Coverage
Hand-authored analysis of breaches, enforcement actions, and regulatory developments — what happened, what controls would have prevented it, what an independent practice should check on its own systems.
- Industry analysis
Ransomware groups now index and price stolen data before publishing it
Dark-web research finds extortion actors are analyzing breached records into searchable, segmented assets before release, raising the stakes for any organization holding sensitive patient data.
- Industry analysis
Ransomware groups now index and price stolen data before publishing it
Dark-web researchers document a shift in extortion tactics where threat actors analyze and categorize stolen records into searchable, targetable assets before any public release or sale.
- Industry analysis
Ransomware groups now index and price stolen data before publishing it
Dark-web research finds extortion actors are structuring stolen records into searchable, tiered assets, raising the downstream exposure risk for breached healthcare organizations.
- Industry analysis
Ransomware groups now index and price stolen data before publishing it
Dark-web researchers document a shift in extortion tactics where threat actors analyze and segment stolen records into searchable, targetable assets rather than releasing raw bulk dumps.
- Industry analysis
Crime Stoppers International launches bounty program targeting INC Ransomware group
Operation Silent Vector marks the first public bounty initiative aimed at unmasking INC Ransomware operators, a group with a documented record of attacks against hospitals and health systems.
- Industry analysis
Crime Stoppers International launches bounty program targeting INC Ransomware group
Crime Stoppers International has opened a tip line targeting INC Ransomware operators under Operation Silent Vector, a development with direct relevance to US healthcare organizations hit by the group.
- Industry analysis
Crime Stoppers International launches bounty program targeting INC Ransomware operators
Operation Silent Vector offers rewards for tips leading to arrests of INC Ransomware members, a group that has repeatedly struck hospitals and health systems across the United States.
- Industry analysis
Crime Stoppers International launches bounty program targeting INC Ransomware operators
Operation Silent Vector, the first initiative of its kind from Crime Stoppers International, offers rewards for tips leading to arrests of INC Ransomware members — a group with a documented record of attacks on healthcare providers.
- Industry analysis
House attaches decade-long CISA reauthorization to defense bill in narrow vote
The U.S. House passed its FY2027 defense authorization bill 216–212, embedding a ten-year reauthorization of the Cybersecurity Information Sharing Act that healthcare entities rely on for threat intelligence feeds.
- Industry analysis
House attaches decade-long CISA reauthorization to defense bill in narrow vote
The U.S. House passed its FY2027 defense authorization act 216–212, embedding a ten-year reauthorization of the Cybersecurity Information Sharing Act that health sector entities rely on for threat intelligence exchange.
- Industry analysis
Iranian-affiliated actors targeting internet-connected OT devices across US critical infrastructure sectors
A joint cybersecurity advisory warns that Iranian-affiliated threat actors are actively exploiting programmable logic controllers across US critical infrastructure, with healthcare facilities among the sectors at risk.
- Industry analysis
Ransomware groups extort victims a second time even after initial payment, survey finds
New survey data shows 22 percent of organizations that paid a ransom faced a follow-up extortion demand, reinforcing long-standing warnings from law enforcement against paying attackers.
- Industry analysis
Paying ransomware attackers doubles the risk of a second extortion demand, survey data shows
New survey data shows 22 percent of organizations that pay a ransom are extorted again, reinforcing long-standing guidance that payment does not end an incident for healthcare targets.
- Industry analysis
Ransomware payment bans take shape as nearly half of victims pay up
New research shows median ransom demands climbing as regulators in several countries weigh banning payments outright, forcing healthcare organizations to reconsider their incident response calculus.
- Industry analysis
Ransomware payment bans put healthcare targets in a tightening bind
Nearly half of ransomware victims pay the ransom, Sophos research shows, as governments in the UK and elsewhere move to prohibit payments outright, leaving healthcare organizations with shrinking options.
- Industry analysis
Ransomware payment bans gain momentum as nearly half of victims pay up
New Sophos research shows nearly half of ransomware victims pay the demanded ransom, even as jurisdictions in the UK and elsewhere move to prohibit payments outright.
- Industry analysis
Ransomware payment debate intensifies as demands rise and bans spread
Nearly half of ransomware victims paid a ransom in 2025, Sophos research shows, while several jurisdictions are moving toward outright payment bans that could reshape how healthcare organizations respond to attacks.
- Industry analysis
Ransomware payment bans advance as nearly half of victims still pay
New Sophos research shows median ransom demands climbing while jurisdictions including the UK move toward outright payment prohibitions, forcing healthcare organizations to rethink incident response planning.
- Industry analysis
Ransomware payment bans gain traction as nearly half of victims still pay
New Sophos research puts ransomware payment rates at nearly 50% globally as the UK and other jurisdictions move toward outright payment prohibitions, raising compliance and recovery questions for healthcare organizations.
- Industry analysis
Ransomware payment bans gain traction as ransom demands climb
Nearly half of ransomware victims paid attackers in 2025, Sophos research shows, while governments in multiple jurisdictions move toward outright payment prohibitions.
- Industry analysis
Ransomware payment bans gain traction as median demands climb
Nearly half of ransomware targets paid attackers in 2025, Sophos research shows, as governments weigh prohibiting payments — a shift that would force healthcare organizations to harden defenses or face prolonged outages.
- Industry analysis
Ransomware payment bans gain traction as median demands climb
Nearly half of ransomware victims pay attackers, Sophos research shows, as governments in the UK and elsewhere move toward outright payment bans that would reshape incident response for healthcare organizations.
- Industry analysis
Ransomware payment bans gain traction as nearly half of victims pay up
New research shows nearly half of ransomware victims pay demanded ransoms, while governments in the UK and elsewhere move to restrict or ban payments outright, putting healthcare organizations in a difficult position.
- Industry analysis
Ransomware payment bans gain ground as nearly half of victims pay up
New Sophos research shows nearly half of ransomware victims pay demands, while UK and other jurisdictions move toward outright payment bans, sharpening the dilemma for healthcare targets.
- Industry analysis
Ransomware payment bans gain traction as nearly half of victims pay up
New research shows roughly half of ransomware victims pay demands as median ransom amounts climb, while governments in the UK and elsewhere debate outright payment prohibitions.
- Industry analysis
Ransomware payment bans gain traction as median demands climb
Nearly half of ransomware victims paid attackers in 2025, Sophos research shows, as governments in multiple jurisdictions move to prohibit ransom payments outright.
- Industry analysis
Finland issues wanted notice for hacker behind psychotherapy data breach
Finnish police have issued an international wanted notice for a convicted hacker who allegedly fled rather than return to prison after a landmark psychotherapy records breach affecting tens of thousands of patients.
- Industry analysis
ShinyHunters OAuth abuse campaign targets SaaS platforms used across industries
Microsoft researchers documented a year-long ShinyHunters campaign combining voice phishing, supply chain compromise, and misconfigured guest access to breach SaaS environments — a threat pattern directly relevant to healthcare.
- Industry analysis
Progress Software urges ShareFile admins to shut down servers over credible threat
Progress Software has told on-premises ShareFile Storage Zone Controller customers to shut down servers immediately after identifying what it calls a credible external security threat to the file-sharing platform.
- Industry analysis
Progress Software urges ShareFile customers to shut down on-premises servers over credible threat
Progress Software has told ShareFile Storage Zone Controller customers to shut down servers immediately after identifying what it calls a credible external security threat targeting the on-premises file-sharing software.
- Industry analysis
Progress Software urges ShareFile admins to shut down servers over credible threat
Progress Software told ShareFile Storage Zone Controller customers to take servers offline immediately after identifying what it called a credible external security threat to the on-premises file-sharing platform.
- Industry analysis
Progress Software urges ShareFile admins to shut down on-premises servers over credible threat
Progress Software told ShareFile Storage Zone Controller customers to shut down servers immediately after identifying a credible external security threat against the on-premises file-sharing platform.
- Industry analysis
Progress Software urges ShareFile admins to shut down servers over credible threat
Progress Software told ShareFile Storage Zone Controller customers to take servers offline immediately after identifying what it called a credible external security threat to the on-premises file-sharing platform.
- Industry analysis
Progress Software urges ShareFile admins to shut down servers over credible threat
Progress Software has told ShareFile customers running on-premises Storage Zone Controllers to shut down their servers immediately after identifying a credible external security threat to the file-sharing platform.
- Industry analysis
Progress Software tells ShareFile admins to shut down servers over credible threat
Progress Software has urged customers running ShareFile Storage Zone Controllers to take their servers offline immediately after identifying what the company describes as a credible external security threat.
- Industry analysis
Progress tells ShareFile admins to shut down servers over credible threat
Progress Software has urged customers running on-premises ShareFile Storage Zone Controllers to immediately take servers offline after identifying what it calls a credible external security threat to the file-sharing platform.
- Industry analysis
Progress tells ShareFile admins to shut down servers over credible threat
Progress Software has urged on-premises ShareFile Storage Zone Controller customers to take servers offline immediately after identifying what it calls a credible external security threat targeting the file-sharing platform.
- Industry analysis
Ransomware negotiator who fed victim intelligence to BlackCat gets 70-month sentence
A former DigitalMint negotiator was sentenced to 70 months in prison after colluding with BlackCat ransomware operators, sharing victims' defense strategies to maximize extortion payouts.
- Industry analysis
Washington DSHS discloses insider breach affecting 8,600 people
A former Washington Department of Social and Health Services employee accessed sensitive personal records without authorization in March, prompting a breach notice affecting roughly 8,600 individuals.
- Industry analysis
South Africa ruling confirms misdirected emails trigger mandatory breach reporting
An enforcement notice against a South African college shows that accidental email disclosures can constitute reportable data breaches under POPIA, a threshold question US practices face under HIPAA as well.
- Industry analysis
New Zealand pharmacy data leak exposes patient messages sent through contact form
A Wellington pharmacy found that private patient messages submitted through its website contact form had been publicly indexed online, affecting 29 individuals before the content was removed.
- Industry analysis
Analysts argue breach focus on threat actors obscures deeper structural failures
A commentary published on SuspectFile contends that the healthcare and broader data-holding sector fixates on who attacks while overlooking why so much sensitive data sits exposed in the first place.
- Industry analysis
Security analysis shifts focus from attackers to structural data-retention failures
A SuspectFile commentary argues that healthcare and other sectors fixate on threat-actor attribution while ignoring the data-accumulation practices that make breaches catastrophic when they occur.
- Industry analysis
Analysis argues healthcare fixates on attackers while ignoring structural data risks
A published commentary contends that organizations consistently overfocus on threat-actor attribution while overlooking the root causes that make breaches possible — excessive data collection, centralization, and retention.
- Industry analysis
Threat-actor focus masks the structural data problem driving breach severity
A security analyst argues that healthcare organizations fixate on identifying attackers while neglecting the root conditions — excess data collection, centralization, and long retention — that make breaches catastrophic.
- Industry analysis
Overfocus on attackers leaves root causes of healthcare breaches unaddressed
An analysis published on SuspectFile argues that organizations fixate on threat actor attribution while ignoring the structural data practices that make breaches so damaging when they occur.
- Industry analysis
Analysts urge healthcare to examine data retention as a root cause of breach harm
A SuspectFile analysis argues that the healthcare sector's habit of centralizing and retaining vast amounts of sensitive data creates structural conditions that make breaches severe regardless of who launches them.
- Industry analysis
Industry analysis shifts focus from threat actors to structural data practices
A SuspectFile analysis argues that organizations fixate on identifying attackers while ignoring the root causes that make breaches catastrophic — excessive data collection, centralization, and retention.
- Industry analysis
Five Eyes alliance warns AI is shrinking the attack timeline to months
A three-page joint statement from the US, UK, Canada, Australia, and New Zealand signals that AI-assisted cyberattacks are arriving faster than most organizations have planned for.
- Industry analysis
Five Eyes alliance warns AI-powered cyberattacks are months away, not years
A joint intelligence statement from the US, UK, Canada, Australia, and New Zealand warns that frontier AI models are accelerating offensive hacking capabilities on a timeline that demands immediate action from all sectors.
- Industry analysis
Five Eyes intelligence alliance warns AI is compressing the cyberattack timeline to months
A joint statement from the US, UK, Canada, Australia, and New Zealand warns that frontier AI models are accelerating offensive hacking capabilities faster than most organizations have planned for.
- Industry analysis
Novo Nordisk weathered two simultaneous data breaches without a stock hit — here's what that reveals
Novo Nordisk suffered concurrent intrusions from independent threat actors in June 2026, with intellectual property among the alleged stolen data, yet capital markets registered almost no reaction.
- Industry analysis
Novo Nordisk absorbed two simultaneous data breaches without a stock collapse — here is why
Two independent threat actors claimed Novo Nordisk data within weeks of each other, yet the pharma giant's share price held steady, illustrating how breach disclosure outcomes increasingly hinge on perceived operational continuity.
- Industry analysis
FortiBleed campaign extracts working admin credentials from tens of thousands of Fortinet firewalls globally
Researchers identified a large-scale credential-compromise campaign targeting Fortinet FortiGate firewalls, with verified administrator credentials extracted from up to 75,000 devices across 194 countries.
- Industry analysis
FortiBleed campaign extracts working admin credentials from up to 75,000 Fortinet firewalls worldwide
A large-scale credential-harvest campaign targeting Fortinet FortiGate firewalls has yielded verified administrator access to tens of thousands of devices across 194 countries, raising urgent concerns for healthcare networks.
- Industry analysis
FortiBleed campaign exposes administrator credentials on tens of thousands of Fortinet firewalls
A large-scale credential-extraction campaign targeting Fortinet FortiGate devices has yielded verified administrator access for up to 75,000 firewalls across 194 countries, raising immediate concerns for healthcare networks.
- Industry analysis
FortiBleed campaign yields working admin credentials for up to 75,000 firewalls globally
Researchers identified an active credential-extraction campaign against Fortinet FortiGate firewalls in mid-June 2026, leaving verified administrator access exposed across 194 countries and an estimated 30,000 to 75,000 devices.
- Industry analysis
FortiBleed campaign exposes administrator credentials on tens of thousands of Fortinet firewalls
Researchers identified an active credential-harvesting campaign against Fortinet FortiGate firewalls affecting up to 75,000 devices across 194 countries, with verified working administrator credentials in threat actor hands.
- Industry analysis
FortiBleed campaign yields working admin credentials for up to 75,000 firewalls worldwide
Researchers identified a large-scale credential-extraction campaign against Fortinet FortiGate firewalls in mid-June 2026, with verified administrator credentials harvested from tens of thousands of devices across 194 countries.
- Industry analysis
FortiBleed campaign extracts working admin credentials from tens of thousands of Fortinet firewalls
A large-scale credential-harvesting operation targeting Fortinet FortiGate devices has yielded verified administrator access on an estimated 30,000 to 75,000 firewalls across 194 countries, researchers confirmed in mid-June 2026.
- Industry analysis
FortiBleed campaign yields verified admin credentials for up to 75,000 firewalls worldwide
A large-scale credential extraction campaign targeting Fortinet FortiGate devices has produced working administrator credentials for tens of thousands of internet-facing firewalls, with healthcare networks among the exposed.
- Industry analysis
FortiBleed campaign extracts admin credentials from up to 75,000 Fortinet firewalls globally
A large-scale credential-harvesting campaign targeting Fortinet FortiGate firewalls has yielded verified administrator access to tens of thousands of devices worldwide, raising immediate exposure concerns for healthcare networks.
- Industry analysis
INC ransomware group thrives by targeting high-pressure sectors like healthcare
Analysis of the INC ransomware group shows the operation succeeds not through technical sophistication but by focusing on sectors where downtime creates immediate pressure to pay.
- Industry analysis
INC ransomware group targets healthcare by exploiting operational pressure
Analysis of the INC ransomware group shows it has grown by targeting sectors where disruption creates immediate payment pressure, with healthcare among its primary focus areas.
- Industry analysis
INC ransomware group targets healthcare by exploiting operational pressure
Analysis of the INC ransomware group shows it deliberately targets sectors where service disruption creates immediate pressure to pay, with healthcare among its primary focuses.
- Industry analysis
FulcrumSec leaks Novo Nordisk data after $25 million ransom goes unpaid
Ransomware group FulcrumSec published stolen data from Novo Nordisk following an unpaid $25 million demand, exposing supply-chain and partner-notification risks for US healthcare organizations.
- Industry analysis
Two separate threat actors targeted Novo Nordisk with $75 million in combined ransom demands
Danish pharmaceutical giant Novo Nordisk faced extortion demands from two unconnected threat actors — FulcrumSec and an unnamed group — totaling $75 million, with neither claim resulting in payment.
- Industry analysis
Two separate threat actors demanded $75 million combined from Novo Nordisk — and were refused
Novo Nordisk faced back-to-back extortion demands totaling $75 million from two unrelated threat actors, with neither paid, illustrating the compounding exposure large pharmaceutical targets now face.
- Industry analysis
Two threat actors hit Novo Nordisk with separate extortion demands totaling $75 million
Danish pharmaceutical giant Novo Nordisk faced back-to-back extortion attempts from unrelated threat actors, with demands of $50 million and $25 million respectively — neither of which was paid.
- Industry analysis
Two separate threat actors claimed Novo Nordisk breaches and demanded $75 million combined — neither was paid
Danish pharma giant Novo Nordisk faced extortion demands totaling $75 million from two unrelated threat actors in the same period, a convergence that illustrates escalating targeting of global pharmaceutical companies.
- Industry analysis
Chinese espionage group UNC6508 is actively targeting medical and AI research organizations in North America
Google's Threat Intelligence Group has been tracking cyberespionage group UNC6508 since early 2025, with medical research institutions among its confirmed targets across North America.
- Industry analysis
Chinese espionage group UNC6508 shifts focus to medical and AI research targets in North America
Google's Threat Intelligence Group has been tracking UNC6508 since early 2025, and the group's targeting of medical research organizations raises direct concerns for academic medical centers and research-affiliated practices.
- Industry analysis
Chinese espionage group UNC6508 shifts targeting to medical and AI research in North America
Google's Threat Intelligence Group has been tracking UNC6508 since early 2025 as the group pursues cyberespionage campaigns against medical, military, and AI research targets across North America.
- Industry analysis
Chinese espionage group UNC6508 sets sights on North American medical research
Google's Threat Intelligence Group has been tracking UNC6508 since early 2025, linking the Chinese cyberespionage operation to intrusions against medical, military, and AI research targets across North America.
- Industry analysis
Chinese cyberespionage group UNC6508 seen targeting medical research organizations in North America
Google's Threat Intelligence Group has been tracking UNC6508 since early 2025 as the group conducts cyberespionage campaigns against medical, military, and AI research targets across North America.
- Industry analysis
Chinese espionage group UNC6508 targets medical and AI research across North America
Google's Threat Intelligence Group has been tracking cyberespionage cluster UNC6508 since early 2025, with medical research institutions among the confirmed targets in North America.
- Industry analysis
HTTP/2 protocol flaws expose healthcare networks to amplified denial-of-service attacks
Researchers have identified denial-of-service exploits in two HTTP/2 protocol features that attackers can weaponize to overwhelm healthcare network infrastructure with minimal effort.
- Industry analysis
HTTP/2 protocol features weaponized in amplification attacks against healthcare networks
A denial-of-service technique exploiting two bandwidth-saving features in HTTP/2 is exposing healthcare organizations and telecoms to outsized traffic amplification attacks.
- Industry analysis
HTTP/2 protocol flaws enable amplified denial-of-service attacks on healthcare targets
Researchers have identified denial-of-service exploits that weaponize two bandwidth-saving features in HTTP/2, putting hospital networks and health system web infrastructure at elevated risk.
- Industry analysis
HTTP/2 amplification flaw puts healthcare networks in denial-of-service crosshairs
A denial-of-service technique exploiting two HTTP/2 bandwidth-saving features can produce outsized attack amplification, with telecom and healthcare organizations identified as high-exposure targets.
- Industry analysis
HTTP/2 protocol flaws enable amplification attacks against healthcare networks
Researchers have identified a denial-of-service technique that exploits two bandwidth-saving features in HTTP/2, putting healthcare organizations and their patient-facing systems at elevated risk.
- Industry analysis
HTTP/2 protocol features weaponized in amplification attacks against healthcare networks
A denial-of-service technique exploiting two bandwidth-saving features of the HTTP/2 protocol is putting healthcare organizations and telecommunications providers at elevated risk of service disruption.
- Industry analysis
HTTP/2 protocol flaws enable amplified denial-of-service attacks against healthcare networks
Researchers have identified a denial-of-service exploit that turns two HTTP/2 bandwidth-saving features against healthcare organizations and telecoms, enabling outsized disruption with minimal attacker effort.
- Industry analysis
Novo Nordisk discloses breach affecting clinical trial patient data
Novo Nordisk confirmed a security incident exposing data tied to clinical trial participants, adding to a pattern of biopharma breaches that put sensitive research and patient records at risk.
- Industry analysis
Ukrainian national pleads guilty to conspiracy charges in Conti ransomware operation
A 44-year-old Ukrainian national extradited from Ireland admitted to conspiracy charges tied to Conti ransomware attacks, a group responsible for dozens of strikes on US healthcare targets.
- Industry analysis
Chelan County malware incident stretches past three weeks with no restoration date
A malware incident discovered over Memorial Day weekend has left Chelan County, Washington with system-wide disruptions entering a third week and no announced timeline for recovery.
- Industry analysis
Ambient AI reshapes clinical documentation at Beth Israel Lahey Health
Beth Israel Lahey Health's adoption of ambient AI in exam rooms illustrates how health systems are offloading real-time documentation burden from physicians, with implications for workflow, consent, and data governance.
- Industry analysis
Ambient AI tools reshape clinical documentation inside the exam room
Beth Israel Lahey Health's deployment of ambient AI scribing illustrates how health systems are trading screen-focused workflows for real-time transcription that follows the clinical encounter.
- Industry analysis
Ambient AI begins displacing screen-focused documentation in clinical visits
Beth Israel Lahey Health's adoption of ambient AI scribing illustrates a broader shift in how health systems are attempting to reduce documentation load without sacrificing clinical accuracy.
- Industry analysis
Microsoft and Mayo Clinic move to build a frontier AI model for clinical use
Microsoft and Mayo Clinic announced a partnership to develop a healthcare-specific frontier AI model, a collaboration that signals accelerating institutional investment in purpose-built clinical AI.
- Industry analysis
Microsoft and Mayo Clinic team up to build a frontier AI model for clinical use
Microsoft and Mayo Clinic announced a partnership to develop a frontier AI model designed specifically for healthcare, a move that signals growing investment in purpose-built clinical AI at scale.
- Industry analysis
AI forecasting tools reshape how community oncology clinics manage drug costs and inventory
Community oncology practices are applying AI-driven demand forecasting to specialty drug purchasing, aiming to close visibility gaps that have widened as reimbursement margins narrow and drug costs rise.
- Industry analysis
Most organizations missing 24-hour patch window report breaches, CSA study finds
A Cloud Security Alliance study released June 2 found 80% of organizations that miss a 24-hour patch window report security incidents tied to known vulnerabilities, with an AI visibility gap compounding the risk.
- Industry analysis
Most organizations missing 24-hour patch window report breaches, CSA finds
A Cloud Security Alliance study released June 2 found 80% of organizations that miss a 24-hour patching window experience security incidents tied to known vulnerabilities, with AI runtime blind spots compounding the risk.
- Industry analysis
Most organizations missing 24-hour patch window report breaches, CSA study finds
A Cloud Security Alliance study released June 2 found that 80% of organizations that miss a 24-hour patch window report incidents tied to known vulnerabilities, with AI runtime visibility gaps compounding the risk.
- Industry analysis
Study links missed 24-hour patch windows to breach rates across industries
A Cloud Security Alliance report published June 2 found that 80% of organizations failing to patch within 24 hours reported security incidents tied to known vulnerabilities.
- Industry analysis
Most organizations missing 24-hour patch window report breaches, CSA finds
A Cloud Security Alliance study released June 2 found that 80% of organizations that fail to patch within 24 hours report security incidents tied to known vulnerabilities, with AI runtime visibility gaps compounding the risk.
- Industry analysis
Eighty percent of organizations missing 24-hour patch window report breaches, CSA finds
A Cloud Security Alliance study released June 2 found that delayed patching of known vulnerabilities drives the majority of security incidents, with AI runtime blind spots compounding the exposure.
- Industry analysis
CSA study links missed patch windows to breach rates in known-vulnerability incidents
A Cloud Security Alliance report published June 2 found that 80% of organizations failing to patch within 24 hours reported security incidents tied to known vulnerabilities, raising direct questions for healthcare compliance programs.
- Industry analysis
CSA study ties missed 24-hour patch windows to breach rates at most organizations
A Cloud Security Alliance study published June 2 found that 80% of organizations failing to patch known vulnerabilities within 24 hours reported security incidents, with AI-environment visibility gaps compounding the risk.
- Industry analysis
CSA study ties missed 24-hour patch windows to breach rates across sectors
A Cloud Security Alliance report published June 2 found 80% of organizations that miss a 24-hour patching window experience security incidents tied to known vulnerabilities, a finding with direct implications for healthcare IT teams.
- Industry analysis
Most organizations missing 24-hour patch windows report security incidents, CSA finds
A Cloud Security Alliance study released June 2 found that 80% of organizations failing to patch within 24 hours experienced incidents tied to known vulnerabilities, with AI runtime visibility gaps compounding the risk.
- Industry analysis
Epic embeds Northwell's firearm injury risk screening tool in its EHR
Epic has integrated a firearm injury risk screening tool developed by Northwell Health, bringing structured clinical decision support for gun violence prevention into its widely used EHR platform.
- Industry analysis
Joint Commission launches voluntary AI responsibility certification for health systems
The Joint Commission's new Responsible Use of AI in Healthcare certification targets organizational deployment practices rather than individual AI tools, marking a formal accountability framework for the sector.
- Industry analysis
Eight in ten organizations that miss the 24-hour patch window report breaches, CSA finds
A Cloud Security Alliance study published June 2 found that 80% of organizations failing to patch known vulnerabilities within 24 hours experienced security incidents, with AI runtime blind spots compounding the risk.
- Industry analysis
EHR migration windows are the most underestimated security event in a practice's decade
South Central Regional Medical Center is consolidating five clinical sites onto a single Epic instance. The case is unremarkable individually and instructive collectively — EHR transitions are a security event the compliance program rarely treats as one.
- Cybersecurity
Phishing-as-a-service now includes an AI assistant, and healthcare email defenses have not caught up
A newly identified phishing kit called Bluekit ships with 40 templates, automated domain registration, and an AI campaign drafter. The economics of credential-theft attacks against small healthcare practices just shifted again.
- Litigation
Private equity liability for portfolio-company breaches just changed, and healthcare is the largest exposed sector
A California federal court allowed claims against Bain Capital to proceed for a breach at its subsidiary PowerSchool — including conduct that predated the acquisition. The ruling reshapes the risk calculus for the most heavily PE-backed sector in American healthcare.
- Enforcement
State financial regulators are becoming the second front of healthcare breach enforcement
NYSDFS extracted $2.25 million from Delta Dental over the 2023 MOVEit breach — the latest sign that state insurance and financial regulators are operating in parallel with HHS OCR, with their own rules and faster timelines.
- Cybersecurity
Why CFAA prosecutions of credentialed clinical staff are rising, and what it means for insider risk
A federal indictment of a Maryland pharmacist on Computer Fraud and Abuse Act charges follows a pattern — prosecutors are increasingly using the CFAA to reach insider misuse cases that HIPAA alone wouldn't.