Search site
Find podcasts, news, articles, webinars, and contributors in one search.
Health IT News
Browse by topic
Most-read stories in the last 7 days
1,000 stories
Dec 8, 2025·Insurance Journal
The healthcare sector is experiencing an alarming surge in cyberattacks, witnessing a 90% increase in incidents in 2025 compared to the previous year. This escalation not only raises costs associated with ransomware and lawsuits but also emphasizes the need for specialized cyber risk assessment and management tailored to healthcare's unique vulnerabilities, such as legacy systems and limited cybersecurity resources. The rise of double extortion tactics by cybercriminals further complicates claims under cyber insurance policies, as exemplified by the February 2024 breach of Change Healthcare, which disrupted services for numerous providers and jeopardized patient safety. For healthcare professionals, these developments underscore the critical necessity for robust cybersecurity measures and comprehensive insurance strategies to mitigate the impact of such attacks.
Dec 7, 2025·Forbes
In 2025, significant changes in cybersecurity emerged, driven by government enforcement and high-profile cyber incidents. The U.S. Department of War introduced binding cybersecurity standards following critical infrastructure failures, highlighting the urgent need for compliance and increased accountability, especially in healthcare technology. Escalating nation-state cyber threats and direct attacks on civilian systems revealed vulnerabilities in digital infrastructure, emphasizing the importance for healthcare organizations to bolster their cyber defenses. These developments underscore the risks of reliance on major cloud providers and the necessity for proactive measures to ensure operational continuity in the face of evolving cyber threats.
Dec 7, 2025·firstalert4.com
A recent social media claim that BJC Healthcare revokes parental access to children's medical records at age 12 has led to an investigation by Missouri Attorney General Catherine Hanaway. The claim centers on the MyChart platform, which allows parents full proxy access until the child turns 12, after which access becomes limited. Epic Systems, the platform's developer, indicates that access rules are set by healthcare providers in accordance with legal standards. This incident highlights the nuanced dynamics of parental access to minors’ medical records, emphasizing the need for clear communication and understanding of privacy regulations among healthcare professionals.
Dec 4, 2025·Newswire
A recent Black Book Market Research survey shows that U.S. hospitals must prioritize funding in key cybersecurity domains from 2026 to 2028 to protect clinical operations and safeguard financial viability. Identity and access management emerged as the top focus, with 71% of IT leaders ranking it among their top three priorities, followed by endpoint and email security, ransomware resilience, and Zero Trust network security. As hospitals strive for maturity in these foundational areas, there remains a disparity in the faster progression of core domains versus slower advancements in cloud protection and clinical technology risks. This highlights the urgent need for healthcare organizations to enhance their cybersecurity frameworks to mitigate risks that could impact patient care and revenue.
Dec 4, 2025·Axios
Artificial intelligence (AI) is reshaping the landscape of cybercrime, making sophisticated attacks more accessible and efficient for a wider range of criminals. Recent incidents, such as the cyberattacks on the Port of Seattle, illustrate the potential risks posed by AI-enhanced threats, including deepfake scams and large-scale identity thefts. As AI lowers the barriers to entry for executing complex cyber operations, healthcare professionals must prepare for an environment where these threats can manifest rapidly and impact systems critical to patient care. The vulnerability of local agencies to the scale and velocity of these attacks underscores the urgent need for enhanced cybersecurity measures in healthcare institutions.
Dec 4, 2025·HealthcareInfoSecurity
Kaiser Permanente has reached a settlement of up to $47.5 million over a class action lawsuit regarding the unauthorized sharing of patient information through tracking codes on its digital platforms. This incident, which has been classified as a HIPAA breach affecting 13.4 million individuals, highlights significant privacy violations involving sensitive data disclosure to third parties like Google and Microsoft. Although Kaiser denies any wrongdoing, the settlement aims to circumvent lengthy litigation while underlining the critical need for healthcare organizations to enhance data protection practices. The case serves as a cautionary tale, emphasizing the importance of stringent compliance with privacy laws to safeguard patient information in an increasingly digital healthcare environment.
Dec 4, 2025·Cybersecurity Dive
Axis Communications has signed the Cybersecurity and Infrastructure Security Agency’s (CISA) Secure by Design pledge, committing to enhance the cybersecurity resilience of its surveillance products within a year. This decision comes after the identification of vulnerabilities in its cameras that could expose users to hacking risks, emphasizing the need for robust cybersecurity measures in physical security technologies. By implementing principles such as vulnerability disclosure and multifactor authentication, Axis seeks to set a standard for the industry, highlighting the critical importance of security in healthcare technology, where surveillance systems are increasingly used. This initiative reflects a growing awareness among healthcare professionals of the vulnerabilities associated with connected devices and the necessity for stringent cybersecurity practices.
Dec 3, 2025·BleepingComputer
The rise of crime-as-a-service (CaaS) in cybercrime reflects a troubling evolution within the digital threat landscape, enabling even inexperienced attackers to efficiently conduct cyber operations through subscription-based models. Services like phishing-as-a-service and one-time password (OTP) bots allow individuals to launch sophisticated attacks with minimal technical skills by renting tools and infrastructure. This shift emphasizes the increasing accessibility and professionalism of cybercriminal activities, posing significant risks to healthcare systems that rely on digital data security. For healthcare professionals, understanding these changing tactics is crucial for reinforcing cybersecurity measures and protecting sensitive patient information.
Dec 3, 2025·The Register
The ShadyPanda campaign has compromised 4.3 million users of Google Chrome and Microsoft Edge by embedding malware in legitimate browser extensions. After years of gathering downloads, these extensions pushed malicious updates that allowed extensive user tracking and data theft, targeting sensitive information and sending it to servers in China. While some malicious extensions have been removed, others remain active, posing ongoing risks to users and their data security. This situation highlights the urgent need for healthcare professionals and organizations to scrutinize software tools and implement robust cybersecurity measures to protect sensitive health information.
Dec 2, 2025·WebProNews
The emergence of rogue AI chatbots like WormGPT and FraudGPT is transforming cybercrime by empowering unskilled individuals to execute sophisticated attacks, such as generating malware and phishing scripts. These malicious large language models operate without ethical constraints, significantly lowering the barriers to entry for hackers and presenting a formidable challenge to cybersecurity practitioners. The use of AI in malware development enhances its ability to evade detection and adapt dynamically, complicating defensive measures for organizations. Consequently, healthcare professionals must prioritize enhanced security measures to safeguard sensitive patient data amid this evolving threat landscape.
Dec 1, 2025·Forbes
On November 26, OpenAI confirmed a security breach linked to its APIs, which was traced back to Mixpanel, a product analytics platform, following unauthorized access discovered on November 9. The breach exposed limited customer identifiable information, such as names and email addresses, affecting only API accounts, while everyday ChatGPT user accounts remained secure. This incident underscores the vulnerabilities associated with third-party integrations in healthcare technology, raising concerns about data privacy and security for users utilizing these APIs. Consequently, healthcare professionals must prioritize understanding API functionality and implementing robust security measures to safeguard against similar threats.
Dec 1, 2025·I'm sorry
Matt Christensen's appointment as the Assistant Vice President and Deputy Chief Information Security Officer at Intermountain Health underscores the growing importance of cybersecurity in healthcare. With his focus on enhancing information security strategies, Christensen is poised to play a critical role in protecting sensitive patient data amidst ongoing digital transformation in the sector. His acknowledgment of teamwork highlights the collaborative approach necessary for effective security practices. This leadership change is significant as healthcare organizations grapple with increasing cyber threats and the need for compliance with stringent industry regulations.
Dec 1, 2025·Cybersecurity Dive
Microsoft is enhancing the security of its Entra ID cloud identity management platform to mitigate account hijacking risks, with a new measure that prevents scripts from executing during the login process unless they originate from trusted Microsoft domains. This initiative, part of the broader Secure Future Initiative, addresses vulnerabilities exposed by recent cyberattacks, particularly cross-site scripting (XSS) risks. While this update will modify the Content Security Policy (CSP) header, it does not affect Entra External ID used in non-web applications. Healthcare professionals should take note of these changes and test their sign-in processes in advance to ensure secure access and protect sensitive health data.
Nov 30, 2025·govinfosecurity.com
New York State has introduced new cybersecurity regulations for hospitals, effective October 1, that could set a precedent for healthcare providers across the United States. Key requirements include multifactor authentication, risk analysis, incident response protocols, and the appointment of a qualified Chief Information Security Officer (CISO). This shift emphasizes the need for experienced cybersecurity leadership amid a shortage of qualified candidates in the healthcare sector. As other states may adopt similar regulations, compliance with New York's standards is likely to become a focal point for insurers, potentially elevating overall cybersecurity practices in healthcare.
Nov 30, 2025·Financial Times
The UK Health Minister has proposed leveraging the NHS's extensive patient data to generate revenue, suggesting that such an approach could alleviate financial pressures while fostering innovation in healthcare. While this idea presents an opportunity to enhance research and patient care, it raises significant privacy and ethical concerns regarding the commercialization of sensitive data. Critics emphasize the need for safeguards to protect patient confidentiality, and the proposal will require transparency about how generated funds are allocated to gain public trust. Ultimately, the success of this initiative will depend on balancing data utilization for public benefit with strict privacy protections.
Nov 26, 2025·SecurityWeek
the findings underscore the urgent need for healthcare professionals to enhance their cybersecurity protocols, as the healthcare sector is particularly vulnerable to such personalized attacks. The ability of AI to tailor phishing messages using detailed personal information raises significant concerns about patient data security and trust. As cybercriminals leverage these advanced AI capabilities, healthcare organizations must pivot towards implementing more robust defenses, including AI-enhanced detection tools, to safeguard sensitive information. This evolution in the threat landscape highlights the critical intersection of technology and healthcare, emphasizing the need for ongoing vigilance and adaptation in security practices.
Nov 26, 2025·NKC Health
NKC Health has alerted patients to a cybersecurity incident involving Cerner, an electronic medical record vendor, where unauthorized access to sensitive data may have occurred as early as January 22, 2025. Although NKC Health's systems remain secure, the breach potentially affects personal health information, including names, dates of birth, and medical records, although Cerner has not confirmed if specific individuals' detailed medical data were compromised. The incident underscores the vulnerabilities in healthcare data management and highlights the importance of robust cybersecurity measures within the industry. As Cerner responds by securing its systems and cooperating with law enforcement, healthcare professionals must prioritize safeguarding patient information to maintain trust and compliance.
Nov 25, 2025·aha.org
The National Institute of Standards and Technology (NIST) has revealed a significant vulnerability in the widely used 7-Zip software, allowing potential attackers to execute arbitrary code on affected systems. This discovery highlights urgent security concerns for healthcare organizations that utilize 7-Zip for data management, prompting immediate software updates to shield against exploitation. Concurrently, U.S. and international agencies have issued a guide to combat cybercrimes involving bulletproof hosting providers, emphasizing the necessity for collaborative efforts in addressing these threats. Additionally, a joint advisory offers updated strategies for defending against the Akira ransomware group, underscoring the importance of enhancing cybersecurity measures within healthcare and other sectors.
Nov 25, 2025·HR Reporter
A recent privacy breach at an Ontario hospital has exposed critical vulnerabilities in data protection related to AI transcription tools. The incident resulted from a former physician using a personal email for hospital communications and being improperly retained on meeting invite lists, which allowed Otter.ai to record and disseminate sensitive patient information from a virtual meeting. With the personal health information of seven patients compromised and a number of email recipients being former employees, the breach raises significant concerns about data security in healthcare. Experts stress the importance of preparing for the unintentional consequences of AI tools, as evolving regulations in Canada necessitate improved oversight and accountability in their deployment within healthcare settings.
Nov 25, 2025·Insurance Journal
Healthcare professionals in Canada are increasingly adopting public AI tools like ChatGPT and Claude to streamline processes such as drafting clinical notes and translating documents. However, the unregulated use of these tools, referred to as "shadow AI," raises significant cybersecurity concerns, particularly regarding the potential exposure of sensitive patient information due to data breaches. A recent IBM Security report highlights that the average cost of a data breach has surged to nearly US$4.9 million globally, underscoring the urgent need for healthcare organizations to exercise caution. While cases of breaches linked to shadow AI in healthcare remain infrequent, the silent nature of these risks demands proactive measures to protect patient privacy.