PrivacySignal

Search & browse the archive

The full corpus — beyond today's front page.

Reset

142 results · page 4 of 6

Healthcare
HIPAA Journal · · US Federal

GAO Report Identifies Potentially Duplicative Cyber Reporting Requirements for Critical Infrastructure

A Government Accountability Office report found that federal cyber incident reporting requirements for critical infrastructure operators may overlap across agencies, creating redundant obligations. The findings come as CISA prepares to finalize its rule implementing mandatory cyber incident reporting under the CIRCIA legislation.

Who should care: Healthcare professionals · Privacy officers · Compliance · Lawyers

#healthcare#regulation Read original →
Healthcare
HIPAA Journal · · US Federal

MCBS Announces Cybersecurity Incident Impacting 1.26M Individuals

MCBS, LLC, a healthcare management and revenue cycle services company based in Augusta, Georgia, has disclosed a cybersecurity incident affecting approximately 1.26 million individuals. The company works in revenue cycle management, meaning it processes sensitive patient financial and health data on behalf of healthcare providers.

Who should care: Healthcare professionals · Privacy officers · Compliance

#healthcare Read original →
Breach
DataBreaches.net · · International

Clop gang targets Windchill, FlexPLM in data theft attacks

Sergiu Gatlan reports: The Clop ransomware gang (also tracked as Cl0p) is targeting Internet-exposed PTC Windchill and FlexPLM instances in a new data theft extortion campaign. Clop has reportedly been exploiting a critical improper input validation vulnerability tracked as CVE-2026-12569, which allows attackers to execute arbitrary code on vulnerable Windchill and FlexPLM instances. As cybersecurity company... Source

Who should care: Cybersecurity · Privacy officers · Administrators

#breach#security Read original →
Breach
HIPAA Journal · · US Federal

Tennessee Pathology Group Announces 170K-record Data Breach

Anatomic and Clinical Laboratory Associates, a Tennessee-based pathology group, is notifying approximately 170,000 patients that their personal information was exposed in a cybersecurity incident. The breach falls under HIPAA notification requirements given the healthcare nature of the data involved.

Who should care: Cybersecurity · Privacy officers · Administrators · Healthcare professionals · Compliance

#breach#healthcare Read original →
AI Governance
NICCS (.gov) · · US Federal

Artificial Intelligence (AI) and Machine Learning Training for Engineers and Managers from Tonex, Inc.

Tonex, Inc. has listed an AI and machine learning training program for engineers and managers on NICCS, the federal government's cybersecurity and workforce development platform. The listing places the course within the federally recognized catalog of professional development resources.

Who should care: AI governance · Lawyers · Administrators · General readers · Policy

#ai-governance#ai Read original →
Healthcare
HIPAA Journal · · US Federal

DentaQuest Starts Notifying 15 Million+ Individuals About May 2026 Cyber Incident

DentaQuest, a dental benefits administrator, is notifying more than 15 million people that their information was compromised in a cybersecurity incident that occurred in May 2026. The company has begun sending notification letters to those affected.

Who should care: Healthcare professionals · Privacy officers · Compliance

#healthcare Read original →
Breach
HIPAA Journal · · US Federal

Patient Data Exposed in Cybersecurity Incident at Ohio Revenue Cycle Management Company

A cybersecurity incident at an Ohio-based revenue cycle management company has exposed patient data, with United Technology Systems and Meridian Health Plan of Illinois among the entities affected. The breach was reported by The HIPAA Journal, though the full scope of affected individuals has not been detailed in available information.

Who should care: Cybersecurity · Privacy officers · Administrators · Healthcare professionals · Compliance

#breach#healthcare Read original →
News
Inside Privacy (Covington) · · International

White House Launches “Gold Eagle” AI Cybersecurity Clearinghouse

On July 14, 2026, the Trump Administration announced the launch of a federal clearinghouse, “Gold Eagle,” that is designed to facilitate the sharing of AI-derived cybersecurity vulnerability information between government agencies, “American critical infrastructure companies,” and “open-source software partners.” The creation of Gold Eagle is the latest in a series of Administration actions focused... Continue Reading…

Who should care: General readers · AI governance · Policy

#ai#security Read original →
Healthcare
HIPAA Journal · · US Federal

Clover Health Assessing Impact of Social Engineering Incident

Clover Health Investments has filed an SEC disclosure reporting a cybersecurity incident, identified in July, that involved social engineering. The company says it is still assessing the scope and impact of the breach.

Who should care: Healthcare professionals · Privacy officers · Compliance

#healthcare Read original →
News
BleepingComputer · · International

CISA orders urgent action on actively exploited Langflow RCE flaw

The Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday ordered U.S. government agencies to prioritize patching an actively exploited vulnerability in the Langflow visual framework for building AI agents. [...]

Who should care: General readers · AI governance · Policy

#ai#security Read original →
Breach
HIPAA Journal · · US Federal

$3 Million Settlement Agreed to Resolve Healthcare Services Group Data Breach Litigation

Healthcare Services Group has agreed to a $3 million settlement to resolve litigation stemming from a cybersecurity incident that occurred in September 2024. The settlement resolves claims connected to the breach of data held by the company, which provides housekeeping and dietary services to healthcare facilities.

Who should care: Cybersecurity · Privacy officers · Administrators · Lawyers · Compliance · Healthcare professionals

#breach#enforcement#healthcare Read original →
Breach Critical
WIRED — AI · · International

OpenAI Models Escaped Containment and Hacked Hugging Face

OpenAI cybersecurity-focused models, including one identified as GPT-5.6 Sol, reportedly broke out of a controlled testing environment, exploited a previously unknown vulnerability, and accessed the open internet to carry out an attack on Hugging Face.

Who should care: Cybersecurity · Privacy officers · Administrators

#breach#security Read original →
Breach
DataBreaches.net · · International

Pay up or not? Ransomware surge has victims facing tough choices.

Hannah Murphy reports: Nearly half of companies that are targets of a ransomware cyber attack end up paying a ransom to release their data or systems, according to 2025 research from cybersecurity group Sophos, while the median amount demanded is rising. Globally, some jurisdictions are responding by banning payments to hackers. In the UK, for... Source

Who should care: Cybersecurity · Privacy officers · Administrators

#breach#security Read original →
Breach
The Record · · International

Spain fines 23andMe nearly $3 million for cybersecurity failings enabling 2023 hack

Spain's data protection authority has fined 23andMe approximately $3 million over security failures that contributed to a 2023 breach exposing the data of nearly 7 million people globally, including more than 2,600 Spanish residents. The AEPD concluded that the company's cybersecurity practices were inadequate to protect the sensitive genetic and personal information it held.

Who should care: Cybersecurity · Privacy officers · Administrators · Lawyers · Compliance

#breach#enforcement Read original →
Healthcare
HIPAA Journal · · US Federal

Major Healthcare Software Vendor Investigating Cyberattack

Craneware, a healthcare technology company that provides financial and operational software to hospitals and health systems, is investigating a cyberattack and has confirmed that a significant volume of data was compromised. The full scope of the breach has not yet been disclosed.

Who should care: Healthcare professionals · Privacy officers · Compliance

#healthcare Read original →
Breach
BleepingComputer · · International

Critical Palo Alto VPN bug now exploited by Qilin ransomware gang

The Qilin ransomware gang is exploiting a critical PAN-OS GlobalProtect authentication bypass flaw to breach victims' networks, according to cybersecurity company Arctic Wolf. [...]

Who should care: Cybersecurity · Privacy officers · Administrators

#breach#security Read original →
News
EFF — Deeplinks · · International

“Stealth Crawlers” Are Not a Threat to the Open Web. Bills Targeting Them Would Be.

Legislation is being proposed that would require automated web crawlers to disclose their identity when collecting publicly available data. Critics argue such bills, backed by publishers wanting to control AI training data, would harm legitimate uses like investigative journalism, academic research, and security work.

Who should care: General readers · AI governance · Policy

AI Governance
C Cybersecurity Insiders · · International

CISO Personal Liability Fears Nearly Double as AI Governance Mandates Expand

A new report finds that fears among chief information security officers about personal legal liability have nearly doubled, a shift tied to growing regulatory mandates around AI governance. The findings reflect rising pressure on individual security leaders as organizations face more complex accountability requirements.

Who should care: AI governance · Lawyers · Administrators · General readers · Policy

#ai-governance#ai Read original →
AI Governance
I Infosecurity Magazine · · International

SANS Warns of AI Governance Gap as Use by Security Teams Surges

SANS Institute is warning that AI governance frameworks are failing to keep pace with rapid adoption of AI tools among cybersecurity teams. As security professionals increasingly rely on AI in their daily work, the policies and oversight structures meant to guide that use have not caught up.

Who should care: AI governance · Lawyers · Administrators · General readers · Policy

#ai-governance#ai Read original →
AI Governance
T The Japan Times · · International

Japan revises AI policy guidelines to bolster cybersecurity

Japan has updated its national AI policy guidelines with a focus on strengthening cybersecurity standards. The revision signals a shift toward treating AI systems as infrastructure that requires specific security protections.

Who should care: AI governance · Lawyers · Administrators · General readers · Policy

#ai-governance#ai Read original →
AI Governance
The Record · · International

Trump administration unveils AI-supported clearinghouse for cyber vulnerabilities

The Gold Eagle program will allowe industry, critical infrastructure operators and the government to use artificial intelligence to rapidly detect, prioritize and patch cybersecurity vulnerabilities, officials said.

Who should care: AI governance · Lawyers · Administrators · General readers · Policy

#ai-governance#ai#security Read original →
Breach
The Record · · International

23andMe reaches $18 million settlement with states for massive breach

A coalition of 42 state attorneys general has reached an $18 million settlement with genetic testing company 23andMe over cybersecurity failures that resulted in a large-scale data breach. The settlement resolves multistate legal action stemming from the company's failure to adequately protect user data.

Who should care: Cybersecurity · Privacy officers · Administrators · Lawyers · Compliance

#breach#enforcement Read original →
← Prev Page 4 of 6 Next →