Search site
Find podcasts, news, articles, webinars, and contributors in one search.
Health IT News
Browse by topic
Most-read stories in the last 7 days
1,000 stories
Mar 13, 2025·TechCrunch
Meta is launching its Community Notes feature in the U.S. on March 18, a new approach to fact-checking for platforms like Facebook, Instagram, and Threads. This crowdsourced initiative draws inspiration from a similar program by Twitter, as Meta seeks to improve upon its previous reliance on third-party fact-checkers, which faced criticism for biases and misapplications. The Community Notes system allows users to contribute and rate fact-checks, promoting a balanced evaluation of information by ensuring consensus among contributors before a note is displayed. Meta intends to refine this feature domestically before considering international rollout, particularly amid scrutiny from the European Commission.
Mar 12, 2025·LinkedIn
In this post, Joey Meneses, CTO at Grady Health System, examines strategies for managing shadow IT that focus on understanding employee needs while ensuring security. Organizations are encouraged to implement comprehensive discovery methods and technological controls, coupled with streamlined approval processes and ongoing employee education. This dual approach not only mitigates security risks associated with unauthorized systems but also enhances IT efficiency by addressing the root causes of shadow IT use, thereby creating a more secure and responsive business environment.
Mar 12, 2025·Daily Mail
Bank of America has confirmed a data breach that exposed sensitive customer information, including social security numbers, due to improper handling by a third-party data destruction vendor. Though the exact number of affected individuals remains undisclosed, the bank serves around 69 million consumers and small businesses. In light of the breach, the bank is notifying potentially impacted clients and providing two years of free identity theft protection services through Experian. Customers are advised to monitor their accounts for unusual activity and implement additional security measures. This breach follows a previous incident earlier in the year involving another third-party software vendor.
Mar 12, 2025·Dark Reading
Microsoft has released patches for six actively exploited zero-day vulnerabilities, including three in the NTFS file system and another in the Fast FAT File System Driver. The most critical issues involve a remote code execution flaw and a serious heap-based buffer overflow, with recommendations for users to restrict virtual hard disk sources to reduce risks. The update is part of a broader March release addressing 51 vulnerabilities, emphasizing the need for timely action from security teams to mitigate these threats.
Mar 12, 2025·SecurityWeek
Recent data breaches in the healthcare sector have impacted approximately 560,000 individuals, exposing vulnerabilities in the protection of sensitive patient information. These breaches involved unauthorized access to personal identification data, medical records, and financial details, raising concerns over identity theft, fraud, and patient trust. In light of these incidents, experts advocate for enhanced cybersecurity measures, including regular security assessments, employee training, and advanced technologies. The emphasis is on adopting multi-layered security strategies to better safeguard patient data as the industry embraces digital transformation.
Mar 10, 2025·BankInfoSecurity
Anahi Santiago, CISO of ChristianaCare, discussed the dual impact of artificial intelligence on healthcare during an interview at the HIMSS 2025 conference, noting its role in improving cybersecurity and clinical care. While AI enhances productivity, Santiago warned of new risks as cybercriminals adopt AI for malicious activities, such as social engineering. In response, ChristianaCare is updating training programs to prepare staff for evolving threats, including deepfakes. Santiago highlighted the need for cybersecurity professionals to leverage AI effectively in safeguarding sensitive healthcare data while staying ahead of potential attackers.
Mar 10, 2025·The Register
Cybersecurity improvements for rural hospitals in the U.S. are estimated to require over $75 million, as these facilities face heightened risks from cyberattacks, primarily phishing and ransomware, which account for 93% of incidents. Research shows that cyberattacks can lead to increased patient mortality rates, intensifying concerns for already struggling rural hospitals. Implementing essential cybersecurity measures could cost between $30,000 and $40,000 per facility, with a total investment for around 2,100 rural hospitals potentially reaching $45 million. The situation underscores the need for a collaborative effort among healthcare providers, policymakers, and security vendors to enhance cyber defenses, given that rural hospitals cater to about 46 million Americans.
Mar 9, 2025·BleepingComputer
A critical out-of-bounds write vulnerability, CVE-2025-22224, has been identified in VMware ESXi servers, leaving approximately 37,000 systems exposed to cyberattacks. The flaw has been actively exploited by local attackers with administrative privileges, allowing them to execute code on the host system. While Broadcom, the vendor for VMware, has acknowledged this and two other related vulnerabilities as zero-days, details on the attack origins and specific targets remain undisclosed. The U.S. Cybersecurity & Infrastructure Security Agency (CISA) has mandated that federal and state organizations must apply necessary updates by March 25, 2025, or discontinue the use of vulnerable systems.
Mar 9, 2025·Cyberscoop
Cybercriminals have dramatically improved their attack strategies over the past year, achieving lateral movement within networks and data theft in remarkably short timeframes. Current research indicates that the average time for attackers to move laterally is now just 48 minutes, with some cases as brief as 51 seconds. This increase in speed is attributed to attackers refining their methods, leveraging legitimate tools to avoid detection, and targeting administrative credentials. Furthermore, the time from initial breach to data exfiltration has decreased to roughly two days in 2024, with some incidents occurring in under an hour, underscoring a pressing need for organizations to enhance their cybersecurity measures.
Mar 9, 2025·X
Users of x.com have reported access issues potentially linked to specific privacy-related browser extensions. The platform recommends disabling these extensions as a troubleshooting measure to restore functionality. While this situation may cause temporary inconvenience, adjusting browser settings is expected to resolve the problems. This incident underscores the tension between online privacy protections and website accessibility. Users are encouraged to follow the guidance and check if their access improves after making the adjustments.
Mar 6, 2025·LinkedIn
At the HIMSS25 conference, Bill Russell addressed the intersection of healthcare and technology, emphasizing the impact of an upcoming cybersecurity rule from HHS on reimbursement models and planning for the coming year. He discussed the emerging "hospital of the future," driven by advanced technologies, and stressed the need for healthcare organizations to enhance efficiencies and achieve ROI within a year. Russell also defended the relevance of HIMSS as a key venue for networking and establishing partnerships in the healthcare sector, highlighting its role in facilitating learning and business opportunities.
Mar 6, 2025·AHA
Hospitals and health systems in the U.S. have been targeted by fraudulent data extortion letters purportedly from the Russian ransomware group BianLian, raising alarm among healthcare organizations and law enforcement. These letters threaten the disclosure of sensitive patient information unless a ransom is paid, yet they lack evidence of stolen data and reliable contact information. John Riggi from the American Hospital Association highlighted the unusual use of traditional mail for such extortion attempts and suggested these may be hoaxes. He urged recipients to report the letters to the FBI and to preserve them for forensic analysis, while the AHA continues to collaborate with law enforcement to address the ongoing cyber threats facing the healthcare sector.
Mar 5, 2025·Ars Technica
Three significant vulnerabilities in VMware's virtual machine products expose customer networks to serious risks, enabling potential hyperjacking attacks that can compromise the hypervisor and allow unauthorized access to multiple virtual machines. This breach dismantles the isolation typically provided by virtual machines, raising concerns about the security of various organizations' internal networks. Security researcher Kevin Beaumont underscored the critical nature of the vulnerabilities, which have been reported to be actively exploited in the wild. Affected products include all versions of VMware's ESXi, Workstation, Fusion, Cloud Foundation, and Telco Cloud Platform, underscoring the extensive impact across different deployments.
Mar 5, 2025·Cyberscoop
serious risk to U.S. cybersecurity efforts, particularly given the increasing threats from Chinese hacking. Rob Joyce, the former NSA cybersecurity chief, testified before Congress that mass firing of probationary federal employees could heavily impact the government's ability to defend critical infrastructure. He emphasized that these employees, who often have relevant experience and training, are essential for countering cyber threats, and their removal may erode the talent pipeline necessary for effective cybersecurity operations. Joyce also raised concerns about job security affecting the retention of skilled personnel, which could further compromise national security.
Mar 4, 2025·Becker's Hospital Review
Steven Ramirez, who joined Renown Health in early 2022 as vice president and chief information security officer, has since taken on the role of chief technology officer in response to the organization's rapid digital transformation. In a recent podcast, he outlined his evolving responsibilities that encompass overseeing technology integration and cybersecurity. Under the direction of CIO Chuck Podesta, Ramirez's team created an IT plan that aligns with executive goals, focusing on cultural growth and standardization. They identified opportunities to streamline technology spending and implemented a phased approach to integrate AI and automation while maintaining cybersecurity. To guide this transformation, Renown established a governance risk and compliance committee co-chaired by Ramirez, involving key stakeholders to align on initiatives and assess third-party risks through an SBAR process.
Mar 4, 2025·TechCrunch
A recent leak of chat logs from the Black Basta ransomware group, shared with threat intelligence firm Prodaft, has unveiled crucial details about the gang's internal operations and its members. The logs, containing over 200,000 messages dated from September 2023 to September 2024, were released by an anonymous source amid reported internal strife, particularly following failures to deliver decryption tools to victims. The Russian-language group has been involved in multiple high-profile attacks on critical infrastructure worldwide, including U.S. healthcare and UK utilities, and the leaked information provides insight into their unreported targets and techniques. The leak also identifies key members of the group, heightening concerns as the gang allegedly began targeting Russian domestic banks.
Mar 3, 2025·The Record
U.S. Defense Secretary Pete Hegseth has ordered Cyber Command to halt all planning and offensive operations against Russia, signaling a shift in strategy aimed at normalizing relations with Moscow amid the ongoing geopolitical tensions following Russia's invasion of Ukraine. The directive, conveyed to Cyber Command leadership, does not apply to the National Security Agency's signals intelligence activities related to Russia. While the duration of the stand-down is unclear, Cyber Command has been instructed to assess the implications of this order on current missions and potential threats, affecting a significant portion of its personnel dedicated to Russian operations.
Mar 3, 2025·CSO
Cybersecurity professionals experience significant mental health challenges due to the high-pressure demands of their roles. A study by Tines found that 66% of security team members report work-related stress, with 22% experiencing severe levels. The stress negatively impacts job performance and personal well-being, particularly during major incidents that contribute to psychological trauma, such as sleep disturbances and feelings of inadequacy. The mission-driven focus of cybersecurity intensifies these effects, leading to prolonged hypervigilance and potential PTSD symptoms. Chief Information Security Officers (CISOs) face additional pressures and risks of personal liability, which can contribute to higher rates of depression and substance abuse among them.
Mar 3, 2025·BleepingComputer
A study by Modat researchers has identified over 49,000 misconfigured Access Management Systems (AMS) exposed online, raising serious privacy and security concerns across various sectors globally. These systems, which control entry to secure areas via biometrics and ID cards, were found lacking proper security configurations, allowing unauthorized access to sensitive employee data, including personal identification, biometric details, and access logs. Researchers demonstrated the vulnerability by manipulating records and credentials in some systems, highlighting the risks associated with AMS in government and critical infrastructure settings. The majority of exposed systems were located in Italy, Mexico, and Vietnam, with the U.S. also having a significant number of vulnerabilities.
Mar 2, 2025·Security Boulevard
A survey by the Ponemon Institute for Imprivata reveals that 47% of IT and security practitioners work for organizations that encountered a data breach or cyberattack involving third-party access in the past year, with remote access identified as the most common attack method. Two-thirds of respondents expect these breaches to either increase or remain stable over the next 12 to 24 months. Joel Burleson-Davis from Imprivata points out the difficulty organizations face in ensuring the security of third-party connections, emphasizing that many trust these providers without thorough security assessments. The survey indicates that 34% of impacted organizations granted excessive access to third parties, and 58% found their management of privileged access inconsistent. Resource limitations were also identified, with 41% of respondents citing budget constraints as a significant barrier and 44% feeling overwhelmed by managing third-party permissions.