Search site
Find podcasts, news, articles, webinars, and contributors in one search.
Health IT News
Browse by topic
Most-read stories in the last 7 days
1,000 stories
Jan 27, 2026·SecurityWeek
the ongoing vulnerabilities within digital platforms. Following a confirmed breach of its systems, Crunchbase is taking steps to mitigate potential risks and conducting a thorough investigation in collaboration with law enforcement. Users are urged to monitor their accounts for suspicious activity and to change passwords as a precaution. This incident underscores the critical need for healthcare technology professionals to prioritize cybersecurity and remain vigilant against evolving threats, which could have significant implications for patient data privacy and trust.
Jan 26, 2026·GovTech
The article calls for government Chief Information Security Officers (CISOs) to prioritize addressing financial fraud and AI-generated scams over traditional cybersecurity language, particularly as state and local governments contend with budget cuts and staffing shortages. It highlights the alarming rise in fraud, including over $300 billion in fraudulent pandemic-relief payments and a 25% increase in consumer fraud losses reported by the Federal Trade Commission in 2024. In response to the growing threat, the Trump administration has established a new Department of Justice Division for National Fraud Enforcement, emphasizing the need for effective strategies to protect citizen trust and data integrity. With predictions of soaring cybercrime costs due to AI exploitation, this shift in focus is critical for healthcare technology and other sectors reliant on secure, trustworthy digital environments.
Jan 26, 2026·HackRead
The article highlights the urgent need for advanced endpoint security platforms by 2026, which must evolve beyond traditional malware detection to include behavioral context, automated responses, and cross-domain visibility in response to sophisticated cyber threats. With attackers leveraging legitimate tools, healthcare organizations must adopt behavior-based detection methods to protect endpoints, which are prime targets for ransomware and credential theft. Several leading platforms, like Koi and Symantec, exemplify this shift by incorporating features such as behavioral intelligence and machine learning to enhance security measures and streamline threat response. This evolution is critical for healthcare professionals who manage sensitive patient data and require robust defenses against increasingly complex cyber attacks.
Jan 25, 2026·SecurityWeek
The article draws an insightful parallel between the Netflix series "Stranger Things" and the current challenges in cybersecurity, using the "Upside Down" as a metaphor for hidden digital threats. It underscores the necessity for healthcare professionals in cybersecurity to adopt a proactive and adaptive approach to threat detection and response, much like the show's characters who rely on teamwork and quick thinking to navigate danger. With evolving cyber threats impacting the healthcare landscape, the balance of technology and human intuition is crucial for effectively addressing security challenges. This highlights the vital need for ongoing collaboration and continuous learning within cybersecurity teams to safeguard sensitive health data.
Jan 25, 2026·Wolters Kluwer
A recent survey by Wolters Kluwer Health reveals that healthcare administrators at larger systems are increasingly worried about data privacy and security violations linked to AI tools. With the average cost of a healthcare data breach exceeding $7.4 million, the survey highlights that nearly 57% of administrators from major health systems consider data breaches a top risk. This concern is compounded by findings that 97% of organizations facing AI-related security incidents lack proper access controls. These insights underscore the urgent need for robust data governance and security measures to protect patient information as AI technologies continue to evolve in healthcare.
Jan 25, 2026·Los Angeles Times
The Social Security Administration (SSA) has acknowledged that members of Elon Musk's DOGE team accessed and shared personal data, contradicting previous reassurances made to a federal judge, raising significant privacy concerns. This breach involved sensitive information being transferred to a non-Social Security server, alarming advocacy groups about potential identity theft risks for millions of Americans. The revelation has triggered calls for congressional investigations and highlighted the need for stricter data protection measures within federal agencies, emphasizing the vulnerabilities and ethical implications of technology collaborations in healthcare and government sectors. Furthermore, this situation underscores the importance of transparency and accountability in safeguarding personal information, a critical priority for healthcare professionals who often handle sensitive data.
Jan 25, 2026·BankInfoSecurity
Veradigm, previously known as AllScripts, has entered a $10.5 million settlement to resolve a class action lawsuit stemming from a data breach that impacted 2.5 million patients and numerous healthcare clients in December 2024. The breach, which involved unauthorized access to sensitive patient information, raised serious concerns about the security measures employed by electronic health record vendors. Affected individuals can claim up to $5,000 for documented losses or a smaller pro rata payment, alongside two years of free identity theft protection services. This incident underscores the critical need for robust cybersecurity protocols in healthcare technology to safeguard patient data and maintain trust in digital health solutions.
Jan 22, 2026·Healthcare IT News
The Advanced Research Projects Agency for Health (ARPA-H) has allocated $19 million to Northeastern University to advance digital twin technology for enhancing cybersecurity in healthcare through its UPGRADE program. This initiative aims to create detailed digital models of hospital networks, which will aid IT managers in understanding the impacts of cybersecurity measures and facilitate quicker identification and remediation of vulnerabilities. The development is expected to strengthen the autonomy of healthcare IT teams in defending against cyber threats, ultimately ensuring uninterrupted patient care. Collaborations with major healthcare providers like Michigan Medicine and Massachusetts General Hospital highlight the project's potential for widespread application within the industry.
Jan 21, 2026·Cybersecurity Dive
A recent report by Axis Capital highlights a significant rift between CEOs and CISOs regarding the effectiveness of artificial intelligence (AI) in cybersecurity. While 30% of CEOs are optimistic about AI's role in strengthening defenses, only 20% of CISOs share this belief, reflecting a notable discrepancy in trust and perception of AI's risks, particularly around data leakage and shadow AI. This divide points to a complex relationship between corporate leadership and cybersecurity experts, which may affect how AI is adopted and implemented in healthcare settings. Understanding these differing viewpoints is crucial for healthcare professionals as they navigate the integration of AI tools in protecting sensitive patient data and responding to emerging cyber threats.
Jan 20, 2026·CSO Online
The article emphasizes that the primary challenge in cybersecurity is rooted in organizational culture rather than technology, as cultural issues such as weak password policies and disregard for security protocols can severely compromise security efforts. It highlights that even well-developed security strategies can fail if the underlying organizational culture does not genuinely support adherence to these measures, exemplified by a financial firm's vulnerability to phishing despite robust protocols. The distinction between observable culture (policies and training) and non-observable culture (employees' beliefs and attitudes) indicates that effective cybersecurity requires more than just compliance; it necessitates a shift in mindset at all levels of the organization. This insight carries significant implications for healthcare professionals, who must cultivate a secure culture that prioritizes cybersecurity to protect sensitive patient data.
Jan 20, 2026·Cybersecurity Dive
A recently identified vulnerability in Fortinet FortiSIEM, designated CVE-2025-64155, enables attackers to execute unauthorized commands due to improper neutralization of elements within the operating system. Disclosed in August 2025 but only recently made public, this flaw is being actively exploited by threat groups, highlighting ongoing security concerns within the FortiSIEM architecture. Previous vulnerabilities in the phMonitor component suggest a troubling trend of inadequate security measures, raising significant implications for healthcare professionals relying on Fortinet products to safeguard sensitive patient data. As these vulnerabilities persist, healthcare organizations must prioritize both immediate corrective actions and long-term strategic enhancements to their cybersecurity protocols.
Jan 19, 2026·PromptArmor
that the security vulnerability in the Claude Cowork AI agent developed by Anthropic poses a significant risk to users, particularly in healthcare, where sensitive information is frequently handled. Despite identification of the flaw, Anthropic has not yet implemented a fix, placing the responsibility on users to safeguard their data. This raises concerns about the adequacy of security protocols in artificial intelligence tools and highlights the urgent need for better safeguards to protect against unauthorized data access. For healthcare professionals, the situation underscores the critical importance of evaluating the security implications of AI technology before integration into clinical workflows.
Jan 18, 2026·Nextgov
Top officials in the Trump administration are considering withdrawing from the upcoming RSAC Conference due to the appointment of Jen Easterly, a Biden-era cybersecurity leader, as its CEO. This potential boycott underscores ongoing political tensions in cybersecurity, particularly given Easterly's controversial past among certain political factions. The discussions among key White House cybersecurity officials over attendance may reflect broader implications for collaboration across party lines in addressing national cyber threats. The situation highlights the critical role of leadership continuity and political dynamics in shaping cybersecurity initiatives and events.
Jan 15, 2026·Cyberscoop
The Department of Homeland Security (DHS) is finalizing plans for the Alliance of National Councils for Homeland Operational Resilience (ANCHOR), which will replace the disbanded Critical Infrastructure Partnership Advisory Council (CIPAC). This new body aims to enhance communication among federal agencies and industry stakeholders to address threats to critical infrastructure, including cyber attacks. ANCHOR is designed to improve operational efficiency by streamlining processes and increasing transparency, addressing past limitations of CIPAC's bureaucratic structure. The implications for healthcare technology are significant, as better coordination can help safeguard sensitive healthcare data and improve response strategies to cyber threats affecting the sector.
Jan 14, 2026·Cybersecurity Dive
In 2025, the healthcare sector experienced a troubling increase in security breaches, doubling the figures from the previous year, primarily due to ransomware attacks and third-party risks that are jeopardizing operational stability. Notably, while the number of exposed patient records decreased, the industry remains plagued by low confidence in vendor risk assessments and incident response capabilities. A report from Fortified Health Security underscores the urgent need for healthcare organizations to develop robust cybersecurity programs that accommodate high employee turnover, ensuring the preservation of essential knowledge and consistent incident management. This highlights a critical gap in healthcare technology that must be addressed to enhance resilience against evolving cyber threats.
Jan 13, 2026·Cybersecurity Dive
The Cybersecurity and Infrastructure Security Agency (CISA) is encountering significant difficulties as it approaches 2026, largely due to workforce cuts, resource constraints, and diminished partnerships, which hinder its capacity to protect U.S. critical infrastructure. The loss of personnel dedicated to outreach and strategic planning, alongside funding shortages, has created vulnerabilities in national security, particularly in the face of rising cyber threats from geopolitical adversaries like China. Additionally, CISA is tasked with implementing the Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA), a challenge that underscores the importance of strengthening relationships and enhancing information-sharing with infrastructure operators. As healthcare becomes increasingly reliant on digital systems, CISA's limitations could have serious implications for the protection of health technology and data privacy.
Jan 13, 2026·PR Newswire
Epic and several healthcare providers have filed a federal lawsuit against Health Gorilla and other companies for allegedly misusing nearly 300,000 patient records obtained without consent, which they claim were exploited for marketing purposes. The lawsuit accuses the defendants of operating as organized syndicates and using deceptive tactics, such as fictitious websites and false identifiers, to mask their true intentions. This legal action underscores significant concerns over patient privacy, data security, and the integrity of electronic health records (EHR), highlighting the need for stronger protections against unauthorized access and misuse of sensitive medical information in the healthcare sector. The implications of this case may drive policy changes and reinforce the importance of safeguarding patient data in an increasingly digital healthcare landscape.
Jan 12, 2026·Cybersecurity Dive
A critical vulnerability in the n8n workflow automation platform, identified as CVE-2026-21858, presents a severe risk to thousands of systems due to a "content-type confusion" bug that allows attackers to bypass automation processes. This flaw, rated with a severity score of 10, could potentially grant unauthorized access to sensitive credentials from major platforms, including Salesforce and AWS. With over 59,500 instances initially identified as vulnerable, healthcare professionals utilizing n8n in enterprise environments must prioritize updating to version 1.121.0, released to mitigate this significant threat. The situation highlights the urgent need for continuous monitoring and patch management in healthcare technology to protect sensitive data in an increasingly automated landscape.
Jan 11, 2026·CNBC
CrowdStrike's acquisition of identity management startup SGNL for $740 million aims to strengthen its cybersecurity framework amid rising AI-driven cyberattacks. By integrating SGNL into its Falcon cloud security platform, CrowdStrike seeks to enhance identity access management and real-time risk assessments, addressing a critical area in the identity security market, which was valued at $435 million as of the second quarter. Despite the strategic importance of this acquisition, CrowdStrike's shares fell by 3%, indicating possible investor skepticism about the deal's immediate impact. The move highlights the pressing need for healthcare organizations to bolster their identity security measures in light of sophisticated cyber threats targeting sensitive data.
Jan 11, 2026·Cyberscoop
The Trump administration's withdrawal from key international organizations focused on cybersecurity, including the Global Forum on Cyber Expertise and the Online Freedom Coalition, raises significant concerns for healthcare technology and critical infrastructure protection. This disengagement aims to align with U.S. interests as defined by the administration but may inadvertently undermine collaborative efforts essential for addressing cyber threats and ensuring the security of healthcare systems. Experts warn that such a move could diminish the effectiveness of global cybersecurity strategies, which are vital as the frequency and sophistication of cyberattacks continue to escalate. For healthcare professionals, this implies potential vulnerabilities in securing sensitive patient data and operational integrity in an increasingly interconnected digital landscape.