PrivacySignal

Search & browse the archive

The full corpus — beyond today's front page.

Reset

80 results · page 1 of 4

Breach
HIPAA Journal · · US Federal

Healthcare Orgs Warned About Gunra Ransomware Attacks

CISA, the FBI, and international partners have issued a joint advisory warning healthcare organizations about Gunra, a ransomware-as-a-service operation actively targeting the sector.

Who should care: Cybersecurity · Privacy officers · Administrators · Healthcare professionals · Compliance

#breach#healthcare#security Read original →
News
The Guardian — Tech · · International

What happens when medical students rely on AI – and never develop their own judgment? | Simar Bajaj and Joseph Sakran

AI’s danger isn’t just in experts losing the ability to reason. It’s that trainees may never learn how to do so in the first place In healthcare, there’s growing concern over doctors becoming less clinically adept as they increasingly rely on AI tools. But what about the trainees – medical students, residents and fellows – who are using these tools before they’ve built their own clinical judgment? The idea of deskilling implies that someone possessed an ability and then lost it. Here, the danger is not just deskilling but never-skilling. Although a doctor who has forgotten how to reason is re…

Who should care: General readers · AI governance · Policy

Breach
BleepingComputer · · International

Unlimited Technology Systems breach impacts 3.8 million people

Healthcare software company Unlimited Technology Systems disclosed a data breach from October 2025 that affected more than 3.8 million people. The company has reported the incident, though details about the type of data exposed have not been specified in available reporting.

Who should care: Cybersecurity · Privacy officers · Administrators

Healthcare
HIPAA Journal · · US Federal

Five Healthcare Providers Settle Pixel Class Action Lawsuits

Five healthcare providers have reached settlements in class action lawsuits tied to their use of website tracking pixels, part of a broader wave of similar legal actions against the healthcare sector over the past 18 months.

Who should care: Healthcare professionals · Privacy officers · Compliance · Cybersecurity

#healthcare#surveillance Read original →
Breach
DataBreaches.net · · International

Unlimited Technology Systems Data Breach Affects 3.8 Million Patients

Unlimited Technology Systems, an Ohio-based revenue cycle management company serving healthcare providers, suffered a data breach in October 2025 that exposed information belonging to approximately 3.8 million patients. The breach was discovered days after it occurred and publicly reported months later.

Who should care: Cybersecurity · Privacy officers · Administrators · Healthcare professionals · Compliance

#breach#healthcare Read original →
Breach
DataBreaches.net · · International

Cardiology Associates of Port Huron remains silent although they were allegedly hacked and had patient data stolen in June.

Cardiology Associates of Port Huron has not publicly responded to claims by a threat group called Orova that it hacked the medical practice and stole patient data in June. The group, one of roughly four dozen new actors targeting U.S. healthcare in early 2026, listed the cardiology practice on a dark web leak site.

Who should care: Cybersecurity · Privacy officers · Administrators · Healthcare professionals · Compliance

#breach#healthcare#security Read original →
Breach
HIPAA Journal · · US Federal

Settlements Resolve Data Breach Lawsuits Against McKenzie Health System & Aspire Health Alliance

Class action lawsuits stemming from data breaches at McKenzie Health System in Michigan and Aspire Health Alliance have reached settlement agreements. Both cases involved healthcare organizations whose patient data was compromised, prompting litigation that has now been resolved outside of court.

Who should care: Cybersecurity · Privacy officers · Administrators · Healthcare professionals · Compliance

#breach#healthcare Read original →
Breach
HIPAA Journal · · US Federal

Data Breach Lawsuits Settled by Omni Healthcare & Western Montana Clinic

Omni Healthcare Financial Holdings and Western Montana Clinic have each agreed to settle class action lawsuits stemming from separate data breaches. The settlements resolve claims brought by individuals whose personal or medical information was exposed.

Who should care: Cybersecurity · Privacy officers · Administrators · Healthcare professionals · Compliance

#breach#healthcare Read original →
Healthcare
HIPAA Journal · · US Federal

Is Your Organization Ready for a HIPAA Security Incident?

The HIPAA Journal is prompting healthcare organizations to evaluate their readiness for security incidents by conducting formal risk assessments that identify threats to protected health information and gauge the likelihood those threats materialize.

Who should care: Healthcare professionals · Privacy officers · Compliance · General readers · Policy

#healthcare#privacy Read original →
Breach
The Record · · International

Biotech giant Amgen says patient data stolen from third-party cloud systems

Amgen has disclosed to regulators that patient information and proprietary company data were accessed through a breach affecting third-party cloud systems the company relied on. The incident adds to a growing pattern of healthcare and biotech firms suffering data losses through vendors rather than their own internal infrastructure.

Who should care: Cybersecurity · Privacy officers · Administrators · Healthcare professionals · Compliance · Lawyers

#breach#healthcare#regulation Read original →
Healthcare
HIPAA Journal · · US Federal

CareCloud Notifies More Than 345,000 Patients About Cyberattack Data Theft

CareCloud, a New Jersey-based health technology company that provides electronic health records and related clinical services, has notified more than 345,000 patients that their data was stolen in a cyberattack. The company offers cloud-based and AI-assisted tools used by healthcare providers across the country.

Who should care: Healthcare professionals · Privacy officers · Compliance · General readers · AI governance · Policy

#healthcare#ai Read original →
Breach
DataBreaches.net · · International

The double extortion of a Russian ransomware threatens the medical records that Diater has kept for 10 years.

Spanish biopharmaceutical firm Diater has appeared on the dark web victim list published by the ransomware group DeadLock, which is using a double extortion strategy — encrypting data and threatening to publish it. The breach reportedly affects up to a decade of sensitive medical records belonging to patients and healthcare professionals.

Who should care: Cybersecurity · Privacy officers · Administrators · Healthcare professionals · Compliance

#breach#healthcare#security Read original →
Breach
DataBreaches.net · · International

CareCloud Data Breach Impacts Over 350,000

Healthcare IT company CareCloud is notifying more than 350,000 people that their data was stolen after hackers accessed its AWS environment in March 2026, disrupting an electronic health record system within its CareCloud Health division. The company's investigation confirmed unauthorized access to patient and possibly provider information stored in that cloud environment.

Who should care: Cybersecurity · Privacy officers · Administrators · Lawyers · Compliance · Healthcare professionals

#breach#enforcement#healthcare Read original →
Healthcare
HIPAA Journal · · US Federal

Health-ISAC Warns of Increasing ShinyHunters Healthcare Data Theft Attacks

Health-ISAC has issued a warning to healthcare organizations about a rise in successful data theft attacks attributed to the ShinyHunters threat group. The advisory signals that the group is actively targeting the health sector and making meaningful progress against its defenses.

Who should care: Healthcare professionals · Privacy officers · Compliance

#healthcare Read original →
Enforcement
W WSB-TV · · International

Wellstar to settle lawsuit over data privacy, will pay $4.25 million if judge approves plan

Wellstar Health System has agreed to a $4.25 million settlement to resolve a data privacy lawsuit, pending judicial approval. The agreement would compensate individuals affected by the underlying privacy dispute involving the Georgia-based healthcare network.

Who should care: Lawyers · Privacy officers · Compliance · General readers · Policy

#enforcement#privacy Read original →
Enforcement
HIPAA Journal · · US Federal

OSF Healthcare System Pays $552,250 to Settle OCR HIPAA Investigation

OSF Healthcare System has agreed to pay $552,250 to settle a HIPAA investigation by the HHS Office for Civil Rights. The settlement resolves findings related to OSF Healthcare and its affiliated covered entities, though the specific violations were not detailed in the available excerpt.

Who should care: Lawyers · Privacy officers · Compliance · Healthcare professionals

#enforcement#healthcare Read original →
Breach
DataBreaches.net · · International

HHS OCR Settles Ransomware Investigation of OSF Healthcare System and Affiliated Covered Entities

The HHS Office for Civil Rights has reached a settlement with OSF Healthcare and affiliated entities following a ransomware attack carried out in 2021 by a threat group called Xing Team. The investigation examined OSF's handling of the incident, including concerns about its notification timeline and response to affected individuals.

Who should care: Cybersecurity · Privacy officers · Administrators · Lawyers · Compliance · Healthcare professionals

#breach#enforcement#healthcare#security Read original →
Enforcement
F Fierce Healthcare · · International

FTC sues Hims & Hers over data privacy, billing practices

The Federal Trade Commission has filed a lawsuit against telehealth company Hims & Hers, targeting the company's data privacy practices and billing conduct. The action signals continued federal scrutiny of how digital health platforms handle sensitive consumer information and subscription-style charges.

Who should care: Lawyers · Privacy officers · Compliance · General readers · Policy

#enforcement#privacy Read original →
Breach
HIPAA Journal · · US Federal

Former CPA Sentenced for Laundering Stolen Children’s Healthcare of Atlanta Funds

A former CPA has been sentenced for laundering $5.3 million stolen from Children's Healthcare of Atlanta through a 2023 business email compromise attack targeting one of the hospital system's vendors. The fraud exploited payment processes between the healthcare organization and its supply chain.

Who should care: Cybersecurity · Privacy officers · Administrators · Healthcare professionals · Compliance

#breach#healthcare Read original →
Healthcare
HIPAA Journal · · US Federal

Banner Health; LifeStance Health Group Settle Tracking Technology Lawsuits

Banner Health and LifeStance Health Group have each agreed to settle lawsuits stemming from their use of tracking pixels and similar technologies on their websites. The tools allegedly collected and shared patient data with third parties without proper authorization under HIPAA.

Who should care: Healthcare professionals · Privacy officers · Compliance · Cybersecurity

#healthcare#surveillance Read original →
Breach
HIPAA Journal · · US Federal

Soniva Dental Care Data Breach Affects At Least 30,000 Patients

Soniva Dental Care in Texas has disclosed a data breach affecting at least 30,000 patients, part of a wave of healthcare-sector incidents also involving Optalis Management Solutions in Michigan and CareCloud in New Jersey. The breaches were reported in The HIPAA Journal, which covers health data security and compliance.

Who should care: Cybersecurity · Privacy officers · Administrators · Healthcare professionals · Compliance

#breach#healthcare Read original →
Breach
BleepingComputer · · International

Data breach at medical billing firm MCBS affects 1.26 million people

Medical Computer Business Services (MCBS), a healthcare billing company, has disclosed a 2025 network breach that exposed sensitive information belonging to more than 1.26 million people. The company has not yet detailed what specific data was compromised or how long attackers had access.

Who should care: Cybersecurity · Privacy officers · Administrators

AI Governance
H healthcareittoday.com · · International

The Hidden Risk of Rushed Technology: Patrick Lo on Establishing AI Governance

Patrick Lo is calling attention to the risks that come when AI is deployed in healthcare before governance structures are in place to manage it. His argument centers on the idea that speed of adoption and accountability frameworks are not keeping pace with each other.

Who should care: AI governance · Lawyers · Administrators · General readers · Policy

#ai-governance#ai Read original →
Page 1 of 4 Next →