Search site
Find podcasts, news, articles, webinars, and contributors in one search.
Health IT News
Browse by topic
Most-read stories in the last 7 days
1,000 stories
Apr 6, 2025·SecurityWeek
The rise of artificial intelligence (AI) has led to the emergence of "zero-knowledge" threat actors, who utilize advanced AI technologies to execute cyberattacks with reduced risk of detection and attribution. Unlike traditional hackers, these individuals automate their attacks and meticulously cover their tracks, complicating cybersecurity responses. They exploit system vulnerabilities through sophisticated techniques, including machine learning algorithms, which enable them to bypass standard security measures. As AI evolves, organizations must adapt their cybersecurity strategies, moving towards advanced technologies and proactive threat detection to effectively combat these new threats.
Apr 6, 2025·Justice.gov
Colton Neal, a 26-year-old from Brooksville, Florida, has been sentenced to 30 months in federal prison for operating an electronic prescribing fraud scheme that spanned from June 2022 to July 2023. Neal pleaded guilty to wire fraud and aggravated identity theft after using a licensed doctor's name and National Provider Identifier to issue around 144 fraudulent electronic prescriptions for controlled substances, which he promoted on a darknet forum. Payments for these prescriptions were made through cryptocurrency, complicating the investigation conducted by federal agencies including the FBI and the Department of Health and Human Services.
Apr 3, 2025·The Register
A class action lawsuit has been filed against Oracle in Texas by plaintiff Michael Toikach, who claims the company did not properly inform customers about two serious data breaches, possibly affecting sensitive health information. Filed by Shamis & Gentile in the U.S. District Court for the Western District of Texas, the lawsuit alleges Oracle violated state laws by failing to notify affected individuals within the mandated 60-day timeframe. Concerns have been raised regarding Oracle's lack of communication about the breaches, including details of how they occurred and whether compromised data has been secured. The suit also highlights alleged deficiencies in Oracle's security measures, including inadequate network security and insufficient training on data protection.
Apr 3, 2025·Dark Reading
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is undergoing significant downsizing, having lost over 130 positions due to cost-cutting measures by the Trump administration. This reduction raises concerns about CISA's ability to provide essential cybersecurity services, particularly to state and local governments in critical areas like election security. As a result, experts are advising organizations to explore alternative cybersecurity support from the private sector, which is already stepping in with tools and services for critical infrastructure. This transition may lead to an increased dependence on private solutions, especially for smaller entities, heightening concerns about the overall security posture of the U.S. and its allies.
Apr 3, 2025·TechTarget
The Health Sector Coordinating Council (HSCC) has proposed a consultative process with cybersecurity leaders instead of moving forward with the January 2025 NPRM for the HIPAA Security Rule, citing concerns that the NPRM may not effectively address the systemic cybersecurity challenges faced by the healthcare sector. The HSCC's Cybersecurity Working Group has pointed out potential budgetary and implementation issues, advocating for a year-long consultation to develop tailored cybersecurity policies. Additionally, HSCC highlighted previous collaborative efforts with the Department of Health and Human Services (HHS) to assess hospital cybersecurity and set performance goals, arguing that the NPRM overlooks these advancements. Financially, HHS estimates that implementing the NPRM would require approximately $9 billion in the first year and $6 billion annually for the next four years.
Apr 3, 2025·CyberNews
A security breach involving a widely used iOS GPS tracking app has compromised the personal data of approximately 320,000 users, including sensitive information such as GPS locations and phone numbers. Researchers from Cybernews found that a misconfiguration in the app's Firebase database security settings, specifically the lack of password protection, allowed unauthorized access to real-time data. The breach not only exposed user locations but also revealed usernames, device details, and critical API keys, raising significant concerns about privacy and potential exploitation by cybercriminals.
Apr 2, 2025·Cybersecurity News
Apple has issued a security advisory regarding three critical zero-day vulnerabilities (CVE-2025-24200, CVE-2025-24201, and CVE-2025-24085) that are actively being exploited in cyberattacks, affecting a range of devices including iPhones, iPads, and Macs. Users are strongly advised to update their devices immediately to reduce security risks. The first vulnerability allows attackers to disable USB Restricted Mode, compromising device security, while the second affects WebKit, enabling malicious web content to bypass security measures. The third vulnerability involves a flaw in the CoreMedia component, which is critical for handling audio and video.
Apr 2, 2025·MedPage Today
A recent House hearing addressed the cybersecurity vulnerabilities of medical devices, particularly older models that may not comply with current standards. Rep. Gary Palmer emphasized the risks associated with aging technology and outdated software, noting that security issues have been highlighted by the FDA's warnings regarding patient monitors susceptible to unauthorized control. Concerns were raised about the impact of recent staff cuts at the FDA on its ability to enforce cybersecurity standards, with Rep. Yvette Clarke criticizing previous reductions that diminish the agency’s capacity to evaluate compliance with mandated improvements. Cybersecurity experts stressed the importance of a well-resourced workforce at the FDA to adapt to evolving cybersecurity threats in the medical device landscape.
Apr 2, 2025·SC World
The KnowBe4 annual Phishing Trends Report indicates that the rise of artificial intelligence is complicating the detection of phishing attacks, with a notable increase in "polymorphic" phishing campaigns that produce similar but slightly altered messages to bypass security filters. These attacks have led to a 47% rise in undetected phishing attempts, as traditional security technologies struggle to differentiate between known threats and the more sophisticated tactics used in these attacks. The report also reveals a concerning trend of internal phishing threats, including incidents involving North Korean threat actors who impersonate new employees using AI-generated imagery and stolen identification.
Apr 1, 2025·Cybernews
A recent report has revealed the rising threat of browser-native ransomware, which signifies a shift in cybercrime tactics as more applications function within web browsers. With ransomware causing $276 billion in losses over the past five years, the accessibility of enterprise data through cloud storage and SaaS solutions is creating new vulnerabilities. Browser-native ransomware operates stealthily within browsers, eluding traditional detection tools that focus on device file downloads, and can potentially target identities across various applications, amplifying its impact. The report by SquareX presents three hypothetical scenarios demonstrating how such attacks could occur, highlighting the urgent need for enhanced cybersecurity measures.
Apr 1, 2025·HackRead
A data leak involving around 2.87 billion Twitter (now X) user profiles has reportedly occurred, attributed to an insider during company layoffs. The incident, disclosed by a user named ThinkingOne on Breach Forums, could constitute the largest social media data breach to date, although X has not confirmed the breach. The leaked data includes extensive metadata, such as user IDs, display names, and activity counts, but does not contain email addresses, raising concerns about potential phishing and identity theft. ThinkingOne has also combined this leak with a previous 2023 breach, creating a merged file that includes sensitive email information.
Mar 31, 2025·SonicWall
The healthcare industry is increasingly vulnerable to cybersecurity threats due to its handling of sensitive patient data and the urgent nature of its services, according to Michael Prakhye, CISO at Adventist Health. Cybercriminals frequently target healthcare organizations, exploiting their willingness to pay ransoms quickly and often using third-party vendors to infiltrate networks. This risk underscores the need for stringent security measures, especially concerning external partnerships. Ransomware attacks and data breaches pose significant threats, leading to potential legal and financial repercussions, which necessitate ongoing adaptation and proactive defense strategies. While advancements in artificial intelligence offer promise for improved healthcare outcomes, their adoption requires careful attention to security and ethical considerations.
Mar 31, 2025·doublepulsar.com
Oracle is under scrutiny for its handling of a cybersecurity breach involving its cloud SaaS services, after a threat actor known as rose87168 claimed to have accessed sensitive customer data. Initially, Oracle denied any breach and claimed no customer data was compromised. However, the threat actor provided evidence, including an internal meeting recording discussing security issues and leaked employee email addresses, which was later corroborated by cybersecurity firms. This has raised concerns about the security of Oracle's systems and the integrity of customer data, leading to a diminished trust in the company's security protocols as the threat actor continues to release sensitive information.
Mar 30, 2025·Cybersecurity Dive
Cybersecurity firms are increasing vigilance following allegations of a significant breach involving Oracle Cloud, where an attacker is said to have stolen 6 million data records, including user credentials for over 140,000 customers. Despite Oracle's initial denials, evidence from security researchers suggests a critical vulnerability was exploited, prompting firms like Rapid7 to assess potential impacts. Rapid7, while reporting minimal use of Oracle Cloud, is proactively rotating credentials for test accounts as a precaution. Researchers from CloudSEK are analyzing data linked to the breach to verify claims and underscore the ongoing security risks related to the identified vulnerability.
Mar 30, 2025·LinkedIn
Aaron DeSpain's recent post discusses the significance of cybersecurity in healthcare, focusing on the need to protect patient data and ensure system safety amid rising cyber threats. It highlights the critical role of Chief Information Security Officers (CISOs) in implementing robust security measures to prevent unauthorized access to sensitive information, which can compromise both patient safety and healthcare provider integrity. DeSpain emphasizes the evolving challenges in the field and stresses the necessity for healthcare organizations to adapt their cybersecurity strategies and comply with regulations to effectively mitigate risks. Overall, the post advocates for increased awareness and proactive collaboration in addressing cybersecurity threats in the healthcare sector.
Mar 27, 2025·BankInfoSecurity
The U.S. Department of Health and Human Services (HHS) is restarting HIPAA compliance audits for the first time since 2016-2017, with a focus on cybersecurity threats, particularly ransomware and hacking. These audits will involve 50 healthcare organizations and business associates, driven by a significant rise in reported hacking and ransomware incidents. The initiative aims to evaluate compliance with the HIPAA Security Rule provisions essential for preventing data breaches, responding to a notable 30% increase in hacking and a 45% rise in ransomware attacks from 2020 to 2024. Specific details regarding the audit criteria and selection process have not been disclosed, as the project resumes after a period of dormancy due to resource limitations.
Mar 27, 2025·AHA
The FBI has confirmed that there are no specific credible threats against U.S. hospitals following an investigation prompted by a social media post suggesting a coordinated attack. The American Hospital Association (AHA) and the Health Information Sharing and Analysis Center (Health-ISAC) had previously alerted healthcare facilities about the unverified threats. In response, they advised hospitals to maintain vigilance and security measures to deter potential violence, emphasizing the importance of reporting any suspicious activities to local law enforcement.
Mar 26, 2025·Politico
Democrats on the Senate Intelligence Committee criticized the Trump administration's handling of classified information during a recent hearing, following revelations about military strategy discussions in a Signal group chat that included non-official personnel. Ranking member Mark Warner (D-Va.) pointed to this incident as an example of "sloppy" governance under Trump. Notably, CIA Director John Ratcliffe acknowledged his involvement in the chat while defending its appropriateness for work discussions, despite concerns over the potential exposure of sensitive information, including the identity of an active intelligence officer. Senator Michael Bennet (D-Colo.) condemned Ratcliffe's actions, highlighting the risks of such communications—especially when officials are in sensitive locations like Moscow.
Mar 26, 2025·Yahoo Finance
As tax season approaches, scammers are increasingly targeting individuals with a range of deceptive tactics, exploiting the urgency of filing deadlines and sensitive financial information. Experts warn of impersonation schemes, including lookalike communications from the IRS and fraudulent offers on social media, which create false urgency and fear. Additionally, "ghost" tax preparers pose a significant risk by preparing returns without signing them, often filing fraudulent claims to redirect refunds to their own accounts. With recent staff reductions at the IRS potentially limiting their response capabilities, vigilance is critical as the April 15 deadline approaches.
Mar 25, 2025·Security Affairs
The FBI has alerted the public to a growing trend of scams involving free online document converters, which cybercriminals are using to distribute malware. These seemingly legitimate tools can infect users' systems and steal sensitive information, potentially leading to serious issues like identity theft and ransomware attacks. The FBI advises users to be cautious, keep antivirus software updated, and report any incidents they encounter. If victimized, individuals should secure their accounts and change passwords from a trusted device.