healthcare IT News
Kettering Health in Ohio announced the restoration of its radiation oncology services on May 23, following a ransomware attack that began on May 20, which disrupted patient care and led to the cancellation of elective surgeries. During the incident, the health system maintained operations in its emergency rooms and clinics and worked with neighboring hospitals to support continuity of care. The cyberattack, characterized by ransom demands, affected many systems, though Kettering's patient portal remained operational. The health system's leadership expressed appreciation for local hospital support, and staff worked through the Memorial Day weekend to quickly resume radiation treatments for patients.
May 27, 2025·BankInfoSecurity
Shields Healthcare Group has reached a $15.35 million settlement in a class action lawsuit stemming from a 2022 data breach that impacted nearly 2.4 million individuals. The breach allowed unauthorized access to sensitive personal and medical information, with hackers reportedly maintaining access for at least two weeks. Although Shields denies any wrongdoing and disputes allegations of inadequate security, the settlement, approved by a federal judge in Boston, will provide compensation for affected individuals, including claims up to $2,500 for related out-of-pocket expenses.