Search site
Find podcasts, news, articles, webinars, and contributors in one search.
Health IT News
Browse by topic
Most-read stories in the last 7 days
1,000 stories
May 9, 2025·Healthcare IT News
The U.S. Department of Commerce has released Version 1.1 of the NIST Privacy Framework (PFW), aimed at enhancing user data protection in the face of increasing cyber threats. This update aligns more closely with the Cybersecurity Framework (CSF) 2.0, allowing organizations to better integrate privacy risk management with cybersecurity practices. Key revisions include clearer concepts and strategies for managing privacy risks, an emphasis on artificial intelligence, and a new online guide for organizations. Originally launched in 2020, the PFW is designed to support ethical decision-making in the use of personal data while addressing feedback from various stakeholders.
May 9, 2025·Cybersecurity Dive
CrowdStrike has announced a reduction of 500 jobs, or 5% of its global workforce, to enhance operational efficiency and support its goal of $10 billion in annual recurring revenue. CEO George Kurtz highlighted the impact of rapid advancements in AI and evolving customer demands as key factors in this decision. While layoffs are being implemented, the company plans to continue hiring in customer-facing and product-engineering roles. The move comes amid heightened competition in the cybersecurity sector, marked by aggressive strategies from rivals and challenges such as a significant IT outage that affected millions of devices.
May 9, 2025·Drex DeFord
John Kindervag, a key figure in cybersecurity, promotes an ethical approach to hacking that focuses on constructive engagement to improve security systems. He advocates for organizations to adopt proactive security measures and foster a culture of security awareness among employees to effectively mitigate risks. Kindervag also highlights the need for continuous learning and adaptation to address sophisticated cyber threats, indicating a shift toward collaboration and knowledge-sharing in the industry. His perspective underscores the importance of ethical hacking in enhancing security rather than merely reacting to breaches.
May 6, 2025·BankInfoSecurity
Ascension Health, a Catholic hospital chain based in Missouri, is notifying hundreds of thousands of individuals across several states about multiple hacking incidents affecting third-party vendors. Recent breaches have occurred in Texas, Alabama, Michigan, Indiana, Tennessee, and Massachusetts, with around 116,000 Texas residents impacted by an incident involving the inadvertent disclosure of patient information due to third-party software vulnerabilities. In addition, another breach related to a Missouri law firm has resulted in unauthorized access to sensitive personal data. Ascension has filed breach reports with state regulators, although details on the specific breaches and affected individuals are still coming to light.
May 6, 2025·CyberNews
A study by Cybernews examining over 19 billion passwords has revealed a troubling trend of weak password reuse, with 94% of passwords being reused or duplicated. The analysis shows that users often prefer passwords of 8 to 10 characters, with eight characters being the most common. Many passwords consist solely of lowercase letters and digits, increasing vulnerability to cyberattacks. Despite ongoing educational efforts about password security, predictable and weak passwords remain prevalent, with users frequently choosing simple options like "password" and using common names or positive words, further compromising their security.
May 6, 2025·healthsystemcio.com
Gordon Groschl, CISO and Director of Healthcare Technology Management at Texas Children’s Hospital, is addressing the challenge of securing biomedical equipment amidst a rapidly changing healthcare IT environment. He leads a team of over 70 professionals focused on enhancing the cybersecurity of increasingly interconnected medical devices, which often pose vulnerabilities due to outdated systems and vendor restrictions. Texas Children’s has reorganized its biomedical engineering under the IT department to prioritize cybersecurity, and Groschl is spearheading efforts to align clinical workflows with IT governance. His team has conducted a cyber-readiness audit to pinpoint areas needing improvement, particularly in vulnerability management and access controls, while implementing stricter vendor access policies to protect the hospital’s network.
May 5, 2025·Bleeping Computer
Microsoft is transitioning to a "passwordless by default" strategy for all new accounts to improve security against phishing and other common cyber threats. This initiative follows enhancements to sign-in experiences on web and mobile platforms, prioritizing passwordless and passkey authentication methods. Users will have various options to access their accounts without a password, and existing users can delete their passwords if they choose. Microsoft encourages the use of passkeys that leverage biometric authentication, and reports a 20% reduction in password usage during their trials, aiming for further declines in traditional password reliance as adoption increases.
May 5, 2025·Cybersecurity Dive
President Donald Trump has proposed a 17% budget cut for the Cybersecurity and Infrastructure Security Agency (CISA) as part of his Fiscal Year 2026 spending plan, reducing its funding by $491 million. This proposal stems from his claims that CISA has engaged in censorship against conservatives, particularly in its efforts to combat misinformation and disinformation, which would be eliminated under the budget cuts. The Office of Management and Budget Director, Russell Vought, supported this narrative, accusing CISA of being part of a "Censorship Industrial Complex" and mismanaging its resources. However, former CISA executive director Brandon Wales pointed out that the agency's budget for misinformation initiatives was minimal, casting doubt on the validity of the proposed cuts.
May 4, 2025·LinkedIn
Houston Methodist's Data Governance/Sharing Committee plays a critical role in balancing innovation in healthcare with the management of associated risks. Composed of experts in IT security, compliance, and health care law, the committee identifies potential risks of new initiatives and recommends strategies for mitigation, fostering safer project advancements. By promoting cross-functional collaboration and aligning with the latest technological developments, the committee enhances responsible data management and ensures that advancements in patient care do not compromise safety, compliance, or patient rights.
May 4, 2025·Healthcare IT News
Healthcare organizations are urged to implement a privileged access model to mitigate ransomware threats, a strategy that necessitates collaboration between IT and security teams and organization-wide support. Erik Decker, Chief Information Security Officer at Intermountain Health, underscores the importance of safeguarding systems like Active Directory, which are commonly targeted by attackers seeking to escalate privileges and access sensitive information. By adopting a secure-by-design approach grounded in established security principles, Intermountain Health aims to reduce credential exposure and bolster its cybersecurity defenses against tactics frequently employed by cybercriminals.
May 4, 2025·Becker's Hospital Review
Vermont has enacted a new bill requiring all hospitals to create comprehensive security plans to prevent workplace violence, effective July 1. Signed by Governor Phil Scott, the law mandates hospitals to form development teams that include healthcare workers and law enforcement, ensuring a collaborative approach to security informed by a risk assessment. Additionally, hospitals must appoint a trained employee in trauma-informed care and victim support to facilitate communication with law enforcement in violent incidents, aiming to enhance safety for both staff and patients.
May 1, 2025·WWMT
Ascension has disclosed a security incident affecting patient data at multiple care sites across five states, attributed to an inadvertent disclosure to a former business partner due to a vulnerability in third-party software. Identified on December 5, 2024, the breach potentially involved the theft of sensitive patient information, including personal and clinical details. Despite the seriousness of the situation, Ascension confirmed that its own systems and electronic health records were not compromised. The affected states are Alabama, Michigan, Indiana, Tennessee, and Texas, with an investigation concluding on January 21 revealing the specifics of the data exposed.
May 1, 2025·CSO
Recent reports from Mandiant and Verizon highlight a notable shift in cyberattack trends in 2024, with stolen credentials and perimeter exploits emerging as prominent methods, while phishing attacks have decreased. Mandiant's data indicates that stolen credentials were involved in 16% of breaches, overtaking phishing at 14%. The report underscores the growing use of infostealers and keyloggers for credential theft and emphasizes the necessity of multifactor authentication (MFA) for protection. Exploited vulnerabilities remain the main form of initial access, now responsible for a third of intrusions, with an increasing focus on zero-day vulnerabilities in security devices. Financial motivations are evident, with 35% of attacks driven by profit, and data theft linked to 37% of incidents.
May 1, 2025·CNN
Michael Scheuer, a former Disney menu production manager, has been sentenced to three years in prison for hacking into the company's servers and altering restaurant menus, which included falsifying allergen information and inserting profane language. He was ordered to pay nearly $690,000 in restitution after pleading guilty to computer fraud and aggravated identity theft. Scheuer’s actions raised concerns about public health and safety, particularly due to manipulated allergen information that could have endangered individuals with allergies. Disney identified and corrected all alterations before they affected restaurant operations, but Scheuer's misconduct also included disabling employee accounts, disrupting the menu creation system, and necessitating the application’s removal for restoration.
Apr 30, 2025·Censinet
The February 2024 ransomware attack on Change Healthcare underscored significant vulnerabilities in the healthcare sector, revealing how connected systems can disrupt care delivery and patient safety. In light of rising cybersecurity threats, organizations are increasingly adopting established frameworks like the NIST Cybersecurity Framework 2.0 to enhance their cybersecurity preparedness. The 2025 Healthcare Cybersecurity Benchmarking Study highlights ongoing gaps in areas like third-party risk management and asset management, stressing the need for improved resilience. Based on a survey of 69 healthcare and payer organizations, the study correlates cybersecurity practices with factors such as insurance premiums, spending, and staffing.
Apr 30, 2025·Cybersecurity Dive
During her keynote address at the RSAC Conference in San Francisco, Homeland Security Secretary Kristi Noem outlined a strategic redirection for the Cybersecurity and Infrastructure Security Agency (CISA), stressing the need to realign its efforts with its original mission of countering cyber threats. She criticized CISA for diverging from this purpose, particularly as the agency faces staffing challenges amid concerns over job cuts and resignations. Notably, Noem emphasized the rising risks posed by Chinese hackers to small businesses and local governments, advocating for enhanced resilience and secure technology development as part of the Trump administration's cybersecurity strategy.
Apr 30, 2025·SecurityWeek
JPMorgan Chase's Chief Information Security Officer (CISO) has warned organizations about the increasing sophistication of cybersecurity threats, particularly as the RSA Conference approaches. This caution underscores the urgent need for businesses to enhance their security measures amid a landscape of evolving cyber risks, especially in the financial sector, which handles sensitive data. The CISO advocates for collaboration among industry leaders to share best practices and emphasizes the importance of investing in advanced technologies and training for effective threat response.
Apr 30, 2025·healthsystemcio.com
Cyberattacks are posing significant risks to the healthcare sector, prompting information security leaders to adopt the zero trust security model, which requires no user or device to be trusted by default. In a recent webinar by healthsystemCIO, experts emphasized that zero trust should be viewed as a comprehensive architectural shift rather than a mere technical update, necessitating a fundamental change in security mindset and practices. Erik Decker, CISO of Intermountain Healthcare, underscored the need for organizations to rethink their entire security architecture in light of potential adversarial threats, while Greg Garneau from Hospital Sisters Health System pointed out the obsolescence of relying solely on secure network perimeters. The implementation of zero trust in legacy systems is complex, with challenges arising from outdated devices and infrastructures, highlighting the necessity for a strategic, phased approach.
Apr 29, 2025·Cyberscoop
The 2024 FBI Internet Crime Complaint Center (IC3) report indicates a significant surge in cybercrime, with reported losses totaling $16.6 billion—an all-time high. The IC3 received 859,532 complaints in the past year, showing a 33% increase compared to the previous year, and averaging approximately $19,372 per complaint. Cyber-enabled fraud was the primary driver of these losses, with a dominant focus on investment fraud, which alone accounted for $6.57 billion. The report also highlights a rising use of cryptocurrency for fraudulent schemes, complicating recovery efforts. Seniors aged 60 and over were especially affected, filing over 147,000 complaints with substantial financial losses.
Apr 28, 2025·LinkedIn
JPMorgan Chase has issued an Open Letter to its third-party suppliers warning about security risks linked to the hasty adoption of artificial intelligence (AI) technologies. The letter points out that 78% of enterprise AI implementations lack sufficient security measures, leading to a threefold increase in vulnerabilities. Chief Technology Officer Pat Opet stressed the importance of understanding the systems being deployed, particularly in the financial sector, which handles sensitive data. To mitigate risks, JPMorgan recommends AI governance frameworks, regular security testing, clear documentation for AI processes, and dedicated AI security response teams. The bank has committed $2 billion to enhance its own AI security initiatives.