Search site
Find podcasts, news, articles, webinars, and contributors in one search.
Health IT News
Browse by topic
Most-read stories in the last 7 days
1,000 stories
Feb 27, 2025·SC World
Recent budget cuts at the Cybersecurity and Infrastructure Security Agency (CISA) have raised alarms about the agency's capacity to protect national cybersecurity amid a rise in cyberattacks. A 3% budget reduction, coupled with the establishment of the Department of Government Efficiency (DOGE), is viewed by critics as detrimental to essential programs designed to safeguard critical infrastructure. Key initiatives, such as the Cyber Incident Reporting for Critical Infrastructure Act and Continuous Diagnostics and Mitigation programs, have been suspended, limiting CISA's effectiveness in countering threats from adversaries like China. While supporters of the cuts argue for reallocating resources, critics warn of potential long-term consequences for U.S. cybersecurity.
Feb 27, 2025·Dark Reading
Unmanaged devices, such as personal laptops and smartphones used for work, present significant security risks for organizations, with nearly half allowing access to sensitive resources without adequate protection. A recent study revealed that 92% of ransomware attacks in 2024 involved these unmanaged devices, which often lack fundamental security measures. Although traditional management solutions have fallen short, security leaders are exploring layered, innovative strategies to address the vulnerabilities posed by these devices, highlighting the need for a proactive approach to organizational security.
Feb 26, 2025·Star Tribune
UnitedHealth Group is notifying patients about a data breach linked to its subsidiary, Change Healthcare, a year after a cyberattack that affected approximately half of the U.S. population. Recent letters suggest that patient data, including contact details, health plan IDs, diagnoses, and Social Security numbers, may have been compromised. To address concerns, the company is offering free credit monitoring and identity protection services. Following the breach, which was detected in February 2024, the attack disrupted pharmacies and healthcare operations, leading to the shutdown of a key data clearinghouse for medical claims processing. While the company has claimed to have repaired the impacted systems, the long-term effects of the incident continue to be felt.
Feb 26, 2025·Healthcare IT News
Recent research from the Healthcare Information Management Systems Society (HIMSS) underscores the need for enhanced governance in healthcare cybersecurity, particularly regarding the integration of artificial intelligence (AI). The 2024 Healthcare Cybersecurity Survey Report reveals that, while healthcare organizations are increasing investments in cybersecurity—growing from 10% of IT budgets in 2020 to 14% in 2024—there remains a notable lack of formal governance for AI use. This lack of structure raises concerns about vulnerabilities related to AI, insider threats, and third-party data handling, indicating that additional financial support and governance measures are crucial to mitigate emerging cybersecurity risks.
Feb 25, 2025·Cybersecurity Dive
Shawn Henry, the Chief Security Officer of CrowdStrike, will retire on March 31, 2025, after a notable career in cybersecurity and law enforcement. His transition to an executive advisor role was announced on February 14, allowing him to continue advocating for cybersecurity. Henry, a former FBI executive assistant director with a 24-year background in cyber investigations, has significantly influenced CrowdStrike, particularly during the recent global IT outage affecting 8.5 million Microsoft Windows devices. He managed the incident's impact and publicly acknowledged the support of employees, customers, and partners following the company’s software update issues.
Feb 25, 2025·Cyberscoop
Retired General Paul Nakasone, the former head of the NSA and Cyber Command, expressed concerns about the United States' cybersecurity trajectory during his speech at the DistrictCon cybersecurity conference. He pointed out the increasing capabilities of adversaries, including state-sponsored attacks on U.S. infrastructure and the rise in ransomware incidents, indicating a struggle within the U.S. to secure its networks effectively. Nakasone warned of future cyber threats potentially leading to physical damage and highlighted the role of artificial intelligence in reducing human oversight in military targeting. He also advocated for a more aggressive U.S. approach to offensive cyber operations.
Feb 24, 2025·CNN
A gunman, Diogenes Archangel-Ortiz, took hostages at UPMC Memorial Hospital in York, Pennsylvania, resulting in the death of Officer Andrew Duarte and injuries to five others. Archangel-Ortiz had visited the hospital’s ICU days before the incident, but the motive for his actions remains unclear. During the standoff, he threatened hospital staff and engaged with law enforcement, which ended when police returned fire. Officer Duarte, who had recently joined the West York Police Department, was noted for his commitment to public service and had previously worked for five years in Denver.
Feb 24, 2025·HackRead
A joint advisory from the FBI, CISA, and MS-ISAC warns of the ongoing threats from Ghost ransomware, active since 2021 and linked to actors in China. The group has impacted organizations across various sectors worldwide, including healthcare and education, primarily for financial gain. The ransomware exploits vulnerabilities in outdated software, using publicly available code to target systems like Fortinet FortiOS and Microsoft Exchange. Once inside, it encrypts files and demands ransoms in cryptocurrency. The advisory also provides indicators of compromise (IOCs) for organizations to help identify potential Ghost ransomware activity.
Feb 24, 2025·Apple News
Signal has rolled out a major update to enhance its messaging platform's security against phishing techniques linked to Russian espionage. This update addresses vulnerabilities that previously allowed attackers to impersonate real users and solicit sensitive information. Key features include improved user verification processes and mechanisms to prevent identity spoofing, which collectively aim to bolster communication security. Additionally, Signal is prioritizing user education on recognizing phishing tactics to encourage vigilance among its user base. This comprehensive approach reflects Signal’s commitment to user privacy and security amid growing geopolitical digital threats.
Feb 24, 2025·Health System CIO
Sutter Health is revamping its integration strategy by adopting a holistic approach that prioritizes technology, personnel, and processes over simple IT system mergers. Chief Integration Officer Jacki Monson underscores the necessity of creating a seamless operational ecosystem during mergers and acquisitions, focusing on aligning culture, security, and governance standards to maintain cybersecurity across all entities. Given recent cyberattacks on healthcare organizations, Sutter Health is prioritizing cybersecurity to address vulnerabilities before advancing with IT integration, especially with hospitals that may still use paper records or varying EHR platforms. Furthermore, Sutter Health is leveraging artificial intelligence (AI) to enhance operational efficiencies and patient care, using AI to expedite data analysis during the integration due diligence process.
Feb 24, 2025·dailydarkweb.net
Investing.com has reportedly experienced a significant data breach, with a threat actor claiming to have accessed approximately 6.5 million user records by exploiting an Insecure Direct Object Reference (IDOR) vulnerability. This breach, which allegedly remained active for about a week, resulted in the exposure of sensitive user data, including IDs, email addresses, and registration details. The perpetrator has shared examples of compromised records and indicated that the dataset, which includes information dating back to 2014, is available for sale on BreachForums. As of now, Investing.com has not issued an official response to the incident.
Feb 20, 2025·Breaking Defense
Katie Arrington is returning to the Pentagon as the new Chief Information Security Officer (CISO) for the Department of Defense, after previously serving in a similar role for acquisition and sustainment. Her appointment follows a period of suspension due to allegations of mishandling classified information, which resulted in her security clearance being revoked by the NSA. Arrington, who first joined the DoD in 2019 and contributed to the development of the Cybersecurity Maturity Model Certification, had a varied career that included a stint as a South Carolina lawmaker and an unsuccessful congressional campaign. She previously resigned from the DoD in February 2022, citing the politically charged circumstances surrounding her suspension.
Feb 20, 2025·BankInfoSecurity
A major data breach involving DM Clinical Research has reportedly compromised over 1.6 million clinical trial records due to an unencrypted database lacking password protection. Security researcher Jeremiah Fowler uncovered the exposure, which included sensitive patient information such as names, birthdates, and medication details. Although the database was secured within 24 hours of notification, the length of time it was accessible remains uncertain, raising concerns about unauthorized access. Experts warn of potential legal ramifications related to personally identifiable information and compliance issues with HIPAA and Title 21 CFR Part 11, as DM Clinical Research could face penalties from pharmaceutical companies despite not being classified as a covered entity under HIPAA.
Feb 20, 2025·Nextgov
Edward Coristine, a 19-year-old staff member at Elon Musk's Department of Government Efficiency, has raised security concerns after gaining physical access to the Cybersecurity and Infrastructure Security Agency (CISA), with reports indicating his potential connections to hacking groups and a history of inappropriate behavior. Coristine, linked to a cybercrime syndicate known as The Com, allegedly used the alias "Rivage" to interact in hacking forums and previously leaked proprietary information while employed at Path Networks. Recent reports also noted that a Telegram account associated with him had solicited a distributed denial-of-service (DDoS) attack. The CISA and the Department of Homeland Security have yet to respond to inquiries about his access and activities.
Feb 19, 2025·Krebs on Security
The resurgence of carding, the illicit practice of stealing and selling payment card data, is being driven by innovative cybercriminal tactics, particularly from China, that have adapted to circumvent security measures associated with chip-based cards. Phishing schemes have evolved to send convincing messages that lure victims into revealing their card information and one-time passcodes, which criminals then use to link stolen data to mobile wallets compatible with major platforms like Apple and Google. These operations are highly organized, with criminals utilizing tutorials and bulk sales strategies to maximize profits, while new technologies such as "ghost tap" facilitate transactions without requiring physical access to users' devices, complicating detection and prevention efforts.
Feb 18, 2025·Cybersecurity Dive
President Trump plans to nominate Sean Cairncross as the new national cyber director, a key role in overseeing the nation’s cybersecurity strategy. Cairncross, a former Republican National Committee official, will be among the nominees sent to the Senate for confirmation. His background includes founding a strategic consultancy, serving as CEO of the Millennium Challenge Corporation, and holding a position as deputy assistant to the president. He takes over from Harry Coker, Jr., who focused on advancing the Biden administration’s cybersecurity efforts.
Feb 17, 2025·Ars Technica
Researchers from Symantec have identified a partnership between financially motivated hackers and espionage groups, specifically noting the RA World ransomware group's use of a toolset previously linked to Chinese espionage operations. The toolset is a variant of the custom backdoor PlugX, associated with various Chinese threat actors, and was involved in espionage attacks targeting government entities in Southeast Asia and southeastern Europe from August 2024 to January 2025. This unusual crossover of tactics—typically not found in Chinese cyber actors' financially driven operations—raises questions about the hackers' motivations, prompting speculation about potential connections to known groups like Bronze Starlight and whether these ransomware deployments serve as a cover for espionage activities.
Feb 16, 2025·Ars Technica
The recently launched Department of Government Efficiency (DOGE) website, intended to present an official U.S. government initiative, has faced significant security concerns due to its vulnerability to edits by the public. Web developers discovered that the site could be altered by anyone, leading to instances where pranksters posted mocking messages about its security flaws. Further investigation revealed that the site is hosted on Cloudflare Pages, allowing third-party access to its database, which has raised alarms among federal employees about the potential mishandling of sensitive information. Although the site was initially sparse, it was quickly updated following a press conference by Elon Musk, where he emphasized transparency.
Feb 16, 2025·CSO Online
OmniGPT has experienced a significant data breach affecting over 30,000 users, exposing sensitive information such as email addresses, phone numbers, API keys, and user messages. A hacker known as "Gloomer" has claimed responsibility for the breach and is selling samples of the stolen data on the dark web, which includes more than 34 million lines of messages. The compromised data raises serious concerns about the potential for account takeovers, identity theft, and other cyberattacks, particularly given the presence of crypto private keys among the stolen information.
Feb 13, 2025·The Register
Dawid Moczadło, co-founder of Vidoc Security Lab, recently dealt with two instances of deepfake job applicants leveraging AI-generated alterations to secure interviews at his company. Both applicants, who posed as software developers, raised alarms about the potential risks, such as intellectual property theft, posed by these sophisticated tactics. In one case, an applicant advanced through several interview rounds before a video call exposed the use of altering software. A second similar instance involved an applicant demonstrating a strong Asian accent, despite claiming to be Serbian, further highlighting the challenges posed by deceptive technology in recruitment.