Search site
Find podcasts, news, articles, webinars, and contributors in one search.
Health IT News
Browse by topic
Most-read stories in the last 7 days
1,000 stories
Apr 16, 2025·Ars Technica
Microsoft's Recall, an AI tool in Windows 11 that tracks and stores user activity every three seconds, is facing renewed scrutiny as it returns after a temporary suspension. Initially launched in May 2024, Recall drew significant backlash over privacy concerns, particularly its risks for users of sensitive messaging apps and potential misuse by malicious insiders. Despite Microsoft’s assurances that users must opt-in and authenticate through Windows Hello to access stored snapshots, critics remain unconvinced that these measures effectively address the underlying security issues. Recall is currently available to insiders using the Windows 11 Build 26100.3902 preview version.
Apr 16, 2025·Cybersecurity Dive
The Cybersecurity and Infrastructure Security Agency (CISA) has renewed funding for the Common Vulnerabilities and Exposures (CVE) program for an additional 11 months, ensuring the continued tracking of software vulnerabilities. This agreement follows warnings from Mitre Corporation regarding the potential expiration of funding, which raised concerns among cybersecurity professionals about the risks posed by delayed vulnerability disclosures. Experts warned that funding lapses could exacerbate backlogs in addressing security flaws, increasing exposure to exploitation by criminal and state-sponsored actors.
Apr 16, 2025·BankInfoSecurity
Northeast Radiology has agreed to a $350,000 settlement to resolve potential HIPAA violations stemming from a hacking incident that compromised the data of nearly 300,000 patients. The U.S. Department of Health and Human Services' Office for Civil Rights found that the practice failed to perform an adequate risk analysis to protect electronic protected health information. The settlement mandates a corrective action plan, which will be monitored for two years, and requires the practice to conduct a comprehensive HIPAA security risk analysis.
Apr 15, 2025·Cybersecurity Dive
Over 14,000 Fortinet devices globally have been compromised through a new post-exploitation technique that allows attackers to maintain access even after security patches are applied. The Shadowserver Foundation indicated that exploitations of known vulnerabilities—CVE-2022-42475, CVE-2023-27997, and CVE-2024-21762—allowed for unauthorized access, with a symlink-based persistence mechanism enabling continued access to sensitive files. The majority of affected devices are located in Asia, particularly in the United States, Japan, Taiwan, and China. In light of these risks, CERT NZ has issued an advisory on the ongoing exploitation of Fortinet vulnerabilities since 2023.
Apr 15, 2025·BankInfoSecurity
DaVita Inc. has reported a ransomware attack affecting its operations across its network of over 3,100 dialysis centers in the U.S. and 13 other countries. The company activated its response protocols and is working with cybersecurity experts to isolate impacted systems and assess the situation after becoming aware of the incident over the weekend. While DaVita continues to provide patient care and has contingency plans in place, it has not fully determined the extent of the disruption or its potential impact on patient services. Experts express concerns about the risks associated with the attack, particularly regarding the potential encryption of patient records and associated sensitive information.
Apr 14, 2025·Record
During a recent Senate Armed Services cyber subcommittee hearing, Lt. Gen. William Hartman, the acting head of U.S. Cyber Command and the NSA, responded to inquiries regarding the dismissal of his predecessor, Gen. Timothy Haugh, which raised bipartisan concerns about leadership stability in cybersecurity. The hearing, under an hour long and with limited attendance, also addressed Cyber Command’s modernization initiative, "CYBERCOM 2.0," and questioned the effectiveness of the dual leadership structure of Cyber Command and the NSA, which Hartman defended as essential for national security. He further discussed the threat posed by foreign hacking groups, notably from China, targeting critical infrastructure.
Apr 14, 2025·KLAS Research
the integration of artificial intelligence in healthcare cybersecurity is becoming increasingly important. The 2025 Healthcare Cybersecurity Benchmarking Study reveals that, despite some organizations making strides in adopting established frameworks like the NIST Cybersecurity Framework 2.0, a significant number still take a reactive approach to threats. Following a major breach at Change Healthcare in 2024, vulnerabilities within interconnected health systems and third-party vendors were spotlighted. The study highlights the need for improved practices in areas such as Supply Chain Risk Management and Asset Management, while organizations using the NIST framework reportedly experience less drastic increases in cybersecurity insurance costs.
Apr 13, 2025·NBC News
U.S. cybersecurity officials are facing increased vulnerability following President Trump's order for a Justice Department investigation into Chris Krebs, the former director of the Cybersecurity and Infrastructure Security Agency (CISA). This order, perceived as politically motivated, has created discontent within CISA amid recent downsizing and has hindered employees' ability to focus on their mission of safeguarding the nation from cybersecurity threats. With rising dangers from foreign adversaries and ransomware attacks, the tumult within CISA raises concerns about the agency's capacity to effectively respond to these challenges.
Apr 13, 2025·Reuters
UnitedHealth Group is demanding that healthcare providers repay approximately $9 billion in loans issued following a ransomware attack on its tech unit, Change Healthcare, in February 2022. Providers received repayment notices from UnitedHealth's Optum unit, warning that failure to comply could result in withheld reimbursements. Many providers are grappling with financial difficulties caused by the cyberattack's disruptions, and they express concern that the repayment demands take advantage of their ongoing hardships. Change Healthcare has indicated a willingness to explore repayment options with providers, but initial agreements included clauses that could penalize non-repayment.
Apr 10, 2025·The Register
The Cybersecurity and Infrastructure Security Agency (CISA) is undergoing significant staff cuts, potentially impacting nearly 1,300 employees, which has raised concerns among cybersecurity experts and lawmakers about the implications for national security. Critics, including retired Rear Admiral Mark Montgomery, argue that these layoffs will disrupt essential operations and collaborations between government and the private sector, thereby weakening defenses against increasing cyber threats. Additionally, CISA has slashed funding for important programs like the Multi-State Information Sharing and Analysis Center (MS-ISAC), further threatening the agency's ability to provide effective threat detection and response services at state and local levels.
Apr 10, 2025·Mercury News
Kaiser Permanente has dismissed its security chief amid an ongoing investigation into a significant database breach that compromised sensitive patient information. This incident has raised concerns regarding the organization's compliance with data protection laws and the adequacy of its security measures. Patients and advocacy groups are demanding transparency and accountability, as the breach has sparked outrage. Legal experts warn that Kaiser Permanente may face serious repercussions, including fines and lawsuits, which could harm its reputation and trust with stakeholders. The situation is under close scrutiny as the organization works to address the breach and implement measures to prevent future occurrences.
Apr 9, 2025·GlobeNewswire
In 2024, healthcare data breaches affected over 276 million records, a 64.1% increase from the previous year and impacting 81.38% of the U.S. population. A report by Cybernews Business Digital Index reveals significant shortcomings in cybersecurity among major U.S. hospitals, with 79% receiving D grades or worse in assessments. The report indicates that 65% of the top 100 hospitals have faced data breaches, while 30% show critical vulnerabilities. Overall, 45% are categorized as high risk, and only 5% achieved an A score, with an average security score of 72 out of 100. Key security issues include inadequacies in SSL/TLS configurations, essential for safeguarding sensitive patient data.
Apr 9, 2025·InformationWeek
CIOs and CISOs in healthcare are addressing the fallout from breaches involving Oracle Health's Cerner Legacy servers, which have compromised patient data. Although Oracle has not confirmed the breaches, sources indicate hackers targeted these outdated systems, which still hold sensitive information yet to be migrated to the cloud. The lack of transparency from Oracle has raised concerns, especially as the full extent of the breach remains unreported to the U.S. Department of Health and Human Services. Experts like Scott Mattila emphasize the risks of legacy systems, which are appealing to cybercriminals due to weak security. Healthcare leaders are encouraged to activate incident response plans, enhance monitoring for unusual activities, and strengthen access management as they navigate these cybersecurity challenges.
Apr 9, 2025·Becker's Hospital Review
Sentara Health has disclosed a privacy incident involving a former remote employee, prompting notifications to patients whose personal data may have been improperly accessed during a suspected cyber scam. The issues began shortly after hiring the employee, when management raised doubts about their identity following a virtual meeting. An investigation suggested the employee may have been part of a job-sharing scam, leading to their termination. However, Sentara has not confirmed if the individual accessing patient information was indeed the hired employee. The compromised data includes sensitive details like names, birth dates, and Social Security numbers, raising significant privacy concerns for the affected patients. Sentara has publicly committed to enhancing data security and has expressed regret over the incident.
Apr 8, 2025·SecurityWeek
The rise of artificial intelligence (AI) has given rise to "zero-knowledge" threat actors, who utilize advanced AI tools to conduct cyberattacks with limited prior knowledge of their targets. Unlike traditional hackers who rely on reconnaissance, these actors automate vulnerability identification and attack execution, increasing their efficiency and danger. They employ AI techniques to develop sophisticated phishing schemes, automate social engineering tactics, and produce adaptive malware, challenging existing cybersecurity defenses. As organizations integrate AI into their operations, they inadvertently create new vulnerabilities, necessitating that cybersecurity teams remain proactive and continuously update their strategies to effectively counter these evolving threats.
Apr 7, 2025·Nextgov
The Cybersecurity and Infrastructure Security Agency (CISA) is set to reduce its workforce, potentially laying off around 1,300 employees, mainly from its industry contracting teams. These cuts are seen as part of an effort to streamline the agency amid criticism from the Trump administration over its focus on online disinformation and election security. The layoffs may also include the termination of private sector threat-hunting contracts, raising concerns among cybersecurity experts about the potential negative impact on national security and public-private collaboration in defending critical infrastructure.
Apr 7, 2025·LinkedIn
Despite increased investments in cybersecurity technologies, 74% of data breaches are still attributed to human factors, according to IT executive Joey Meneses. He argues that traditional security measures fail to address the psychological tactics used by cybercriminals, such as social engineering. Meneses advocates for a shift in perspective, viewing employees as security assets rather than liabilities, and recommends a human-focused security strategy encompassing relevant training, applied learning through simulations, and cultural integration for a security-minded environment. Organizations adopting these strategies have seen notable improvements, including a 60-75% decline in successful phishing attacks and an 82% rise in security incident reporting, highlighting the importance of creating a culture of security awareness.
Apr 6, 2025·BankInfoSecurity
The Health Sector Coordinating Council (HSCC) is calling on the Trump administration to abandon proposed updates to the HIPAA security rule initiated during the final days of the Biden administration. HSCC urges for a collaborative approach among the White House, federal regulators, and healthcare leaders to develop feasible and effective cybersecurity standards that promote patient safety. Executive Director Greg Garcia highlights concerns about the potential impracticality and costs of the proposed regulations, which may confuse compliance efforts. The HSCC has submitted a policy proposal advocating for a year-long dialogue to establish best practice cybersecurity requirements instead of developing strict regulations in isolation.
Apr 6, 2025·Newsweek
A lawsuit against the University of Maryland Medical Center alleges that pharmacist Matthew Bathula installed spyware on hospital computers to secretly monitor female medical personnel, including capturing video footage of them in private moments and accessing their home security cameras. The complaint, filed by six women who claim emotional distress as a result of these invasions, highlights concerns about privacy violations within the healthcare environment and calls into question the adequacy of current security measures. While Bathula has not been identified as a defendant or faced criminal charges, the case underscores the potential risks of technology misuse in medical settings and the need for enhanced oversight and regulations.
Apr 6, 2025·Cybersecurity Dive
concerns about the effectiveness of national cybersecurity measures. The 22 House members' letter to Commerce Secretary Howard Lutnick underscores the potential risks associated with losing experienced personnel at NIST, as it may hinder the establishment of vital cybersecurity standards and overall technological advancements. This situation reflects a broader trend of workforce reductions within federal agencies, including the Cybersecurity and Infrastructure Security Agency (CISA), raising alarms about the overall impact on the U.S. ability to maintain leadership in critical tech sectors.