Search site
Find podcasts, news, articles, webinars, and contributors in one search.
Health IT News
Browse by topic
Most-read stories in the last 7 days
1,000 stories
Feb 12, 2025·Bloomberg Law
The Electronic Privacy Information Center (EPIC) has initiated a lawsuit against the Department of Government Efficiency (DOGE) and multiple federal agencies, including the U.S. Office of Personnel Management and the Treasury Department, alleging a significant data breach affecting millions of federal employees and citizens. Filed in the U.S. District Court for the Eastern District of Virginia, the suit claims these agencies violated federal security laws by failing to adequately protect sensitive personal information and improperly disclosing it. The complaint points to DOGE's leadership under Elon Musk, asserting unlawful access to secure government systems and highlighting the risks posed by such breaches to individuals' personal data.
Feb 12, 2025·National Law Review
The Cybersecurity and Infrastructure Security Agency (CISA) and the FDA have issued a joint warning about a critical cybersecurity vulnerability in certain patient monitoring devices. This vulnerability, identified as a backdoor access point, could potentially allow unauthorized users to infiltrate these medical devices, posing significant risks to patient safety and data integrity. Healthcare providers are urged to assess their networks for these vulnerabilities and implement recommended security measures to mitigate potential threats. The agencies emphasize the importance of immediate action to protect both patient health and sensitive information.
Feb 12, 2025·Ars Technica
A recent Consumer Reports survey reveals that many consumers are unaware of the risks linked to Internet of Things (IoT) devices, particularly the necessity for ongoing software support. A substantial percentage of users, including 55% of smart TV owners and 46% of smartphone owners, mistakenly believe their devices will remain functional even after official support ends, potentially leading to security vulnerabilities and wasted investments. The findings emphasize the need for improved communication from manufacturers regarding product lifespan and support, prompting advocacy groups to urge the Federal Trade Commission (FTC) to mandate clearer disclosures about the duration of device support.
Feb 11, 2025·Corporate Compliance Insights
Chief Information Security Officers (CISOs) and boards of directors often find themselves at odds over cybersecurity priorities, primarily due to differing focuses—CISOs emphasize technical aspects while boards concentrate on financial implications. As cybercrime increases and regulations tighten, clear communication between these groups is crucial for improving organizational resilience against cyber threats. To bridge this gap, CISOs should express cyber risks in financial terms that resonate with board members, utilize benchmarking data to highlight internal and external risks, and adopt accessible language to garner support for cybersecurity initiatives. Recognizing the financial benefits of robust cybersecurity can help align strategies with business goals, while an emphasis on regulatory compliance will ensure that both CISOs and boards incorporate these risks into their strategic planning.
Feb 11, 2025·Becker's Hospital Review
Epic is enhancing its patient identity verification by partnering with CLEAR to integrate secure identity verification tools within its Epic Toolbox, accessible via MyChart. This collaboration aims to streamline patient account creation and recovery processes while reducing administrative burdens on healthcare staff. The embedded tool will automate identity verification, thus improving cybersecurity and patient experience for over 27 million existing CLEAR users, who can authenticate their identities using a selfie. As CLEAR expands from its established biometric ID checks in airports into healthcare, this integration reflects a growing trend toward streamlined digital authentication in medical settings.
Feb 10, 2025·Bleeping Computer
CISA has directed federal agencies to address a serious vulnerability in the Linux kernel, known as CVE-2024-53104, which is actively being exploited. Originating from an out-of-bounds write issue in the USB Video Class driver, this flaw allows for privilege escalation on unpatched devices. Google has released a patch for Android users, but the vulnerability requires immediate attention from federal agencies, as it falls under the November 2021 Binding Operational Directive that mandates securing networks against such risks. The deadline for compliance is set at three weeks.
Feb 10, 2025·Independent
OpenAI is investigating unverified allegations of a data breach that may have exposed login credentials for approximately 20 million user accounts, as claimed by an individual on a hacking forum. While the company has found no evidence to support these claims, they are taking the situation seriously and are currently conducting inquiries. Cybersecurity experts recommend that users update their passwords and credentials as a precautionary measure, emphasizing the potential risks if the breach is confirmed, which could result in unauthorized access to user data and OpenAI's APIs.
Feb 9, 2025·Industrial Cyber
The Health-ISAC has issued a whitepaper highlighting the importance of cybersecurity across the lifecycle of medical devices, focusing on the shifting responsibilities between manufacturers and healthcare delivery organizations (HDOs). It identifies four key phases: development, support, limited support, and end of support, detailing how manufacturers initially control cybersecurity measures during development, while HDOs take over risk management as the device ages. Effective communication is emphasized as critical, especially as medical devices approach their end-of-life or end-of-support stages, to ensure that both parties coordinate efforts and address potential security vulnerabilities.
Feb 9, 2025·Krebs on Security
DeepSeek, a Chinese AI company, has launched mobile apps that quickly rose to popularity, securing top rankings on Apple and Google download charts since January 25, 2025. However, these apps have raised serious security and privacy concerns, particularly due to hard-coded encryption keys and the transmission of unencrypted user data to Chinese firms. A security analysis by NowSecure highlighted that the app collects extensive user data and compromises privacy through disabling critical security features, recommending removal from organizational devices. The report underscored the risk of interception and deanonymization of users, thus highlighting significant vulnerabilities in the app's design.
Feb 9, 2025·Forbes
Pentera's "Scapegoat to Cyber GOAT" campaign aims to shift the perception of cybersecurity in professional sports by underscoring its significance as sports organizations manage sensitive data. The campaign features a humorous Super Bowl commercial that introduces Gary, a half-man, half-goat character representing the often-overlooked cybersecurity professionals. By redefining the acronym GOAT to honor these experts, Pentera encourages a proactive security approach through the Continuous Threat Exposure Management (CTEM) framework. The initiative also incorporates a multi-channel strategy, including gamified elements like an interactive scavenger hunt and a giveaway of a Tom Brady autographed helmet.
Feb 6, 2025·Cyberscoop
Concerns are escalating among cybersecurity experts and government officials over the security risks associated with Elon Musk's involvement in the Department of Government Efficiency (DOGE). Since January 2025, actions taken by Musk's team may jeopardize personal data of millions of federal employees, with potential violations of laws protecting sensitive information. Experts highlight the risk of new vulnerabilities, particularly regarding the Department of the Treasury's payment systems. A significant concern is the reported installation of an unauthorized private server at the Office of Personnel Management (OPM), which holds sensitive employee records. Critics, including Senator Elizabeth Warren, stress the importance of strengthening security measures amid the risk of unauthorized access to key federal payment systems, especially after conflicting reports about access privileges within DOGE.
Feb 6, 2025·Reuters
In the context of mergers and acquisitions, cybersecurity and data privacy have become major concerns due to the potential impact of cyber threats on transaction value and success. Buyers are increasingly incorporating indemnification provisions into M&A agreements to mitigate risks associated with cybersecurity issues that may arise after closing. These provisions allocate responsibility and provide a mechanism for compensation in case of undisclosed liabilities. It is important for buyers to distinguish between general and specific indemnities, as tailored indemnities targeting specific risks identified during due diligence offer more effective protection against potential cyber threats.
Feb 6, 2025·Dark Reading
Ransomware groups are now incorporating advertising elements in their ransom notes to solicit insider information, according to researchers from GroupSense. This new tactic, observed in communications from groups like Sarcoma and a LockBit impersonator known as DoNex, involves threatening potential victims while also offering rewards for insider tips. Notes invite individuals to expose their company's vulnerabilities, along with instructions to engage through a secure messaging platform to maintain privacy. Kurtis Minder, CEO of GroupSense, suggests this strategy may enhance the visibility and effectiveness of ransom demands, indicating a possible trend that other groups might adopt.
Feb 5, 2025·Sophos
Sophos has completed its acquisition of Secureworks for approximately $859 million, marking a significant move in the cybersecurity landscape by establishing Sophos as a leading provider of Managed Detection and Response (MDR) services. The deal, supported by Thoma Bravo, will create a unified security operations platform with extensive integrations aimed at improving the efficiency and effectiveness of cybersecurity for over 28,000 organizations worldwide. Sophos plans to enhance its capabilities with Secureworks' Counter Threat Unit™ and security advisory teams, which will bolster its threat intelligence and services. CEO Joe Levy highlighted the rising demand for MDR services, noting that the integration will leverage Sophos's strengths in ransomware detection and artificial intelligence to improve cybersecurity outcomes.
Feb 4, 2025·Dark Reading
Frederick Health and New York Blood Center Enterprises (NYBCe) are responding to recent ransomware attacks that have interrupted their services. Frederick Health is collaborating with cybersecurity experts following an attack identified on January 27, which has closed its Village Laboratory and may delay patient care. NYBCe detected suspicious activity and took its systems offline on January 26 to address the threat, though a timeline for full restoration is uncertain. Ransomware attacks continue to threaten healthcare organizations, with significant financial implications and risks to patient safety. Limited funding and staffing for cybersecurity further heighten these vulnerabilities, making healthcare facilities susceptible to evolving threats from ransomware groups.
Feb 4, 2025·IT Pro
A new phishing campaign is leveraging Microsoft’s Active Directory Federation Services (ADFS) to steal user credentials and circumvent multi-factor authentication (MFA). According to research from Abnormal Security, attackers are creating convincing spoofed ADFS sign-in pages that resemble legitimate portals to deceive users into providing their credentials and secondary authentication codes. The campaign starts with emails that impersonate urgent IT helpdesk notifications, featuring obfuscated URLs and dynamic organizational branding to enhance credibility. Post-compromise, attackers also implement covert mail filters to intercept responses and maintain persistence, with over 150 organizations reportedly targeted.
Feb 3, 2025·BankInfoSecurity
New York Blood Center Enterprises (NYBCe) experienced a ransomware attack on January 28, disrupting blood supply operations amid an already critical blood shortage due to a 30% decline in donations. The organization, which serves multiple states, is collaborating with cybersecurity experts and law enforcement to address the incident. The attack has exacerbated supply issues, particularly for O negative and B negative blood types, and highlights ongoing vulnerabilities in the cybersecurity infrastructure of healthcare organizations, which are increasingly targeted by cybercriminals due to their essential services and sensitive data.
Feb 3, 2025·Dark Reading
Community Health Center (CHC) has informed over one million patients of a data breach that compromised sensitive personal information, marking the third significant healthcare data breach in a week. Discovered on January 2, the breach involved a skilled hacker who accessed various datasets, including names, birth dates, and Social Security numbers. CHC responded by enhancing its security protocols and stated that no data was deleted or operational disruptions occurred. Despite containing the breach quickly, the incident illustrates the ongoing cybersecurity vulnerabilities within the healthcare sector.
Feb 2, 2025·Forbes
GhostGPT has been identified as a new AI chatbot catering specifically to cybercriminals, posing serious risks in the realm of cybercrime. A report from Abnormal Security indicates that this uncensored chatbot enables users to create malware and execute phishing scams without the safeguards typical of conventional AI systems. Available through the Telegram platform for a fee, GhostGPT provides low entry barriers for individuals with minimal technical skills by promoting its capabilities for tasks such as coding and exploit development. Its rapid processing and no-logs policy enhance its appeal to those seeking anonymity while engaging in illegal activities.
Feb 2, 2025·MedTech Dive
The FDA has issued a safety communication regarding cybersecurity vulnerabilities in Contec's CMS8000 patient monitors and Epsimed's MN-120 product line, which could allow unauthorized access and manipulation of the devices used for monitoring patients' vital signs. The vulnerabilities, identified as high severity by the Cybersecurity and Infrastructure Security Agency (CISA), could enable attackers to control the monitors remotely, potentially compromising patient safety by affecting device functionality and data integrity. Although no incidents of harm or data breaches have been reported, the FDA is advising patients, healthcare providers, and IT personnel to adopt precautionary measures to mitigate associated risks.