Search site
Find podcasts, news, articles, webinars, and contributors in one search.
Health IT News
Browse by topic
Most-read stories in the last 7 days
1,000 stories
Apr 28, 2025·The Hacker News
In the first quarter of 2025, 159 Common Vulnerabilities and Exposures (CVEs) were reported as exploited, an increase from 151 in the previous quarter, according to VulnCheck. Of these, 28.3% were weaponized within 24 hours of disclosure, totaling 45 vulnerabilities, while another 14 were exploited within a month and 45 within a year. The majority of these vulnerabilities were found in content management systems, with notable impacts on Microsoft Windows, Broadcom VMware, and other vendors. On average, 11.4 Known Exploited Vulnerabilities were disclosed each week, equating to 53 per month.
Apr 27, 2025·SecurityWeek
Yale New Haven Health has experienced a data breach affecting approximately 5.5 million patients, prompting concerns over the security of sensitive health information. The breach was identified following unauthorized access to their systems, leading to an investigation into the extent of data exposure, which includes personal information such as names and medical records. The organization is notifying affected individuals and providing resources for monitoring potential misuse of their information while working with cybersecurity experts to strengthen their defenses. This incident underscores the ongoing vulnerabilities in the healthcare sector and the necessity for improved cybersecurity measures to protect patient trust and confidentiality.
Apr 27, 2025·Cybersecurity Dive
Madhu Gottumukkala has been appointed deputy director of the Cybersecurity and Infrastructure Security Agency (CISA) by Secretary of Homeland Security Kristi Noem. Transitioning from his role as Chief Information Officer for South Dakota, Gottumukkala will manage CISA's day-to-day operations during a challenging time that includes potential layoffs and reductions in support for local governments. His background in software engineering presents a shift from the typical homeland security experience of previous leaders, raising questions about his approach to cybersecurity and infrastructure protection. As local officials face concerns over diminished federal assistance, Gottumukkala will need to facilitate communication and identify alternative resources to support state and municipal IT needs.
Apr 27, 2025·Medical Buyer
Healthcare organizations, especially small and rural hospitals, are increasingly challenged by cybersecurity threats, according to Errol Weiss of Health-ISAC. He stresses the need for these facilities to adopt cybersecurity best practices, maintain software updates, and ensure regular system backups. Given their limited resources, smaller institutions often require support to enhance their cybersecurity posture, which Health-ISAC provides through collaboration and shared best practices. Weiss highlights the disparity in cybersecurity resources between healthcare and financial sectors, noting that hospitals often lack the personnel necessary to combat cyber threats effectively. As healthcare technology advances, maintaining a balance between innovation and robust security measures is crucial to safeguard patient data and safety, particularly with the rise of remote monitoring technologies that may introduce new vulnerabilities.
Apr 27, 2025·The Daily Beast
Pete Hegseth, the Secretary of Defense, faces criticism after his personal phone number was found exposed on the Signal messaging app, raising significant cybersecurity concerns. Experts warn that this exposure makes him susceptible to hacking and espionage, particularly given its link to sensitive military communications regarding U.S. operations in Yemen. The use of a personal number for official communications contradicts established security protocols, and its availability online poses risks of malicious exploitation. Additionally, his number's use across various platforms further complicates his digital security and increases his vulnerability to cyber threats.
Recent research from GreyNoise Intelligence indicates that threat groups are increasingly targeting older vulnerabilities, particularly in edge devices like VPNs and routers. The report states that over half of these vulnerabilities are linked to edge technologies, with nearly 70% of unpredictable vulnerabilities, known as Black Swan vulnerabilities, also affecting these devices. Approximately 40% of Black Swan vulnerabilities specifically target VPNs and routers, raising significant risks for organizations that rely on these technologies. These vulnerabilities often reemerge years after their initial disclosure and are frequently overlooked, creating opportunities for threat actors to exploit them due to their well-documented nature and lack of monitoring. Factors such as lack of awareness and reliance on outdated infrastructure contribute to the persistence of these vulnerabilities.
Apr 24, 2025·IT Brew
A new cyber threat called "fast flux" has been flagged by global agencies like the NSA and CISA, as it complicates detection for cybersecurity professionals. This tactic involves rapidly changing the IP addresses linked to a single domain, making it difficult to block malicious activities effectively. The advisory calls for increased collaboration between cybersecurity experts and Internet Service Providers (ISPs) to address the risks associated with this evasive technique, which is gaining traction amidst a rise in cybercriminal activities. Traditional blocking methods are ineffective against fast flux due to its dynamic nature, highlighting the need for improved detection and response strategies.
Apr 24, 2025·Bleeping Computer
Blue Shield of California has disclosed a data breach affecting approximately 4.7 million members, resulting from a misconfiguration of Google Analytics that exposed protected health information to Google’s advertising platforms. The breach, which occurred between April 2021 and January 2024, involved the sharing of insurance plan details and demographic information, but not sensitive data like Social Security numbers or banking information. The organization identified the misconfiguration on February 11, 2025, and has since updated members to remain vigilant regarding their personal information.
Apr 24, 2025·Knox News
Tennova Healthcare is currently dealing with a significant internal computer system outage that has forced staff to revert to manual documentation methods. The outage, caused by the accidental deletion of a crucial database by Cerner engineers during routine maintenance, has not interrupted hospital operations or services, according to marketing coordinator Rylee Sawyer. Importantly, there has been no compromise of patient data, addressing concerns about data security during this incident. Tennova operates multiple medical centers across Middle and East Tennessee.
Apr 24, 2025·CyberNews
Jeffrey Bowie, CEO of a cybersecurity firm in Edmond, Oklahoma, was arrested for allegedly installing malware on a restricted computer at SSM Health’s St. Anthony Hospital. The incident, which occurred in August 2024, was discovered when a staff member spotted Bowie using a computer meant for employees only. An investigation revealed he accessed multiple computers and installed malware that captured screenshots to send to an external address. Fortunately, hospital staff detected the unauthorized access in real-time, preventing any data breach. Bowie now faces two counts under the Oklahoma Computer Crimes Act.
Apr 24, 2025·Ohio Capital Journal
Chase Fopiano, a former police officer now focused on cybersecurity, discusses the shift in law enforcement's perception of cyber threats as technology and hacking techniques have advanced. Cyberattacks on police and government entities, once considered minor, have increased significantly, highlighting vulnerabilities within these organizations. In response, President Trump signed an executive order transferring some cybersecurity responsibilities to state and local governments, but funding cuts have hampered these efforts, leaving many states ill-equipped to handle the growing threats. Recent incidents, such as a significant cyberattack in Rhode Island that affected sensitive data, further emphasize the urgent need for improved cybersecurity measures.
Apr 22, 2025·SecurityWeek
Microsoft has improved the security of its Azure cloud platform by eliminating inactive accounts and rotating encryption keys following a nation-state hacking incident. These measures aim to decrease vulnerabilities that attackers could exploit and enhance the protection of sensitive data. The company highlights its commitment to maintaining customer trust and acknowledges the growing complexity of cyber threats, particularly from advanced nation-state actors. This initiative underscores the necessity for strong security protocols and consistent monitoring of account activity as organizations increasingly depend on cloud services.
Apr 22, 2025·Forbes
The Ghost ransomware group, a Chinese cybercriminal organization, is increasingly targeting sectors like government, healthcare, energy, and financial services, primarily in North America and the U.K., with a focus on profit-driven attacks rather than state-sponsored espionage. A joint advisory from the Cybersecurity and Infrastructure Security Agency (CISA) and the FBI warns organizations in more than 70 countries of the group's tactics, which include exploiting unpatched vulnerabilities in public-facing systems and deploying ransomware that encrypts data and threatens permanent loss if a ransom is not paid. The group's rebranding efforts complicate detection and tracking, making their activities a significant cybersecurity concern.
Apr 21, 2025·LinkedIn
Cybersecurity strategies must align closely with business objectives to effectively protect profitability, according to Dennis E. Leber, Ph.D. Organizations should first understand their revenue-generating activities and their associated technology infrastructure to identify critical systems and potential vulnerabilities. By assessing technical debt, companies can determine the value of legacy systems and focus resources on technologies that support revenue generation. This understanding enables businesses to implement targeted security measures for vital systems and improves incident response efforts, ensuring resilience and operational efficiency.
Apr 21, 2025·CISA
CISA has released guidance addressing potential unauthorized access to a legacy Oracle cloud environment, underscoring the risks linked to compromised credentials, such as usernames and passwords. While the full impact of the incident is still unclear, concerns are raised regarding the reuse of these credentials, especially when hardcoded into scripts, which complicates detection and can lead to unauthorized access. Organizations are urged to take proactive measures, including resetting passwords, reviewing source code for hardcoded credentials, monitoring authentication logs, and adopting multi-factor authentication, to mitigate the risks associated with credential compromises.
Apr 20, 2025·BankInfoSecurity
Community Dental Care, Minnesota's largest nonprofit dental practice for Medicaid patients, has informed nearly 135,000 individuals about a data breach that occurred in December 2024, involving unauthorized access to a network server. The breach potentially exposed personal and health information but was detected on December 20 and reported to federal regulators on March 28. Although the investigation pinpointed the unauthorized access around December 6, there is currently no evidence of misuse of the compromised data. The organization is offering affected individuals credit and identity monitoring services while facing potential class action lawsuits from several law firms. This incident underscores the ongoing vulnerabilities within the healthcare sector, particularly among dental practices.
Apr 17, 2025·Wired
Attorneys from the group American Oversight are suing the U.S. government regarding the use of disappearing Signal messages for military coordination in Yemen, alleging that recent court filings indicate a strategy by Trump administration officials to avoid transparency laws. They argue that these encrypted communications violate the Federal Records Act, highlighting inconsistencies in the government's preservation efforts, particularly from the CIA, which claims it has archived no meaningful communications. The issue gained attention after an unintentional group chat inclusion by The Atlantic's editor revealed discussions on military actions, prompting Freedom of Information Act requests and legal actions to preserve any non-deleted messages. Court filings also disclosed a chaotic compliance process across various agencies in response to preservation orders, resulting in significant delays.
Apr 17, 2025·Apple News
Christopher Krebs, the former head of the Cybersecurity and Infrastructure Security Agency (CISA), has left his position at cybersecurity firm SentinelOne. His departure follows an executive order from former President Trump aimed at strengthening national infrastructure security. Krebs was notable for his role in safeguarding the 2020 election from foreign interference and was dismissed for his views on election security. His leadership at CISA emphasized collaboration between public and private sectors to combat cyber threats. Krebs's exit raises concerns about how political developments may affect cybersecurity leadership and strategy within the private sector.
Apr 17, 2025·CISA
The Cybersecurity and Infrastructure Security Agency (CISA) has released guidance amid concerns of unauthorized access to a legacy Oracle cloud environment, primarily highlighting the dangers of compromised credentials. While the extent of the breach is not fully determined, the situation poses significant risks as exposed or reused credentials can lead to unauthorized access across systems. CISA warns that attackers can exploit harvested credentials for escalating privileges, accessing sensitive systems, and launching phishing campaigns. To counter these threats, organizations are advised to reset passwords for affected users, examine code for hardcoded credentials, monitor authentication logs for anomalies, and implement phishing-resistant multi-factor authentication (MFA). CISA also encourages organizations to refer to their cybersecurity resources for further best practices.
Apr 16, 2025·BankInfoSecurity
A data breach affecting 1.6 million patients linked to Planned Parenthood clinics has been reported, following unauthorized access to sensitive information at the Laboratory Services Cooperative, a nonprofit medical testing entity. The breach, which occurred in October 2024, compromised personal and health data, including names, addresses, medical records, and financial details. In response, the cooperative is offering up to 24 months of complimentary identity and credit monitoring and has set up a call center for affected individuals. The incident has raised significant concerns about identity theft and the potential misuse of the exposed data, prompting a federal investigation.