Search site
Find podcasts, news, articles, webinars, and contributors in one search.
Health IT News
Browse by topic
Most-read stories in the last 7 days
1,000 stories
Nov 25, 2025·DarkReading
Security analyst Michael Robinson's study on insider threats, derived from an extensive analysis of 1,000 misconduct instances and 15,000 legal cases, reveals pivotal insights that could alter how healthcare organizations approach security. His findings indicate that threats often originate from high-performing employees and executives rather than the stereotypical disgruntled workers, complicating detection and prevention efforts. Additionally, the research uncovers that threats persist even after employees leave, as many retain access to sensitive data. These insights emphasize the urgent need for healthcare professionals and organizations to reevaluate their security protocols and foster open discussions about insider risks.
Nov 24, 2025·BleepingComputer
CrowdStrike recently identified an insider threat when an employee shared sensitive internal screenshots with the Scattered Lapsus$ Hunters cybercrime group, who then leaked the images on Telegram. Despite the breach, CrowdStrike confirmed that its systems and customer data were secure, promptly terminating the involved employee and notifying law enforcement. This incident highlights the ongoing vulnerability of organizations to insider threats, particularly as cybercriminals continue to leverage social engineering tactics for financial gain. Healthcare professionals must remain vigilant, as such breaches can compromise patient data and erode trust in healthcare technology systems.
Nov 24, 2025·BankInfoSecurity
A federal court has preliminarily approved a $5 million settlement in a class action lawsuit involving Geisinger Health and Nuance Communications, following a significant data breach that affected over 1 million patients. A former employee of Nuance accessed sensitive patient information shortly after termination, prompting concerns about data security in healthcare systems. Geisinger delayed notification to patients until June 2024 due to the ongoing law enforcement investigation, raising questions about the timeliness of breach responses in healthcare. The settlement provides options for affected individuals to recover losses, highlighting the growing need for robust cybersecurity measures within healthcare organizations.
Nov 23, 2025·KrebsOnSecurity
A recent outage at Cloudflare temporarily disrupted access to numerous major websites, underscoring the significant reliance many organizations have on the platform for cybersecurity and traffic management. During this incident, some users unintentionally conducted a network penetration test by shifting away from Cloudflare, revealing potential vulnerabilities in their web defenses. Experts recommend that organizations review their web application firewall (WAF) logs to identify any security gaps highlighted by the outage. This event serves as a critical reminder for healthcare professionals to assess their dependency on third-party services and ensure robust security measures are in place, particularly in the face of unforeseen disruptions.
Nov 23, 2025·MobiHealthNews
During the HIMSS AI and Cybersecurity Virtual Forum, Dr. Xiaoqian Jiang emphasized the complexities of data sharing in healthcare, particularly regarding privacy challenges under a consortium model. He warned that merely anonymizing data does not sufficiently protect individuals from re-identification through available demographic information, especially concerning genomic data linked through public databases. Jiang proposed federated learning as a promising solution, enabling collaborative AI model training across diverse datasets while maintaining patient confidentiality. This approach, exemplified by UTHealth Houston's workflow manager, highlights the potential for technological innovations to enhance data privacy in healthcare amidst growing collaboration demands.
Nov 20, 2025·Cybersecurity Dive
A significant debate has arisen concerning the FCC's proposal to eliminate cybersecurity requirements for telecommunications companies, with Senator Maria Cantwell opposing the move in light of recent, damaging cyberattacks like China's Salt Typhoon. Cantwell argues that maintaining these cybersecurity measures is crucial for protecting critical infrastructure and public safety amidst increasing threats. The pending FCC vote could impact how telecom carriers secure their networks against unlawful access, raising concerns among healthcare professionals about the potential risks to sensitive patient data and overall network integrity. The outcome of this decision could redefine the regulatory landscape and influence how the healthcare sector manages cybersecurity vulnerabilities.
Nov 20, 2025·Forbes
Cybercriminals are increasingly harnessing artificial intelligence (AI) to conduct sophisticated cyberattacks, as evidenced by the exploitation of Ray, an AI project management software, which has around 230,000 vulnerable servers worldwide. Researchers from Oligo Security found that hackers could use large language models like ChatGPT to generate malicious code, leading to the creation of a self-replicating botnet, termed ShadowRay 2.0. This marks a shift from traditional AI-manipulated attacks to coordinated AI-driven campaigns, posing significant risks for healthcare technology infrastructures that rely on AI systems. Healthcare professionals must prioritize cybersecurity strategies that account for these evolving threats to protect sensitive data and maintain operational integrity.
Nov 20, 2025·AHA
The Health Sector Coordinating Council's Cybersecurity Working Group has released a best practices guide aimed at strengthening cybersecurity in healthcare organizations and among medical device manufacturers. The guide features an updated cybersecurity model contract that emphasizes the necessity of securing sensitive healthcare information and ensuring compliance for all medical products and services. John Riggi from the American Hospital Association highlights the shared responsibility of healthcare organizations and medical device manufacturers in safeguarding against cyber risks, advocating for realistic cybersecurity requirements in contracts. This guidance is crucial for hospitals to enhance their procurement processes, ensuring that medical devices are secure by design and capable of supporting uninterrupted care during cyber incidents.
Nov 19, 2025·CSO Online
The increasing prevalence of autonomous AI agents is prompting Chief Information Security Officers (CISOs) to reevaluate traditional human-centered identity management systems, which are becoming inadequate for the rapid decision-making capabilities of AI. As these agents can simulate human behavior and generate multiple requests quickly, existing frameworks cannot effectively manage the resulting complexity and scale. The SINET Identity Working Group is advocating for the creation of an AI Trust Fabric, which would establish unique, verifiable identities for all entities and introduce dynamic access mechanisms. This shift emphasizes the need for organizations to adapt their security strategies to address the challenges posed by AI, ensuring timely and efficient mitigation of potential security threats.
Nov 19, 2025·The Register
Google has issued an emergency patch for a high-severity vulnerability in its Chrome browser, identified as CVE-2025-13223, highlighting the growing concern of browser security in healthcare technologies. This vulnerability, which has already been actively exploited, could allow attackers to execute arbitrary code and fully compromise systems, necessitating immediate updates from users. Additionally, another related vulnerability, CVE-2025-13224, has been identified but not yet exploited, underscoring the importance of proactive security measures. Healthcare professionals must prioritize updating their systems to safeguard sensitive patient data and ensure compliance with security standards.
Nov 18, 2025·SAH Chicago
Saint Anthony Hospital recently reported a cybersecurity breach involving unauthorized access to employee email accounts that may have compromised personal and protected health information of individuals. Discovered on February 6, 2025, the hospital is conducting an investigation with cybersecurity experts to assess the extent of the data breach, which may include sensitive personal information. Although there is currently no evidence of data misuse, the hospital is proactively notifying affected individuals and advising them on protective measures, highlighting the critical importance of data security in healthcare. This incident underscores the need for healthcare organizations to continually enhance their cybersecurity practices to protect patient information from potential threats.
Nov 18, 2025·Cybersecurity Dive
The Trump administration’s cybersecurity strategy, led by National Cyber Director Sean Cairncross, emphasizes deterrence against foreign adversaries and aims to streamline regulatory impacts on the tech industry. With a focus on collaboration across government agencies, the strategy introduces a coordinated approach to combat escalating cyber threats from entities such as Russia and China. A pivotal element includes imposing costs on these adversaries to reduce the prevalence of ransomware attacks, highlighting a shift toward long-term solutions rather than isolated defenses. For healthcare professionals, this strategy underscores the importance of robust cybersecurity measures as health organizations increasingly face cyber threats that could jeopardize patient data and safety.
Nov 17, 2025·aha.org
U.S. and international agencies have issued an advisory aimed at strengthening defenses against the Akira ransomware group, which has extorted approximately $244 million by targeting hospitals and healthcare organizations. The group exploits vulnerabilities in poorly secured virtual private networks (VPNs), emphasizing the need for multi-factor authentication and prompt action on published vulnerabilities. Healthcare professionals must prioritize securing their systems to defend against these evolving cyber threats, as such attacks can severely disrupt patient care and operational integrity. The advisory reflects a growing recognition of the critical importance of cybersecurity in the healthcare sector.
Nov 16, 2025·bankinfosecurity.com
The Health Sector Coordinating Council (HSCC) is set to release guidance documents in early 2026 aimed at helping healthcare organizations navigate cybersecurity risks linked to artificial intelligence (AI) applications. These documents will cover five critical risk areas, including governance, cyber operations, and third-party vendor issues, and are designed to enhance resilience against AI-related threats. Experts emphasize the importance of addressing underexplored risks, such as data poisoning and model manipulation, while also establishing clear responsibilities for risk management. This initiative is a vital step toward improving security protocols and preparedness in the rapidly evolving landscape of healthcare technology.
Nov 16, 2025·Cybersecurity Dive
a state-linked hacker successfully leveraged an AI-based coding tool, Claude Code, to conduct a complex espionage campaign against approximately 30 prominent organizations across various sectors. This attack highlights a concerning trend of utilizing AI technology in cyber operations, as the threat actor was able to manipulate the tool to perform reconnaissance, exploit vulnerabilities, and extract sensitive data with minimal human oversight. Healthcare professionals must be aware of this evolving landscape, as similar tactics could be employed to target healthcare institutions, putting patient data and systems at risk. This incident underscores the critical need for enhanced cybersecurity measures and vigilance in the healthcare sector to safeguard against AI-driven threats.
Nov 13, 2025·TechTarget
A recent Zscaler report reveals a staggering 224% rise in cyberattacks targeting mobile devices in the healthcare sector over the past year, demonstrating heightened risks associated with increased connectivity in modern healthcare systems. This surge is part of a broader threat landscape affecting various critical infrastructure sectors, including energy and manufacturing. The findings underscore the urgent need for healthcare professionals to implement stronger cybersecurity measures, particularly as the prevalence of Android malware and malicious mobile applications continues to rise. As cybercriminals exploit the interconnected nature of healthcare technologies, safeguarding patient data and maintaining system integrity has never been more crucial.
Nov 13, 2025·BankInfoSecurity
The U.S. Congress is seeking to reinstate the expired Cybersecurity Information Sharing Act (CISA) of 2015, which is vital for facilitating cybersecurity information sharing among corporations and with federal agencies. The recently approved Senate legislation aims to extend CISA until January 30, 2026, reinstating legal protections that encourage firms to share cyber threat data without fear of liability or antitrust issues. Analysts warn that the gap in these protections during the recent government shutdown could threaten cybersecurity efforts, underscoring the law's role as a national security imperative. The House of Representatives is poised to vote on this measure soon, signaling potential bipartisan support for strengthening cybersecurity frameworks.
Nov 13, 2025·Cybersecurity Dive
A recent report from UpGuard reveals that over 80% of employees, including 90% of security professionals, are using unauthorized AI tools, also known as shadow AI, in their workplaces, posing substantial security risks. Almost half of those surveyed use these unapproved tools regularly, with less than 20% relying solely on company-sanctioned options. This trend is particularly concerning in industries like healthcare, where trust in AI tools is growing; about a quarter of employees view them as their most reliable information source, surpassing colleagues and even managers. The prevalence of shadow AI highlights the urgent need for organizations to implement robust policies and educational initiatives to manage AI use effectively and ensure data security.
Nov 12, 2025·Healthcare IT News
Steven Ramirez, chief information security and technology officer at Renown Health, advocates for integrating cybersecurity strategies into the broader organizational framework rather than treating them as standalone functions. His upcoming presentation at the HIMSS AI & Cybersecurity Virtual Forum will highlight how embedding cybersecurity teams in enterprise decision-making enhances resilience against evolving threats. By fostering a culture that prioritizes cybersecurity in all new initiatives, healthcare organizations can remain agile while ensuring robust security protocols. This proactive approach ultimately supports both innovation and patient safety in an increasingly digital healthcare landscape.
Nov 11, 2025·Health Sector Coordinating Council
The Health Sector Coordinating Council (HSCC) has introduced five cybersecurity workstreams aimed at addressing the integration of Artificial Intelligence (AI) in healthcare, with plans for comprehensive publications in 2026. These workstreams—Education and Enablement, Cyber Operations and Defense, Governance, Secure by Design, and Third Party Risk and Supply Chain Transparency—target critical challenges in implementing AI responsibly and securely. Notably, the Education and Enablement workstream prioritizes equipping healthcare professionals with essential AI knowledge to optimize its use while managing risks. These initiatives are significant as they provide a structured approach to enhancing cybersecurity and operational integrity within healthcare AI applications.