Survey Reveals Patients Want to Know When and How AI is Used in Healthcare

A recent survey has revealed that patients are concerned about the use of AI tools by doctors’ offices and other healthcare providers, and the vast majority of patients believe that they should be informed if their healthcare provider is using AI tools in connection with their healthcare. The survey also indicates that more than half of patients are unaware whether AI is currently being used in relation to their healthcare.

The survey was conducted on almost 5,000 U.S. adults in late June 2026 by the Pew Research Center. The survey revealed that 72% of patients believe it is extremely important or very important for their healthcare providers to disclose whether they are using AI tools in connection with healthcare, with 16% of respondents believing that it is somewhat important. Only 7% of respondents said they are not too bothered or not at all bothered about being informed about the use of AI.

Concern varied across different uses of AI, with the greatest concern expressed about AI being used to make diagnostic decisions (81%), analyze medical scans (81%), explain medical test results (80%), and take notes during a medical appointment (72%).  More than half of patients believe that they should be informed about behind-the-scenes administrative services such as getting prescription refills (64%) and scheduling medical appointments (56%), although the latter had the largest percentage of patients who do not feel that disclosure is needed (33%). Across all areas of questioning, 9% or 10% of patients were not sure if they should be informed, potentially indicating they are unaware of any risks involved.

While most patients believe that they should be informed about the use of AI in healthcare, almost half of all surveyed patients (46%) said they were unaware whether their doctor’s office and other healthcare providers were using AI solutions, with only 16% of patients saying a doctor has actually told them that AI was used in their care. Adoption of AI in healthcare has grown considerably, with ONC’s figures showing that 71% of hospitals were using AI tools in 2024, up from 66% in 2023. Despite the high level of AI adoption, 33% of respondents believe their healthcare providers are not using AI tools, which suggests a lack of transparency.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

While patients want to be informed and have a say in how AI is used in healthcare, many Americans do not believe they have control over how AI is used. The survey revealed that more than half of respondents (53%) believe they either have no say or not much say in the use of AI in healthcare, with 16% believing they have some say. 63% of respondents to the survey would like more say in how AI is used, and only 21% of respondents said they are comfortable with how much say they currently have.

As AI adoption grows, it is important for healthcare providers to explain to patients how the tools are used and to obtain patient consent in order to maintain trust. It is also important for the tools, including transcription tools and chatbots, to be continuously evaluated to ensure they are fit for purpose and are generating accurate results.

The post Survey Reveals Patients Want to Know When and How AI is Used in Healthcare appeared first on The HIPAA Journal.

SonicWall Warns of Actively Exploited Vulnerabilities in SMA1000 Appliances

Two remotely exploitable zero-day vulnerabilities in SonicWall SMA1000 appliances are being chained together to achieve remote code execution, according to a recent SonicWall security alert. SMA1000 appliances are used for secure remote access and VPN connections and, as such, are commonly exposed to the Internet.

One of the vulnerabilities, tracked as CVE-2026-83548, is a critical pre-authentication server-side request forgery issue in the Appliance Work Place interface that allows command injection. The vulnerability has been assigned a maximum CVSS v 3.1 severity score of 10. Successful exploitation allows a remote attacker to access sensitive functions and perform unauthorized actions.

The vulnerability is being chained with an exploit for a high-severity (CVSS v3.1: 7.8) OS command injection vulnerability – CVE-2026-83549 – in the Appliance Management Console. Attackers with admin privileges can exploit the vulnerability and execute OS commands. The vulnerability is due to improper neutralization of special elements used in an OS command.

The SonicWall PSIRT has investigated a case where the threat actor chained the two vulnerabilities in an attack on a customer. The Cybersecurity and Infrastructure Security Agency (CISA) has added both vulnerabilities to its Known Exploited Vulnerability (KEV) Catalog, and federal civilian Executive Branch agencies have been given until Saturday to upgrade to the latest hotfix.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

The vulnerabilities affect SMA1000 6210, 7210, and 8200v models, but not SSL-VPN running on SonicWall firewalls or SMA 100 Series products. The affected software versions are 12.4.3-03453 (platform-hotfix) and older versions, and 12.5.0-02835 (platform-hotfix) and older versions.

The extent to which the vulnerabilities are being exploited is unclear. The latest attack(s) come just two months after a different pair of vulnerabilities in SMA1000 appliances were exploited to install malware, enabling ransomware attacks. Since threat actors actively target vulnerabilities in remote access and VPN appliances, users of vulnerable devices are strongly advised to upgrade to the latest hotfix as soon as possible. Currently, there are approximately 400 SMA1000 devices worldwide that are exposed online, the majority of which are in the United States.

The post SonicWall Warns of Actively Exploited Vulnerabilities in SMA1000 Appliances appeared first on The HIPAA Journal.

Resource Center of Dallas Notifies 12,500 Patients About Cyber Incident

Data breaches have been announced by Resource Center of Dallas, Kern Psychiatric Health and Wellness Center, The Asthma Center, Integrative Emergency Services, and Psychiatry of Texas (PsychPlus).

Resource Center of Dallas

Resource Center of Dallas, Inc., a provider of health, wellness, and advocacy services to the LGBTQIA+ community in North Texas, is notifying 12,490 individuals about a data security incident earlier this year. Third-party cybersecurity professionals were engaged to investigate suspicious network activity and determined that certain systems within its computer network were accessed by an unauthorized third party between February 4, 2026, and February 12, 2026. The threat actor accessed or removed files that contained personal and/or protected health information.

The data review was completed on or around July 2, 2026, when it was confirmed that the impacted data included names, dates of birth, medical information, health insurance information, financial account information, and other identification information. For certain individuals, the exposed data included Social Security numbers. The Resource Center of Dallas said it takes the security of personal and health information very seriously and had taken many precautions to safeguard it and continually evaluates and modifies its practices to enhance privacy and security. Since the incident, privacy and security protocols and practices have been reviewed and additional safeguards implemented to reduce the risk of similar incidents in the future.

Kern Psychiatric Health and Wellness Center (Genesis Healthcare Management)

Kern Psychiatric Health and Wellness Center, a Bakersfield, California-based psychiatric and behavioral care provider, has recently notified the California Attorney General about a data breach involving its management company, Genesis Healthcare Management. Genesis Healthcare Management identified suspicious activity within its computer network on June 22, 2026. Third-party cybersecurity specialists were engaged to assist with the investigation and confirmed that its network had been accessed by an unauthorized third party.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

The compromised parts of the network contained the personal and protected health information of Kern Psychiatric Health and Wellness Center patients, including names, dates of birth, Social Security numbers, medical record numbers, driver’s license numbers, government-issued ID numbers, Medicare/Medicaid numbers, diagnoses, treatment information, lab results, patient account numbers, provider names and locations, and health insurance information.

Notification letters are being mailed to the affected individuals, and complimentary credit monitoring and identity theft protection services have been offered for 12 months. The incident is not yet shown on the HHS’ Office for Civil Rights breach portal, so it is unclear how many individuals have been affected.

Allergic Disease Associates (The Asthma Center)

Philadelphia-based Allergic Disease Associates, P.C., doing business as The Asthma Center, has started notifying certain patients about a data security incident identified in November 2025. An investigation was launched to determine the cause of anomalous network activity, which determined that its network had been accessed by an unauthorized third party between October 28, 2025, and November 17, 2025. During that time, files containing patient information may have been copied from its network.

A comprehensive review was initiated to determine the patients affected and data types involved, and that process was recently completed. The Asthma Center has confirmed that data compromised in the incident included names, dates of birth, health insurance member numbers, provider names, limited clinical information, diagnosis information, prescription information, and treatment information. The Asthma Center is reviewing its policies, procedures, and practices related to data privacy and security to prevent similar incidents in the future. The number of affected individuals has yet to be publicly disclosed.

Integrative Emergency Services

Integrative Emergency Services, LLC, a Dallas, Texas-based physician-led acute care and emergency medicine group, has notified 2,009 patients about a June 2026 security incident. Suspicious activity was identified within an employee’s email account on June 16, 2026, and the account was rapidly secured. The investigation revealed that the account had been accessed by an unauthorized third party for a period of four hours.

The account was reviewed, and on July 9, 2026, Integrative Emergency Services identified an email in the account that contained patient information, which may have been viewed by an unauthorized third party. The email contained patient names, medical record identifiers, and certain health information. No Social Security numbers, financial information, or patient addresses were involved. Integrative Emergency Services has increased its employee training to help employees recognize and avoid phishing attempts.

Psychiatry of Texas (PsychPlus)

Psychiatry of Texas, aka PsychPlus, a psychiatric medical practice based in Houston, Texas, has identified a breach of the protected health information of 4,565 patients. The incident was first identified on March 31, 2026. The network anomaly was investigated, with assistance provided by third-party cybersecurity experts. The investigation determined that its network was accessed by an unauthorized third party on March 31, 2026, and that files containing patient data may have been acquired on that date.

The exposed files were reviewed and found to contain names, dates of birth, Social Security numbers, diagnoses, treatment information, health insurance information, electronic identification/account numbers, usernames, email addresses, passwords, and parents’ premarital surnames. While no misuse of the exposed data has been identified, patients have been advised to remain vigilant against identity theft and fraud. As a precaution, individuals whose Social Security numbers were involved have been offered complimentary credit monitoring and identity theft protection services.

The post Resource Center of Dallas Notifies 12,500 Patients About Cyber Incident appeared first on The HIPAA Journal.