Search site
Find podcasts, news, articles, webinars, and contributors in one search.
Health IT News
Browse by topic
Most-read stories in the last 7 days
1,000 stories
Dec 22, 2025·BankInfoSecurity
MedStar Health is currently managing a significant data breach resulting from an attack by the Rhysida ransomware group, which has compromised 3.7 terabytes of sensitive patient information affecting over 7 million individuals. The breach has prompted a federal class action lawsuit against MedStar, alleging negligence in safeguarding patient data and demanding enhanced security measures. In addition to notifying affected patients, MedStar is offering free identity monitoring services, indicative of the growing need for healthcare providers to bolster their cybersecurity protocols in the face of increasing ransomware threats. This incident underscores the critical importance of protecting patient information and the potential repercussions for healthcare organizations failing to prevent data breaches.
Dec 22, 2025·Security Boulevard
The HBO series "The Pitt" dramatizes the increasing threat of ransomware attacks in healthcare by portraying a shutdown of an emergency department relying on paper records during such an incident. This scenario mirrors real-life events, notably the February 2024 attack on Change Healthcare, which resulted in a $22 million ransom and affected nearly 193 million individuals by disrupting critical operations like claims processing and pharmacy workflows. Such attacks underscore the urgent need for healthcare professionals to recognize ransomware as not merely an IT issue but a systemic risk that compromises patient care and financial stability across the healthcare ecosystem. The American Hospital Association warns that these attacks have far-reaching implications, impacting not only direct victims but also the entire network of vendors and service providers.
Dec 21, 2025·Dark Reading
Recent findings from the Potential Harm Assessment & Risk Evaluation (PHARE) benchmark report reveal that large language models (LLMs) from major tech companies, such as OpenAI and Google, continue to fall short in safety and cybersecurity despite their financial growth for developers. Although Anthropic's models performed better, many LLMs, including some high-profile ones, display significant vulnerabilities to jailbreaks—a serious concern given the potential for manipulation and misinformation. The report indicates that the ability to resist attacks does not correlate with model size, highlighting an urgent need for healthcare technology professionals to prioritize security measures in AI deployment to safeguard sensitive information and ensure trustworthy interactions. Addressing these vulnerabilities is crucial as the healthcare sector increasingly adopts LLMs for clinical and administrative applications.
Dec 21, 2025·Fortune
The introduction of AI coding tools in 2025 significantly transformed software development, enhancing efficiency and allowing developers to focus on complex tasks. However, this shift also raised concerns over security vulnerabilities, as some exploits emerged that demonstrated how these AI systems could be manipulated for malicious purposes. In response, the industry is now prioritizing stronger security protocols and guidelines to mitigate risks and ensure that AI tools provide benefits without compromising software safety. This focus on security underscores a critical challenge for healthcare professionals and technologists as they consider the integration of AI into their systems.
Dec 18, 2025·krebsonsecurity.com
warns that healthcare professionals and organizations must be aware of the growing dangers posed by malicious parked domains, particularly those that mimic legitimate health-related websites. As over 90% of visits to such domains lead to exposure to scams and malware, there is an urgent need for enhanced cybersecurity measures within healthcare systems to safeguard sensitive patient information and maintain trust. Since many users rely on direct navigation for accessing online health resources, implementing strict URL validation and educating staff about the risks associated with mistyped domains will be crucial in mitigating potential threats. This shift highlights the necessity for ongoing vigilance in the face of evolving digital threats in the healthcare sector.
Dec 18, 2025·Cybersecurity Dive
The National Institute of Standards and Technology (NIST) has released a draft Cybersecurity Framework Profile for Artificial Intelligence to support organizations in managing cybersecurity risks associated with AI systems. This framework addresses critical focus areas: "secure," "defend," and "thwart," which reflect the need for robust cybersecurity strategies as AI becomes more integrated into organizational operations. By facilitating a structured approach to applying existing cybersecurity practices to AI concerns, the profile aims to help healthcare professionals and other sectors enhance their defenses against AI-driven cyber threats. With contributions from over 6,500 stakeholders, the framework underscores the importance of collective expertise in navigating the complexities of AI-related cybersecurity challenges.
Dec 16, 2025·BankInfoSecurity
Memorial Hospital and Manor in Georgia has settled a class action lawsuit following a 2024 ransomware attack that compromised 1.15 terabytes of patient data. The settlement affects approximately 105,170 current and former patients, granting them various compensation options for identity theft-related losses and offering a year of free medical data monitoring along with $1 million in identity theft insurance. This incident underscores the pressing need for enhanced cybersecurity measures in healthcare, particularly for small rural facilities that may lack robust defenses. As data breaches become more commonplace, healthcare professionals must prioritize patient data protection to mitigate risks and maintain trust.
Dec 16, 2025·The Register
Google has raised an alarm regarding a critical vulnerability, CVE-2025-55182, in the React JavaScript library, which allows unauthorized code execution by attackers. Exploited by state-sponsored groups from China and Iran, as well as cybercriminals, this flaw has been linked to the deployment of malicious backdoors and cryptocurrency miners across over 50 organizations in various sectors. The swift exploitation of this vulnerability, disclosed by React maintainers on December 3, underscores significant cybersecurity risks and the urgent need for healthcare technology professionals to enhance their defenses against such threats. Addressing this issue is crucial for safeguarding sensitive healthcare data and infrastructure from escalating cyberattacks.
Dec 16, 2025·SecurityWeek
In the digital age, cybersecurity has become a critical component of business strategy rather than merely a technical issue, especially as threats to operations and reputations grow more sophisticated. Organizations are increasingly investing in advanced security measures, risk assessments, and employee training to protect sensitive information and maintain compliance. This shift necessitates the involvement of cybersecurity professionals in executive decision-making, emphasizing a collaborative culture of security awareness across all organizational levels. For healthcare professionals, understanding this trend is vital as it impacts patient data protection, regulatory compliance, and overall operational resilience in a sector increasingly targeted by cyber threats.
Dec 15, 2025·CUInfoSecurity
An analysis presented by Max Smeets at Black Hat Europe reveals that paying LockBit ransomware attackers can backfire by drawing more media attention, contrary to the hackers' assurances of confidentiality. Based on data from Britain's National Crime Agency, the study found that victims who paid ransoms received more media coverage than those who did not, illustrating a phenomenon similar to the Streisand Effect. This trend underscores a critical implication for healthcare professionals: paying ransoms may signal a loss of control and invite further scrutiny, potentially jeopardizing reputation and operational security. Additionally, the research suggests recent law enforcement crackdowns have led to a decline in LockBit's activities, indicating a shift in the ransomware landscape that healthcare organizations must navigate.
Dec 15, 2025·Cybersecurity Dive
The Cybersecurity and Infrastructure Security Agency (CISA) has released Version 2.0 of its Cross-Sector Cybersecurity Performance Goals (CPGs) to enhance protections for critical infrastructure, including healthcare facilities. This updated framework integrates insights from three years of operational experience and emphasizes the importance of business leadership in cybersecurity governance through a new "Govern" category. Key enhancements focus on consolidating information technology (IT) and operational technology (OT) goals, addressing supply-chain risks, and promoting zero-trust architecture. These changes aim to improve risk management and accountability, offering clearer guidance to help organizations tackle evolving cybersecurity threats effectively.
Dec 14, 2025·technology.org
An IP address, often overlooked as a technical detail, can reveal significant information about an individual's online identity, including their physical location and internet service provider. This data, especially when combined with browser fingerprints, can create detailed user profiles, raising serious privacy concerns in healthcare settings where sensitive information is exchanged. The ease of tracking through public Wi-Fi and shared networks magnifies these risks, potentially exposing healthcare professionals and patients to targeted advertising and even doxxing. As such, healthcare technology must prioritize robust privacy protections to safeguard user data against misuse.
Dec 14, 2025·The Cyber Express
Gartner has raised alarms about the cybersecurity risks posed by AI browsers, emphasizing their capacity for autonomous web navigation and transactions that could undermine traditional security protocols. Analysts cautioned that such browsers might inadvertently leak sensitive information or execute erroneous transactions, particularly if their default settings prioritize user experience over security. The ability of these browsers to autonomously access phishing sites and transfer data to cloud services heightens the urgency for enhanced security measures. This warning urges healthcare professionals and organizations to scrutinize the adoption of AI browsers, ensuring robust security frameworks are in place to mitigate these emerging threats.
Dec 11, 2025·The Register
December's Patch Tuesday saw significant updates from top tech firms, notably Microsoft, which addressed 57 critical vulnerabilities (CVEs), including one zero-day exploit that could allow local privilege escalation through the Windows Cloud Files Mini Filter Driver. This poses a serious threat as attackers with existing code execution can escalate their access to system-level controls. Notepad++ also responded to an active security risk that allowed traffic hijacking from its updater, emphasizing the need for stringent validation processes in software updates. These vulnerabilities highlight the ongoing challenges in securing healthcare technology systems, which often rely on software integrations that can be targeted by cyber threats.
Dec 11, 2025·TechRepublic
VITAS Healthcare, the largest for-profit hospice chain in the U.S., recently suffered a cybersecurity breach that compromised the sensitive information of over 319,000 patients, including personal and medical details. The attackers gained access through a third-party vendor's account, remaining undetected for 36 days and emphasizing critical vulnerabilities in healthcare vendor security. This incident reflects a troubling rise in cyberattacks targeting healthcare organizations, which have increasingly become lucrative targets for hackers. For healthcare professionals, this breach underscores the urgent need for enhanced cybersecurity measures to protect patient information, particularly for vulnerable populations in end-of-life care.
Dec 10, 2025·MeriTalk
The ISC2 Cybersecurity Workforce Study reveals a pivotal shift in the cybersecurity field, where skill deficiencies have overtaken headcount concerns as the primary issue facing organizations. The survey of over 16,000 cybersecurity professionals found that 59% reported significant skills shortages, particularly in areas such as artificial intelligence and cloud security. This highlights an urgent need for healthcare organizations to focus on developing specialized skills within their teams to effectively combat cybersecurity threats. As the hiring market stabilizes, addressing these skills gaps is essential for maintaining robust cybersecurity practices and protecting sensitive patient data.
Dec 9, 2025·StateScoop
New Jersey has launched its Civilian Cyber Resilience Corps as part of a broader initiative to enhance cybersecurity readiness and response within the state. Spearheaded by Chief Information Security Officer Michael Geraghty, this program will rely on volunteers to support cybersecurity preparedness and recovery efforts under the New Jersey Cybersecurity and Communications Integration Cell. By prioritizing a proactive approach to cybersecurity, the initiative aims to mitigate incidents before they escalate, following the successful models set by similar volunteer corps in states like Michigan. This development highlights the increasing recognition of volunteer contributions to cybersecurity frameworks, underscoring the vital role of community engagement in protecting healthcare data and infrastructure.
Dec 9, 2025·New York Times
As patients increasingly upload their complete medical records into chatbots for quick health advice, significant concerns about privacy, data security, and advice reliability arise. While the convenience of centralized health information is appealing, these chatbots often lack the sophistication to interpret complex medical data accurately, leading to potential misinterpretations and harmful recommendations. This trend emphasizes the ongoing need for integrated and user-friendly digital tools in healthcare, highlighting that patients should still seek guidance from qualified healthcare professionals. Addressing these issues is crucial to ensure that technology enhances, rather than undermines, patient care.
Dec 9, 2025·Cybersecurity Dive
The Cybersecurity and Infrastructure Security Agency (CISA) is phasing out its Cybersecurity Retention Incentive (CRI) program due to findings of mismanagement from a recent audit. The CRI program, launched in 2015 to retain cybersecurity talent through financial incentives, will be replaced by the Cyber Talent Management System (CTMS), which aims to streamline hiring and enhance salary competitiveness. This change underscores a strategic shift in how CISA plans to recruit and retain cybersecurity professionals, though it raises concerns regarding the future of current CRI beneficiaries and the potential impact on workforce stability. Healthcare technology sectors, which increasingly rely on cybersecurity expertise, may face challenges in attracting and retaining skilled professionals amid this transition.
Dec 8, 2025·Warner Senate
U.S. Senators have reintroduced the Health Care Cybersecurity and Resilience Act to strengthen cybersecurity in the health care sector, particularly for rural providers facing resource limitations. The bipartisan legislation aims to protect sensitive health data by offering grants for cybersecurity improvements and training on best practices. Additionally, it promotes enhanced interagency coordination between HHS and CISA for better response strategies against cyber threats. This act highlights the urgent need for improved cybersecurity measures to safeguard patient care and private medical information amid increasing cyberattack risks.