Search site
Find podcasts, news, articles, webinars, and contributors in one search.
Health IT News
Browse by topic
Most-read stories in the last 7 days
1,000 stories
Mar 24, 2025·HIPAA Journal
On March 17, 2025, Nebraska Governor Jim Pillen enacted Legislative Bill 241, which limits private companies' liability in class action lawsuits stemming from cybersecurity incidents, reflecting a nationwide trend to protect businesses from the financial repercussions of data breaches. The law stipulates that such lawsuits are only permissible if there is evidence of willful or grossly negligent conduct by the company, encouraging organizations to adopt better cybersecurity practices without the fear of excessive legal repercussions. However, this protection does not apply to regulatory actions, such as those related to HIPAA violations, and it defines private companies broadly to include various entities affected by adverse cyber events.
Mar 24, 2025·CSO Online
A security breach involving Oracle Cloud has exposed sensitive records from over 140,000 enterprise customers due to a vulnerability in Oracle Access Manager. Discovered by CloudSEK's XVigil team, the breach resulted in the theft of six million records, including critical security components like Java KeyStore files and encrypted passwords. The perpetrator, operating under the alias "rose87168," is selling the stolen data on underground forums and demanding ransom payments from affected organizations. While Oracle denies that customer data was compromised, the investigation indicates that the compromised server had not been updated in over a decade, highlighting significant security risks associated with known vulnerabilities. This breach has initiated an extortion campaign, presenting financial and ethical challenges for the impacted companies.
Mar 24, 2025·BankInfoSecurity
The White House has initiated a shift in cybersecurity responsibilities, as President Donald Trump signed an executive order transferring management from the federal government to state and local agencies. This change aims to enhance state capabilities in managing infrastructure risks, particularly regarding cyberattacks. However, it comes amid federal budget cuts to cybersecurity support, raising concerns about states' ability to cope with growing threats. Experts warn that the reduction of federal services may lead to inconsistencies in cybersecurity readiness, particularly affecting local governments and educational institutions that often lack sufficient resources.
Mar 24, 2025·Dark Reading
Organizations leveraging artificial intelligence in cloud environments are frequently risking their cybersecurity by making significant configuration errors. A Tenable report reveals that 91% of those surveyed had deployed Amazon SageMaker with root access enabled by default, posing serious risks if compromised, as root access can allow manipulation of critical systems. The report highlights the trend of excessive permissions and public exposure as significant vulnerabilities, alongside the "Jenga concept" where each service inherits risks from others, leading to potential cascading failures. To mitigate these risks, organizations need to proactively reassess their security settings rather than relying on default configurations.
Mar 21, 2025·Time
Elon Musk's Department of Government Efficiency (DOGE) has sparked concerns among cybersecurity experts due to substantial cutbacks in federal programs and key cybersecurity personnel. The dismissal of top officials and cancellation of essential contracts aimed at safeguarding sensitive data have raised alarms about potential hacks, fraud, and privacy violations. Experts specifically criticize DOGE for mishandling personal information and engaging in unauthorized practices, such as insecure server connections and website alterations. These actions not only jeopardize individual privacy, particularly for vulnerable populations, but also threaten national security by undermining protections for critical infrastructure.
Mar 21, 2025·Healthcare IT News
The Department of Health and Human Services (HHS) has proposed new cybersecurity regulations to address rising breaches in the healthcare industry, following the establishment of HHS Cyber Performance Goals in 2023. The notice of proposed rulemaking (NPRM), issued in December 2024, aims to strengthen requirements that were deemed inadequate under the Health Insurance Portability and Accountability Act (HIPAA). Key changes include mandatory encryption, multifactor authentication, and formalized incident response protocols to protect electronic protected health information (ePHI). Healthcare organizations are advised to prepare by conducting gap analyses and engaging leadership to ensure compliance with the forthcoming regulations.
Mar 21, 2025·Cyberscoop
Congress is being urged to reauthorize the Cybersecurity Information Sharing Act (CISA) before its expiration at the end of September. The act offers legal protections for companies sharing cyber threat information, helping to facilitate essential real-time data exchange needed for responding to cyber attacks. Acknowledging bipartisan support, particularly from key leaders in intelligence committees despite some opposition on privacy grounds, advocates stress that renewing CISA is crucial for encouraging critical infrastructure operators to report cyber incidents without fear of legal repercussions. Additionally, there are calls for new legislation to address conflicting cybersecurity regulations and establish an interagency committee to streamline rules.
Mar 21, 2025·CyberNews
Alphabet has announced its acquisition of cybersecurity firm Wiz for $32 billion, marking its largest purchase to date. Founded in 2020, Wiz specializes in cloud security and has collaborated with major tech firms like Amazon and Microsoft to safeguard data in remote centers. Integrating Wiz into Google Cloud aims to enhance security offerings amid a growing focus on artificial intelligence and multicloud capabilities. Despite earlier stalled negotiations when Wiz was valued at $23 billion, this agreement will ensure that Wiz's products remain available across multiple cloud platforms. Google CEO Sundar Pichai emphasized the move's significance in meeting the increased demand for comprehensive cloud security solutions.
Mar 20, 2025·JD Supra
On March 3, 2025, Atlas Healthcare Group reported a data breach affecting sensitive consumer information, including names, Social Security numbers, and medical records, to the U.S. Department of Health and Human Services. The breach, which was discovered through an internal investigation, had allowed unauthorized access to confidential files since January 20, 2023. Atlas Healthcare, which operates several facilities across the northeastern United States, is in the process of notifying those impacted and is assessing the full extent of the compromise to inform affected individuals about potential risks and protective measures.
Mar 20, 2025·TechCrunch
The Cybersecurity and Infrastructure Security Agency (CISA) is working to reconnect with over 130 former employees following a federal court ruling that their layoffs were illegal. U.S. District Judge James Bredar ordered their reinstatement after layoffs in February as part of a broader workforce reduction by the Trump administration. CISA is facing challenges in verifying the contact details of those affected and has prompted eligible employees to submit their information securely. The agency will place reinstated workers on administrative leave with full pay and benefits during this process, emphasizing the ongoing complexities of managing its workforce amid cybersecurity demands.
Mar 19, 2025·Forbes
The FBI has issued a warning regarding new scams targeting users of popular web browsers, specifically involving malicious websites that can steal sensitive data. These scams have been linked to online document converter tools that may introduce malware onto users' devices, potentially leading to ransomware attacks. The agency stresses the necessity of public education to prevent such incidents and encourages reporting of any scams encountered. Users are advised to exercise caution, maintain updated antivirus software, and enable safe browsing features. Additionally, the FBI cautions against fraudulent applications masquerading as well-known services like Adobe and DocuSign, which aim to compromise Microsoft 365 credentials. To enhance security, it is recommended to use trusted providers for document conversion and avoid third-party sites that request personal information.
Mar 19, 2025·TechTarget
Microsoft's rural hospital cybersecurity program has gained significant traction, with one-third of U.S. rural hospitals enrolling since its launch in June 2024. The initiative provides free security assessments, tailored training, and discounted products to help enhance defenses against cyber threats. However, assessments reveal major vulnerabilities in cybersecurity practices, with many hospitals failing to implement essential measures such as multifactor authentication. Financial difficulties, including low patient volumes and inadequate reimbursements, further complicate efforts, as nearly half of these hospitals operate at a loss, limiting their capacity to address cybersecurity needs effectively.
Mar 18, 2025·CBS News
Over 130 probationary employees terminated from the Cybersecurity and Infrastructure Security Agency (CISA) will be reinstated due to a court order from U.S. District Judge James Bredar. The order, which affects employees from various federal agencies including Agriculture, Commerce, and Education, mandates their reintegration by March 17, although they will initially remain on paid administrative leave. CISA has communicated to those affected that their pay and benefits will resume, and employees have the choice to decline reinstatement if they wish.
Mar 18, 2025·Cybersecurity Dive
RansomHub, a new ransomware group, is utilizing the SocGholish malware-as-a-service framework to conduct attacks against U.S. government entities and various sectors, reportedly affecting over 200 victims since early 2024, including Change Healthcare and Rite Aid. SocGholish, operational since 2018, lures users into downloading malicious software through deceptive browser and software updates, leveraging a network of compromised websites. The malware employs an obfuscated JavaScript loader and utilizes a traffic distribution system to direct users to these threats, while also incorporating Python-based backdoors for initial access to command and control servers in their ransomware operations.
Mar 17, 2025·WSJ
The FBI has issued a warning about the ongoing threat posed by Medusa ransomware attacks, which have targeted users of Gmail, Outlook, and VPNs. The advisory underscores the importance of implementing cybersecurity measures, specifically the activation of two-factor authentication (2FA), as the Medusa group has exploited unpatched vulnerabilities and social engineering tactics since 2021, affecting over 300 victims. In collaboration with the U.S. Cybersecurity and Infrastructure Security Agency (CISA), the FBI provided recommendations for organizations, such as enabling 2FA, using complex passwords, maintaining secure data backups, and regularly updating software to mitigate risks associated with these attacks.
Mar 17, 2025·The Record
CISA has announced a $10 million reduction in annual funding for the Multi-State Information Sharing and Analysis Center (MS-ISAC) and the Election Infrastructure Information Sharing and Analysis Center (EI-ISAC), both vital for cybersecurity support to state and local governments. The cuts are part of a strategy to focus on essential areas and remove redundancies in services. This decision has sparked concerns among cybersecurity experts and officials who warn that the loss of federal support may jeopardize election security and increase vulnerability to cyberattacks amid rising threats. Industry leaders stress the reliance of many local election offices on the services these centers provide, raising alarms about the potential impact on local cybersecurity efforts.
Mar 17, 2025·Dark Daily
Lehigh Valley Health Network (LVHN) will pay $65 million to settle a class-action lawsuit resulting from a ransomware attack that compromised patient data, including sensitive personal information. The lawsuit, filed by a cancer patient whose intimate images were leaked online, highlights LVHN's alleged failure to protect data in violation of HIPAA, resulting in the exposure of information for approximately 134,000 patients and staff members. The incident, which occurred in early 2023 after LVHN refused to meet the ransom demands, underscores the pressing need for enhanced cybersecurity measures in healthcare to safeguard patient privacy. Compensation for affected patients will vary based on specific circumstances.
Mar 16, 2025·The Record
The Cybersecurity and Infrastructure Security Agency (CISA) has announced a $10 million cut in annual funding for the Center for Internet Security (CIS), which supports vital programs like the Multi-State Information Sharing and Analysis Center (MS-ISAC) and the Election Infrastructure Information Sharing and Analysis Center (EI-ISAC). These centers provide critical cybersecurity assistance to state governments, particularly in the context of rising cyber threats. The cuts have raised concerns among experts and state officials about the potential impact on their operations and the cybersecurity of local election offices.
Mar 16, 2025·Healthcare IT News
Cloudflare's security service has blocked access to a website as a precaution against potential online threats, which can originate from suspicious activity such as the use of specific keywords or improper data submissions. Affected users are encouraged to contact the site owner via email, providing details about their activity and the Cloudflare Ray ID to assist in understanding the block's context. While such security measures are essential in combating cyber threats, they may inadvertently affect legitimate users, highlighting the ongoing challenges of cybersecurity in the digital environment.
Mar 16, 2025·Fierce Healthcare
A recent report by Clearwater Security identifies significant gaps in cybersecurity preparedness among private equity-backed healthcare companies. These organizations often have inadequate governance and lack consistent cybersecurity policies, a concern heightened by their rapid growth. The report, which uses the HHS 405(d) Cybersecurity Practices framework for evaluation, reveals that technical controls frequently outstrip formal documentation, leading to governance deficiencies. Clearwater advises private equity firms to assess the cybersecurity risk profiles of potential acquisitions, as weak cybersecurity can devalue a company and result in regulatory consequences. Additionally, many healthcare organizations lack effective incident response plans, further exposing them to risks.