Search site
Find podcasts, news, articles, webinars, and contributors in one search.
Health IT News
Browse by topic
Most-read stories in the last 7 days
1,000 stories
Jan 11, 2026·bleepingcomputer.com
Starting in February 2026, Microsoft will mandate multi-factor authentication (MFA) for all users accessing the Microsoft 365 admin center, blocking those who do not comply. This requirement aims to enhance security by making it significantly harder for attackers to gain unauthorized access to accounts, thereby protecting sensitive data from threats such as phishing and credential stuffing. Healthcare professionals utilizing Microsoft 365 must act quickly to enable MFA, as failure to do so could disrupt IT operations and administrative functions crucial for maintaining patient data security. The move is part of Microsoft's broader initiative to strengthen security across its platforms, highlighting the increasing need for robust authentication measures in healthcare technology.
Jan 8, 2026·Cybersecurity Dive
The National Institute of Standards and Technology (NIST) is seeking public feedback to improve the security of artificial intelligence (AI) agents, highlighting the increasing concerns surrounding their vulnerabilities. In a recent Federal Register notice, NIST's Center for AI Standards and Innovation (CAISI) invited stakeholders to share practices and methodologies for securely developing and deploying these systems, particularly in critical infrastructure settings. This initiative is critical as the integration of unsecured AI agents poses significant risks to public safety and consumer trust, potentially stalling the broader adoption of AI technologies in healthcare and other sectors. With a 60-day period for input, NIST aims to gather diverse insights to address these pressing security challenges.
Jan 8, 2026·BleepingComputer
In 2026, the integration of artificial intelligence (AI) into cybercrime is significantly altering the landscape by making illicit activities more accessible to individuals lacking technical expertise. This trend, exemplified by tools like FraudGPT and PhishGPT, allows hackers to automate tasks such as phishing, thereby lowering barriers to entry for new cybercriminals. The concept of "vibe hacking" highlights a shift towards intuitive, AI-guided methods, challenging traditional notions of necessary skills in hacking. For healthcare professionals, the rise of these tools underscores the urgent need for enhanced cybersecurity measures and continuous vigilance against increasingly sophisticated threats.
Jan 7, 2026·Cybersecurity Dive
A recent report by Netskope highlights significant security risks associated with the unregulated use of artificial intelligence (AI) tools in enterprises, particularly through personal accounts that often lack adequate security measures. Nearly half of generative AI users engage with these tools outside corporate oversight, which increases exposure to cyber threats and complicates oversight for IT departments. The report reveals a concerning trend of users switching between personal and enterprise accounts, emphasizing the need for companies to enhance the appeal and security of sanctioned AI tools. As the landscape evolves toward a mix of AI-driven threats, healthcare professionals must be vigilant in addressing these vulnerabilities to protect sensitive patient data and maintain compliance with regulatory standards.
Jan 6, 2026·ramimac.me
Security vendors significantly influence the cybersecurity landscape, yet their research often suffers from pitfalls that can diminish its credibility and effectiveness. Common issues include the use of fear-based marketing tactics, which can mislead healthcare executives about the true nature of threats, and the misrepresentation of existing research as novel insights, undermining both trust and the integrity of the research community. These practices pose risks for healthcare professionals, who rely on credible information to allocate budgets and implement best practices for safeguarding sensitive data. An emphasis on accurate, context-rich research could promote a more informed approach to cybersecurity within the healthcare sector.
Jan 6, 2026·Network World
The ISC2 2025 Cybersecurity Workforce Study reveals an alarming skills gap in cybersecurity that is more pressing than mere staff shortages, as nearly 90% of cybersecurity professionals report significant incidents linked to this deficit. Despite some stabilization in budget cuts and layoffs, the industry faces increasing pressure from the inability to hire qualified personnel, emphasizing the need for capability development in critical areas such as AI and cloud security. As organizations integrate AI tools into their cybersecurity operations, the demand for skilled professionals in these technologies is urgent, highlighting a crucial area for investment and training for healthcare technology stakeholders. The findings suggest immediate action is necessary to address these gaps to mitigate security risks effectively.
Jan 5, 2026·The Register
According to Wendi Whitmore of Palo Alto Networks, AI agents are expected to become a significant insider threat to organizations by 2026, as their integration into enterprise applications is projected to rise sharply. While these agents can help mitigate the cybersecurity skills gap by automating tasks, their access to sensitive data introduces substantial security risks. Whitmore emphasizes the need for careful management, including implementing least-privilege access controls, to prevent AI agents from being exploited or misused. This highlights the critical importance for healthcare and other sectors to understand the security implications of deploying AI technologies and to develop robust safeguards against emerging threats.
Jan 5, 2026·SecurityWeek
Covenant Health recently suffered a data breach affecting approximately 478,000 individuals, exposing sensitive personal information such as Social Security numbers and medical records. Discovered during a routine security audit, the breach has raised significant concerns about the adequacy of current security measures and the heightened risks of identity theft and fraud for those affected. In response, Covenant Health is not only offering credit monitoring but is also committing to strengthening its cybersecurity infrastructure through enhanced training and protocols. This incident underscores the critical need for healthcare providers to adopt robust cybersecurity strategies to safeguard patient information amidst escalating cyber threats.
Jan 5, 2026·TechCrunch
OpenAI has acknowledged the significant threat posed by prompt injection attacks, which exploit vulnerabilities in AI agents like ChatGPT Atlas, despite ongoing efforts to enhance security measures. These attacks, which can manipulate browser behavior through innocuous text in documents, highlight a persistent challenge faced by AI technology, not just by OpenAI but also by other platforms such as Perplexity’s Comet. The U.K. National Cyber Security Centre advocates for a focus on risk mitigation rather than complete elimination of these vulnerabilities, underscoring the need for continuous defense strengthening. OpenAI's proactive response strategy, involving a specialized automated attacker for identifying new threats, exemplifies the evolving measures healthcare professionals and technology developers must adopt to safeguard AI applications in sensitive environments.
Jan 4, 2026·BankInfoSecurity
In the healthcare sector, mergers and acquisitions (M&As) carry significant cybersecurity and data privacy risks, as highlighted by attorney Jonian Rafti. Buyers must recognize that acquiring a company involves inheriting its regulatory challenges, requiring careful diligence on compliance with laws like HIPAA. To address these risks, both buyers and sellers should engage legal and cybersecurity experts to conduct thorough assessments of compliance and technical systems. Effective preparation and rigorous evaluations can help mitigate potential post-acquisition challenges, ensuring a smoother integration process and better protection of sensitive data.
Jan 4, 2026·HIPAA Journal
Oracle Health has suffered a significant data breach impacting approximately 80 hospitals, with the theft of sensitive patient information such as names, Social Security numbers, and medical records. While at least 14,485 individuals have been officially notified, the actual number of affected patients may be much higher, complicating notification and response efforts across multiple states. The incident has prompted class action lawsuits, indicating widespread concern over data security in healthcare technology. Healthcare providers must navigate increased scrutiny and regulatory requirements, highlighting the urgent need for robust cybersecurity measures to protect patient data.
Jan 4, 2026·Mashable
Conduent, a provider of healthcare billing services, recently reported a massive data breach impacting 10.5 million individuals, marking one of the largest incidents in healthcare history. The exposed data includes names and Social Security numbers, raising significant concerns about patient privacy and security in healthcare technology. Although there is currently no evidence of data misuse, the breach underscores the vulnerabilities within healthcare systems and the critical need for enhanced cybersecurity measures. As Conduent collaborates with forensic experts to address the incident, healthcare professionals must be vigilant and proactive in safeguarding sensitive patient information.
Jan 4, 2026·Cybernews
Hospitals are confronting serious cybersecurity challenges related to connected medical devices, which are essential for patient care but often inadequately protected. A survey revealed that 93% of healthcare organizations faced cyberattacks in the past year, with 43% of chief information security officers citing device visibility as a critical issue. The difficulties arise from a lack of comprehensive inventories and unclear ownership of these devices, leading to potential vulnerabilities in hospital networks. These findings highlight an urgent need for healthcare professionals to prioritize improved security measures and establish clear accountability within their organizations.
Jan 1, 2026·Aflac Data Breach
Aflac, a leading insurance provider, has reported a significant data breach affecting approximately 26.5 million individuals after a cyberattack in June 2025. The breach, which was initially underestimated, compromised multiple systems through social engineering tactics attributed to the hacking group Scattered Spider, known for targeting the insurance sector. Sensitive information, including names, Social Security numbers, and health data, was exposed, raising concerns about the security of personal health information in the insurance industry. This incident highlights the critical need for healthcare organizations to invest in robust cybersecurity measures to protect sensitive data from increasingly sophisticated cyber threats.
Jan 1, 2026·BleepingComputer
Two former cybersecurity professionals, Ryan Clifford Goldberg and Kevin Tyler Martin, have pleaded guilty to participating in BlackCat ransomware attacks that affected several U.S. companies in 2023. Exploiting their cybersecurity backgrounds, they used their knowledge to commit extortion, targeting various industries, including healthcare, by demanding ransoms ranging from $300,000 to $10 million. Their actions underscore significant security vulnerabilities in healthcare technology, where sensitive data is increasingly at risk of ransomware attacks. This case highlights the critical need for robust cybersecurity measures within healthcare organizations to protect against insider threats and enhance overall resilience against cybercrime.
Dec 29, 2025·HIPAA Journal
Oklahoma Spine Hospital has reached a $1.1 million settlement following a July 2024 data breach that compromised the personal information of approximately 39,000 patients, sparking two consolidated class action lawsuits. These lawsuits alleged negligence and other misconduct related to the breach, which leaked sensitive data such as medical records, financial information, and identification details. The hospital chose to settle to avoid prolonged litigation despite denying any wrongdoing, with settlement funds earmarked for legal fees and benefits for affected patients, including credit monitoring services and reimbursement for documented losses. This incident highlights significant vulnerabilities within healthcare data security and underscores the importance of protective measures to safeguard patient information.
Dec 29, 2025·BankInfoSecurity
Implantable brain devices and neural interfaces face significant cybersecurity and privacy challenges, as emphasized by Professor Kevin Fu of the Archimedes Center for Healthcare and Medical Device Cybersecurity. These technologies manage highly sensitive neural data, necessitating robust security measures, particularly as they evolve to incorporate automatic therapy adjustments. Fu highlights the difficulty of integrating strong privacy protections within the limited power constraints of these devices, which are critical for treating conditions like Parkinson's disease and sciatica. The need for enhanced cybersecurity measures is essential to safeguard both patient data and the integrity of these emerging healthcare technologies.
Dec 28, 2025·MobiHealthNews
Jose Saucedo has filed a proposed class action lawsuit against Sharp Healthcare in San Diego for allegedly using ambient AI technology, specifically Abridge’s clinical documentation app, to record his medical visit without consent. The lawsuit raises significant privacy issues, as California law requires consent from all parties involved in recording confidential conversations. Saucedo claims the recordings contained sensitive medical information and were accessed without authorization, highlighting the risks associated with the integration of AI in healthcare documentation. This case underlines the critical need for clear consent protocols and safeguarding patient privacy in the adoption of emerging health technologies.
Dec 28, 2025·Forbes
The Trump administration is developing a new national cybersecurity strategy expected to be released in January 2026, focusing on six key pillars designed to combat escalating cybersecurity threats. This high-level framework aims to enhance federal cyber operations through deterrence, regulatory alignment, network modernization, workforce development, infrastructure protection, and attention to emerging technologies. The strategy signals a potential shift towards utilizing cyber capabilities as a means of statecraft, raising significant implications for healthcare professionals who must navigate compliance and security in an increasingly interconnected and vulnerable technological landscape. The compact nature of the strategy may prompt questions about its depth and implementation, particularly regarding the integration of private-sector solutions in national defense efforts.
Dec 22, 2025·Cybersecurity Dive
Palo Alto Networks emphasizes that the security of AI systems is fundamentally linked to cloud infrastructure, with a recent report revealing that nearly all surveyed organizations experienced attacks on their AI systems within the past year. The report indicates that enhancing cloud security measures could prevent many such attacks, urging businesses to adopt stronger identity management strategies and integrate cloud monitoring into their Security Operations Centers (SOCs). Additionally, concerns regarding the integrity of AI training data and compliance with AI regulations highlight the necessity of securing the foundational elements of cloud infrastructure, which remains a significant vulnerability for modern enterprises. As AI adoption continues to rise, addressing these security challenges is crucial for protecting valuable AI investments and ensuring operational resilience.