Search site
Find podcasts, news, articles, webinars, and contributors in one search.
Health IT News
Browse by topic
Most-read stories in the last 7 days
1,000 stories
Oct 30, 2025·Cybersecurity Dive
A recent report by Vanta and Sepio Research highlights a growing disconnect between the rapid adoption of AI technologies in the corporate sector and the development of essential security and governance frameworks. Approximately two-thirds of IT and business leaders recognize that their understanding of agentic AI lags behind its implementation, and 60% express concerns about evolving AI-based cyber threats. Despite 80% of surveyed leaders prioritizing AI deployment, the absence of robust governance and incident response strategies poses significant risks as organizations integrate these technologies into their operations. These findings underscore the urgent need for healthcare professionals and organizations to prioritize security measures as they adopt AI solutions.
Oct 29, 2025·CyberScoop
Attackers are actively exploiting a critical vulnerability in Windows Server Update Services (WSUS), identified as CVE-2025-59287, which affects software versions dating back to 2012. Despite Microsoft issuing a patch, the vulnerability continues to be exploited due to unpatched systems, with CISA urging organizations to apply the mitigation measures immediately. The rapid response from attackers highlights the urgent need for healthcare IT professionals to prioritize timely software updates and vulnerability management to protect sensitive patient data. The incident reveals the challenges in maintaining cybersecurity in healthcare environments, emphasized by the prevalence of exposed systems that can easily fall victim to such attacks.
Oct 29, 2025·techcrunch.com
AI-powered web browsers, such as OpenAI's ChatGPT Atlas and Perplexity's Comet, are emerging as alternatives to traditional browsers like Google Chrome, featuring AI agents that can assist with tasks. However, experts warn that these technologies carry significant privacy risks, requiring extensive access to personal data and making users vulnerable to cyber threats, particularly prompt injection attacks. These vulnerabilities can lead to unauthorized data exposure and unintended actions, posing serious implications for user security. As adoption of these AI agents increases, healthcare professionals and consumers must remain vigilant about the potential risks associated with their use in managing sensitive information.
Oct 27, 2025·csoonline.com
Chief Information Security Officers (CISOs) are facing intensified stress and challenges in securing healthcare-related technologies amid the rise of AI-enabled cyberattacks, with 66% of security leaders reporting increased stress over the last five years. As AI becomes integrated into systems, 80% of CISOs identify AI-powered threats as their foremost concern, prompting an urgent reevaluation of security protocols and training. The growing volume of unstructured, AI-generated data further complicates data governance and protection efforts, underscoring the need for innovative cybersecurity strategies within healthcare. This evolving landscape necessitates that healthcare professionals prioritize robust security measures to safeguard sensitive information against rapidly advancing threats.
Oct 27, 2025·The Record
The U.N. convention on cybercrime, recently adopted after five years of negotiations, aims to enhance international cooperation in cybercrime investigations but has raised alarms among tech companies and human rights organizations. Critics argue that it could enable increased electronic surveillance and cross-border data sharing without sufficient safeguards, potentially facilitating digital repression by authoritarian governments. As the U.S. deliberates its position on signing the treaty, healthcare professionals should be aware of the implications for patient data security and privacy, as the framework could influence how health information is handled in the digital age. Balancing the need for enhanced cybersecurity with the protection of individual rights will be crucial for maintaining trust in healthcare technologies.
Oct 26, 2025·Tom's Guide
In December 2025, Microsoft Teams will implement a feature that utilizes office Wi-Fi to automatically track employees’ locations, indicating whether they are physically present in the office. This shift aims to provide employers with greater visibility into team members’ whereabouts, potentially undermining the remote work arrangements that many employees view as beneficial for productivity. While the feature will be off by default and requires opt-in from users, its introduction raises concerns about employee privacy and the implications for workplace autonomy. As companies increasingly adopt monitoring technologies, this development reflects a broader trend in shifting post-pandemic work dynamics and employee management practices.
Oct 23, 2025·HIPAA Journal
The September 2025 Healthcare Data Breach Report indicates a decline in reported data breaches, with a total of 469 incidents year-to-date, down from 554 the previous year. However, this positive trend is undercut by incomplete data due to a government shutdown that halted updates to the Health and Human Services’ Office for Civil Rights portal; thus, the actual number may rise once reporting resumes. September saw the lowest monthly count of breaches affecting over 500 individuals since December 2018, reflecting a significant drop in exposed personal health information. For healthcare professionals, these findings underscore the need for continued vigilance in data security practices even as breach numbers appear to decline.
Oct 23, 2025·UC San Diego Today
UC San Diego's Center for Healthcare Cybersecurity is addressing the growing threat of cyberattacks on hospitals with its Project CRASHCART, which maintains essential services during incidents like ransomware attacks through a temporary private 5G network. The center's research underscores the critical impact of such attacks on patient care, demonstrating that one incident can overwhelm surrounding facilities and degrade patient outcomes. Emphasizing the need for robust cybersecurity protocols, the center advocates for practices beyond traditional staff training, such as implementing two-factor authentication and monitoring for early detection of threats. This proactive approach marks a significant step forward in enhancing the resilience of healthcare technology against cyber risks.
Oct 22, 2025·IT Brew
In 2025, the rise of deepfakes and AI-driven cyberattacks has prompted security awareness training (SAT) companies to innovate their educational approaches, highlighting a critical yet growing threat in cybersecurity. Companies like Adaptive Security and Breacher.ai are utilizing realistic simulations that mimic deepfake scenarios to train employees in recognizing and responding to potential attacks, ultimately aiming to mitigate financial losses stemming from these security breaches. With an emphasis on interactive and adaptive training, these programs are proving effective in decreasing employee error rates during simulated attacks, which is vital for maintaining organizational security. As the sophistication of cyber threats increases, incorporating advanced training methods becomes essential for healthcare professionals to safeguard sensitive information and operational integrity.
Oct 22, 2025·Cybersecurity Dive
A report by security firm ReliaQuest reveals that ransomware-as-a-service (RaaS) groups are increasingly adopting AI-powered tools, significantly reducing their attack execution time from 48 minutes in 2024 to just 18 minutes by mid-2025. These innovations, such as automated antivirus evasion techniques, not only streamline the operational efficiency of cybercriminals but also boost the appeal of their services to potential affiliates. This trend underscores a growing cybersecurity threat, as healthcare organizations may face heightened risks from more sophisticated and faster ransomware attacks enabled by AI technology. As such, healthcare professionals must enhance their cybersecurity measures to combat this evolving landscape.
Oct 22, 2025·Wired
A study by researchers from UC San Diego and the University of Maryland has revealed that approximately 50% of geostationary satellite signals are unencrypted, making sensitive communications vulnerable to interception. The researchers demonstrated this using an $800 receiver, capturing a broad spectrum of unprotected data, including critical infrastructure and military communications. This finding exposes a significant oversight in the perceived security of satellite communications and raises urgent concerns for healthcare technology, particularly as sensitive health data could also be at risk. While some companies like T-Mobile have begun encrypting their transmissions, the widespread nature of the vulnerability indicates a pressing need for improved security measures across the industry.
Oct 21, 2025·Bitdefender
The global internet outage on October 20, 2025, caused by a fault in Amazon Web Services, disrupted major platforms like Snapchat and Fortnite, revealing the precariousness of our digital infrastructure. This incident emphasizes the necessity for healthcare technology stakeholders to not only bolster defenses against cyber threats but also to establish robust redundancies and contingency plans to manage unexpected disruptions. The outage serves as a critical reminder of the vulnerabilities inherent in interconnected systems, highlighting the need for healthcare organizations to prioritize resilience alongside cybersecurity measures. As reliance on digital solutions continues to grow, understanding and mitigating the risks associated with infrastructure failures is essential for maintaining operational continuity and patient care.
Oct 21, 2025·BankInfoSecurity
Heywood Healthcare is currently facing a severe cyberattack that has forced the non-profit system to take its IT network offline, disrupting essential services and redirecting ambulance patients from its two hospitals. The attack has particularly impacted radiology and laboratory capabilities, causing emergency services to steer stroke patients to alternative facilities. This incident highlights the growing vulnerability of healthcare organizations to cyber threats, which not only compromise patient care but also pose significant operational risks and financial burdens. As cybercriminals increasingly target healthcare for profit, it underscores the urgent need for robust cybersecurity measures within the sector.
Oct 20, 2025·Cybersecurity Dive
Nation-state hackers breached F5's systems, compromising its application security products and stealing files that included source code and information on vulnerabilities. Although F5 maintains that the exposed vulnerabilities are not critical, the theft of configuration information could facilitate future attacks on clients. This incident highlights the ongoing risks faced by healthcare technology systems, emphasizing the need for agencies to promptly secure their infrastructures. In light of this breach, CISA has directed federal agencies to review and update their security measures to mitigate potential threats.
Recent studies reveal that traditional security awareness training for employees is largely ineffective in reducing susceptibility to phishing attacks, challenging the notion that human behavior is the weakest link in cybersecurity. Research from institutions like the University of Chicago and ETH Zurich indicates that common training methods fail to bolster resilience against attacks and may, in fact, foster overconfidence. This highlights a crucial need for healthcare organizations to rethink their cybersecurity training strategies, as existing programs may not adequately equip employees to navigate digital threats. The implications for healthcare professionals are significant, necessitating a shift towards more effective methods of behavior change that align training with real-world application.
Oct 16, 2025·BankInfoSecurity
New York hospitals must now adhere to stricter cybersecurity regulations than the federal HIPAA security rule, introducing significant compliance challenges for healthcare providers. Effective from October 2024, hospitals are required to report cyber incidents within 72 hours and must comply with additional mandates by October 2025, including multifactor authentication and appointing a Chief Information Security Officer. These regulations extend beyond HIPAA-protected data to include personally identifiable and business information, complicating data governance efforts. Healthcare professionals need to proactively demonstrate compliance plans to regulators, addressing the challenges posed by this expanded data landscape.
The Cybersecurity and Infrastructure Security Agency (CISA) has warned that a nation-state cyberthreat actor poses an imminent risk to federal networks amid the current government shutdown, following a breach of F5's systems. The actor has stolen sensitive data, including source code, enabling them to potentially create targeted exploits for federal systems. While CISA has confirmed that there is no evidence of active exploitation against federal networks yet, the ongoing shutdown has hampered the agency's response capacity, with only 35% of its staff available to manage critical cybersecurity threats. This situation underscores the vulnerabilities in federal cybersecurity infrastructure and the urgency for healthcare professionals to reinforce defenses against potential breaches that could impact sensitive health information systems.
Oct 16, 2025·healthexec.com
Cyberattacks on healthcare organizations are increasingly compromising patient care, with 72% of institutions reporting delays due to common threats like ransomware and supply chain attacks—up from 69% the previous year. A recent report from Proofpoint and the Ponemon Institute highlights that 93% of surveyed entities experienced a cyberattack in the past year, with 96% facing data loss or exfiltration, causing significant disruptions in patient services. The link between cyber safety and patient safety is crucial, as attacks can lead to prolonged hospital stays and suboptimal clinical outcomes, ultimately endangering lives. This underscores the urgent need for healthcare professionals to prioritize cybersecurity measures to protect both data and patient care quality.
Oct 15, 2025·Dark Reading
AI notetaking applications are increasingly integrated into video meeting platforms, facilitating automatic note capture but introducing significant cybersecurity and governance risks for healthcare organizations. Many of these tools lack necessary security measures, such as SOC 2 compliance, which raises concerns about the mishandling or exposure of sensitive information. Furthermore, the potential for "record steering" undermines the integrity of transcripts, as comments may be intentionally manipulated, leading to inaccuracies in the decision-making record. Healthcare professionals must navigate these challenges carefully, ensuring that the benefits of AI notetaking do not compromise the security and reliability of patient data management.
Oct 15, 2025·HIPAA Journal
Integris Health has reached a $30 million settlement to resolve a class action lawsuit stemming from a major data breach in 2023 that exposed the electronic protected health information of over 2.38 million individuals. Unauthorized access occurred when hackers infiltrated the healthcare provider's systems, obtaining sensitive patient data, including Social Security numbers. The incident, which involved unencrypted files, raised significant concerns about the efficacy of security measures in healthcare technology, highlighting the critical need for stronger data protection protocols. Integris Health attributed the breach to a third-party vendor but faced scrutiny for its own security practices, a reminder for healthcare organizations to prioritize cybersecurity in their operations.