Data Breaches Announced by Four Hospitals and Surgery Centers – The HIPAA Journal
Data Breaches Announced by Four Hospitals and Surgery Centers The HIPAA Journal
Data Breaches Announced by Four Hospitals and Surgery Centers The HIPAA Journal
Data breaches have been reported by Wildwood Surgical Center, Michigan Surgical Center, Penobscot Valley Hospital, and Whitfield Regional Hospital. Wildwood […] The post Data Breaches Announced by Four Hospitals and Surgery Centers appeared first on The HIPAA Journal.
Cybersecurity researchers have flagged fresh malicious cyber activity by a threat actor with ties to East Asia targeting government entities in the Middle East. The intrusions have resulted in the deployment of previously unreported malware families dubbed TELESHIM, MIXEDKEY, an…
GitHub has announced a new cooldown mechanism in Dependabot, allowing the tool to wait at least three days after a release is published before opening a pull request. "The cooldown configuration option in the dependabot.yml still controls the behavior, though, so you can choose …
OpenAI connected 300 million weekly health queries to real medical records and the implications are enormous Startup Fortune
Vantage IO Warns Unchecked AI Code Threatens HIPAA Compliance; Launches ClearMap The AI Journal
NOW on-demand, Value-Based Care Insights host Daniel J. Marino speaks with Dr. Angel Martino-Horrall, anesthesiologist, consultant, and perioperative operations expert, to discuss the evolving role of anesthesia leadership in surgical services governance. The post Unlocking Perio…
GitHub and PyPI (Python Package Index) have introduced a time-based mechanism in the Dependabot dependency management tool to protect against supply-chain attacks and to limit their impact. [...]
By Megan Schmidt - Healthcare is spending billions to modernize the future while ignoring one of its most expensive operational failures. Provider data, the foundational information that determines who gets paid, where patients receive care, and how networks function, remains ina…
Steam discussion forums are being abused in ClickFix attacks that pretend to be fixes for game and computer problems but actually infect devices with cryptominers. [...]
A malvertising operation dubbed SourTrade is making victims' browsers build the final Windows executable themselves, using a legitimate Bun runtime as its base instead of serving one complete malicious file from a fixed URL. Confiant, which detailed the campaign on July 23, 2026…
How UTHealth Houston built HIPAA-compliant generative AI at scale: iDFax’s 2-year journey with Amazon Bedrock Amazon Web Services (AWS)
A massive malvertising campaign is using fake Solana, Luno, and TradingView webpages with malicious JavaScript that instructs browsers to assemble malware directly in memory. [...]
Threat actors are using email addresses exposed in data breaches leaked by the ShinyHunters extortion group to send sextortion emails demanding $2,000 in Bitcoin. [...]
OpenAI launched ChatGPT Health and quietly moved your medical records outside HIPAA Startup Fortune
We have rounded up some reports and surveys from around the industry that we thought were of interest from Fortified Health Security, Surescripts, PerfectServe, BioLongevity Supplements, Royal Philips, Sage Growth Partners, Atlas Systems, Experian Health, mPulse, Nurse.com, and m…
Security firms ThreatBook and Imperva say attackers are targeting a critical flaw in Fastjson, Alibaba's JSON library for Java. In affected Spring Boot applications, a malicious JSON request can execute code without authentication, with the privileges of the Java process. Tracke…
For years, phishing campaigns targeting financial institutions followed the same playbook. Victims were tricked into entering usernames and passwords, attackers collected the credentials, and accounts were compromised later when an opportunity arose. That model is changing. Rec…
Threat actors linked to the Cl0p (aka Chubby Scorpius, FIN11, Graceful Spider, and Lace Tempest) ransomware campaign are exploiting flaws in internet-exposed PTC Windmill and FlexPLM deployments as part of a new data extortion campaign. "Attackers chain a pre-authentication info…
The operators of the DevMan ransomware-as-a-service (RaaS) scheme are maintaining a dedicated web platform that offers affiliates the ability to build payloads, oversee earnings, and manage various aspects related to victims. Swiss cybersecurity company PRODAFT is tracking the c…