Survey Reveals Patients Want to Know When and How AI is Used in Healthcare
A recent survey has revealed that patients are concerned about the use of AI tools by doctors’ offices and other healthcare providers, and the vast majority of patients believe that they should be informed if their healthcare provider is using AI tools in connection with their healthcare. The survey also indicates that more than half of patients are unaware whether AI is currently being used in relation to their healthcare.
The survey was conducted on almost 5,000 U.S. adults in late June 2026 by the Pew Research Center. The survey revealed that 72% of patients believe it is extremely important or very important for their healthcare providers to disclose whether they are using AI tools in connection with healthcare, with 16% of respondents believing that it is somewhat important. Only 7% of respondents said they are not too bothered or not at all bothered about being informed about the use of AI.
Concern varied across different uses of AI, with the greatest concern expressed about AI being used to make diagnostic decisions (81%), analyze medical scans (81%), explain medical test results (80%), and take notes during a medical appointment (72%). More than half of patients believe that they should be informed about behind-the-scenes administrative services such as getting prescription refills (64%) and scheduling medical appointments (56%), although the latter had the largest percentage of patients who do not feel that disclosure is needed (33%). Across all areas of questioning, 9% or 10% of patients were not sure if they should be informed, potentially indicating they are unaware of any risks involved.
While most patients believe that they should be informed about the use of AI in healthcare, almost half of all surveyed patients (46%) said they were unaware whether their doctor’s office and other healthcare providers were using AI solutions, with only 16% of patients saying a doctor has actually told them that AI was used in their care. Adoption of AI in healthcare has grown considerably, with ONC’s figures showing that 71% of hospitals were using AI tools in 2024, up from 66% in 2023. Despite the high level of AI adoption, 33% of respondents believe their healthcare providers are not using AI tools, which suggests a lack of transparency.
Get The FREE
HIPAA Compliance Checklist
Immediate Delivery of Checklist Link To Your Email Address
Please Enter Correct Email Address
Your Privacy Respected
HIPAA Journal Privacy Policy
While patients want to be informed and have a say in how AI is used in healthcare, many Americans do not believe they have control over how AI is used. The survey revealed that more than half of respondents (53%) believe they either have no say or not much say in the use of AI in healthcare, with 16% believing they have some say. 63% of respondents to the survey would like more say in how AI is used, and only 21% of respondents said they are comfortable with how much say they currently have.
As AI adoption grows, it is important for healthcare providers to explain to patients how the tools are used and to obtain patient consent in order to maintain trust. It is also important for the tools, including transcription tools and chatbots, to be continuously evaluated to ensure they are fit for purpose and are generating accurate results.
The post Survey Reveals Patients Want to Know When and How AI is Used in Healthcare appeared first on The HIPAA Journal.
SonicWall Warns of Actively Exploited Vulnerabilities in SMA1000 Appliances – hipaajournal.com
SonicWall Warns of Actively Exploited Vulnerabilities in SMA1000 Appliances
Two remotely exploitable zero-day vulnerabilities in SonicWall SMA1000 appliances are being chained together to achieve remote code execution, according to a recent SonicWall security alert. SMA1000 appliances are used for secure remote access and VPN connections and, as such, are commonly exposed to the Internet.
One of the vulnerabilities, tracked as CVE-2026-83548, is a critical pre-authentication server-side request forgery issue in the Appliance Work Place interface that allows command injection. The vulnerability has been assigned a maximum CVSS v 3.1 severity score of 10. Successful exploitation allows a remote attacker to access sensitive functions and perform unauthorized actions.
The vulnerability is being chained with an exploit for a high-severity (CVSS v3.1: 7.8) OS command injection vulnerability – CVE-2026-83549 – in the Appliance Management Console. Attackers with admin privileges can exploit the vulnerability and execute OS commands. The vulnerability is due to improper neutralization of special elements used in an OS command.
The SonicWall PSIRT has investigated a case where the threat actor chained the two vulnerabilities in an attack on a customer. The Cybersecurity and Infrastructure Security Agency (CISA) has added both vulnerabilities to its Known Exploited Vulnerability (KEV) Catalog, and federal civilian Executive Branch agencies have been given until Saturday to upgrade to the latest hotfix.
Get The FREE
HIPAA Compliance Checklist
Immediate Delivery of Checklist Link To Your Email Address
Please Enter Correct Email Address
Your Privacy Respected
HIPAA Journal Privacy Policy
The vulnerabilities affect SMA1000 6210, 7210, and 8200v models, but not SSL-VPN running on SonicWall firewalls or SMA 100 Series products. The affected software versions are 12.4.3-03453 (platform-hotfix) and older versions, and 12.5.0-02835 (platform-hotfix) and older versions.
The extent to which the vulnerabilities are being exploited is unclear. The latest attack(s) come just two months after a different pair of vulnerabilities in SMA1000 appliances were exploited to install malware, enabling ransomware attacks. Since threat actors actively target vulnerabilities in remote access and VPN appliances, users of vulnerable devices are strongly advised to upgrade to the latest hotfix as soon as possible. Currently, there are approximately 400 SMA1000 devices worldwide that are exposed online, the majority of which are in the United States.
The post SonicWall Warns of Actively Exploited Vulnerabilities in SMA1000 Appliances appeared first on The HIPAA Journal.
Resource Center of Dallas Notifies 12,500 Patients About Cyber Incident – hipaajournal.com
Resource Center of Dallas Notifies 12,500 Patients About Cyber Incident
Data breaches have been announced by Resource Center of Dallas, Kern Psychiatric Health and Wellness Center, The Asthma Center, Integrative Emergency Services, and Psychiatry of Texas (PsychPlus).
Resource Center of Dallas
Resource Center of Dallas, Inc., a provider of health, wellness, and advocacy services to the LGBTQIA+ community in North Texas, is notifying 12,490 individuals about a data security incident earlier this year. Third-party cybersecurity professionals were engaged to investigate suspicious network activity and determined that certain systems within its computer network were accessed by an unauthorized third party between February 4, 2026, and February 12, 2026. The threat actor accessed or removed files that contained personal and/or protected health information.
The data review was completed on or around July 2, 2026, when it was confirmed that the impacted data included names, dates of birth, medical information, health insurance information, financial account information, and other identification information. For certain individuals, the exposed data included Social Security numbers. The Resource Center of Dallas said it takes the security of personal and health information very seriously and had taken many precautions to safeguard it and continually evaluates and modifies its practices to enhance privacy and security. Since the incident, privacy and security protocols and practices have been reviewed and additional safeguards implemented to reduce the risk of similar incidents in the future.
Kern Psychiatric Health and Wellness Center (Genesis Healthcare Management)
Kern Psychiatric Health and Wellness Center, a Bakersfield, California-based psychiatric and behavioral care provider, has recently notified the California Attorney General about a data breach involving its management company, Genesis Healthcare Management. Genesis Healthcare Management identified suspicious activity within its computer network on June 22, 2026. Third-party cybersecurity specialists were engaged to assist with the investigation and confirmed that its network had been accessed by an unauthorized third party.
Get The FREE
HIPAA Compliance Checklist
Immediate Delivery of Checklist Link To Your Email Address
Please Enter Correct Email Address
Your Privacy Respected
HIPAA Journal Privacy Policy
The compromised parts of the network contained the personal and protected health information of Kern Psychiatric Health and Wellness Center patients, including names, dates of birth, Social Security numbers, medical record numbers, driver’s license numbers, government-issued ID numbers, Medicare/Medicaid numbers, diagnoses, treatment information, lab results, patient account numbers, provider names and locations, and health insurance information.
Notification letters are being mailed to the affected individuals, and complimentary credit monitoring and identity theft protection services have been offered for 12 months. The incident is not yet shown on the HHS’ Office for Civil Rights breach portal, so it is unclear how many individuals have been affected.
Allergic Disease Associates (The Asthma Center)
Philadelphia-based Allergic Disease Associates, P.C., doing business as The Asthma Center, has started notifying certain patients about a data security incident identified in November 2025. An investigation was launched to determine the cause of anomalous network activity, which determined that its network had been accessed by an unauthorized third party between October 28, 2025, and November 17, 2025. During that time, files containing patient information may have been copied from its network.
A comprehensive review was initiated to determine the patients affected and data types involved, and that process was recently completed. The Asthma Center has confirmed that data compromised in the incident included names, dates of birth, health insurance member numbers, provider names, limited clinical information, diagnosis information, prescription information, and treatment information. The Asthma Center is reviewing its policies, procedures, and practices related to data privacy and security to prevent similar incidents in the future. The number of affected individuals has yet to be publicly disclosed.
Integrative Emergency Services
Integrative Emergency Services, LLC, a Dallas, Texas-based physician-led acute care and emergency medicine group, has notified 2,009 patients about a June 2026 security incident. Suspicious activity was identified within an employee’s email account on June 16, 2026, and the account was rapidly secured. The investigation revealed that the account had been accessed by an unauthorized third party for a period of four hours.
The account was reviewed, and on July 9, 2026, Integrative Emergency Services identified an email in the account that contained patient information, which may have been viewed by an unauthorized third party. The email contained patient names, medical record identifiers, and certain health information. No Social Security numbers, financial information, or patient addresses were involved. Integrative Emergency Services has increased its employee training to help employees recognize and avoid phishing attempts.
Psychiatry of Texas (PsychPlus)
Psychiatry of Texas, aka PsychPlus, a psychiatric medical practice based in Houston, Texas, has identified a breach of the protected health information of 4,565 patients. The incident was first identified on March 31, 2026. The network anomaly was investigated, with assistance provided by third-party cybersecurity experts. The investigation determined that its network was accessed by an unauthorized third party on March 31, 2026, and that files containing patient data may have been acquired on that date.
The exposed files were reviewed and found to contain names, dates of birth, Social Security numbers, diagnoses, treatment information, health insurance information, electronic identification/account numbers, usernames, email addresses, passwords, and parents’ premarital surnames. While no misuse of the exposed data has been identified, patients have been advised to remain vigilant against identity theft and fraud. As a precaution, individuals whose Social Security numbers were involved have been offered complimentary credit monitoring and identity theft protection services.
The post Resource Center of Dallas Notifies 12,500 Patients About Cyber Incident appeared first on The HIPAA Journal.
Midwest Spine and Brain Institute Impacted by Vendor Ransomware Attack – The HIPAA Journal
Midwest Spine and Brain Institute Impacted by Vendor Ransomware Attack
Data breaches have been announced by Midwest Spine and Brain Institute, Brookhaven ENT Allergy and Facial Surgery, Digestive Disease Center and Heart Vascular & Leg Center, Premier Medical Group of the Hudson Valley, Risk Program Administrators, and Telus Health (US).
Midwest Spine and Brain Institute (3C Care Systems)
Midwest Spine and Brain Institute (MSBI), an independent medical clinic serving patients in Minnesota and Wisconsin, has alerted patients about a historic data breach at one of its service providers, the healthcare IT company 3C Care Systems. According to the MSBI notification letters, MSBI recently learned that patient data was accessed and/or obtained from 3C Care Systems. 3C Care Systems is a managed service provider that specializes in workflow automation, cloud-hosted platforms, and data integration services for healthcare organizations. 3C Care Systems conducted its own investigation into the data breach, and MSBI conducted an independent internal investigation.
The MSBI investigation confirmed its larger network was not impacted, only data provided to 3C Care Systems. The investigation concluded on June 18, 2026, revealing that personally identifiable information and protected health information was potentially involved, including first and last names in combination with one or more of the following: date of birth, medical treatment, procedure, and/or diagnosis information, medical record number, medical provider information, medical prescription information, dates of service, and health insurance claim and/or policy information.
MSBI is mailing notification letters to the affected individuals and has offered complimentary identity monitoring and protection services to individuals whose Social Security numbers were involved. The incident is not yet shown on the HHS’ Office for Civil Rights breach portal, so it is unclear how many MSBI patients have been affected.
Get The FREE
HIPAA Compliance Checklist
Immediate Delivery of Checklist Link To Your Email Address
Please Enter Correct Email Address
Your Privacy Respected
HIPAA Journal Privacy Policy
No information was provided as to the nature of the data breach, but this appears to have been a ransomware attack by the now-disbanded RansomHub ransomware operation on or around November 21, 2024. RansomHub claimed it had exfiltrated 100 GB of data from 3C Care Systems, although no separate breach announcement appears to have been made by the IT company, and those claims remain unverified. It is unclear if clients other than MSBI had data compromised in the incident.
Brookhaven ENT Allergy and Facial Surgery
Brookhaven ENT Allergy and Facial Surgery in Brookhaven, Mississippi, has notified 30,403 individuals that some of their personal and protected health information was compromised in a recent cybersecurity incident. The incident involved a third-party electronic health record provider, CareCloud, which reported the data breach to the HHS’ Office for Civil Rights on behalf of certain clients. The CareCloud breach listing on the OCR data breach portal indicates that 3.75 million individuals were affected.
The incident occurred between March 10, 2026, and March 16, 2026, and the file review determined that names, addresses, dates of birth, Social Security numbers, driver’s license numbers/government ID numbers, financial account numbers, credit/debit card numbers, and medical and health insurance information had potentially been compromised. You can read more about the CareCloud data breach in this post. At the time of issuing notifications, no actual or attempted misuse of the impacted data had been identified.
Silver Summit Medical Corporation (Digestive Disease Center and Heart Vascular & Leg Center), California
Silver Summit Medical Corporation, doing business as the Digestive Disease Center and Heart Vascular & Leg Center, has notified certain patients about a cybersecurity incident at a third-party vendor that exposed some of their protected health information. The Bakersfield, California-based ambulatory surgical center learned about the incident on or around July 20, 2026. The investigation determined that an unauthorized third party accessed the unnamed vendor’s systems from November 27, 2025, to November 30, 2025, and exfiltrated files containing personal and protected health information.
The data review determined that the exfiltrated files contained names in combination with one or more of the following: dates of birth, Social Security numbers, driver’s license numbers, financial account information, payment card information, taxpayer identification numbers, passport numbers, and/or other government identifiers. Protected health information included diagnoses, treatment information, prescription information, and health insurance information. The affected individuals were notified on August 19, 2026, and complimentary credit monitoring and identity theft protection services have been made available. The incident is not yet shown on the HHS’ Office for Civil Rights breach portal, so the number of affected individuals is not yet known.
Premier Medical Group of the Hudson Valley, New York
Premier Medical Group of the Hudson Valley, a Poughkeepsie, New York-based multispecialty practice, has started notifying patients impacted by a cybersecurity incident this summer. The incident disrupted certain IT systems, and the forensic investigation determined that there was unauthorized access to files containing patient information on June 14, 2026. The substitute data breach notice on the practice’s website does not state when the incident was detected.
The review of the affected data determined on July 14, 2026, that the exposed files included patient names, contact information, dates of birth, health insurance information, provider names, patient identification numbers, dates of service, medications, and diagnostic and treatment information. Premier Medical Group said it will continue to evaluate and implement enhanced safeguards and security measures to protect its systems from unauthorized access and continue to provide security training to its workforce. The number of affected individuals has yet to be publicly disclosed.
Risk Program Administrators
Risk Program Administrators LLC (RPA), a California-based insurance program administration and management firm, has notified 8,309 individuals about the exposure of some of their personal and protected health information earlier this year. On or around June 16, 2026, RPA identified suspicious activity within an employee’s email account. The account was secured, and an investigation was launched, which confirmed that the account, and certain emails within that account, had been accessed by an unauthorized third party between May 27, 2025, and June 16, 2025.
The account was reviewed and found to contain information such as names, dates of birth, Social Security numbers, financial account information, health insurance information, and medical information, including treatment types, locations, costs, physician information, mental or physical condition, subscriber member numbers, and admission dates.
TELUS Health (US)
TELUS Health (US) LTD., a Canton, Massachusetts-based digital health and wellness provider part of the Canadian telecommunications company TELUS, has disclosed a data breach that involved unauthorized access to systems containing protected health information. Telus Health’s announcement on its website states that the investigation is ongoing, and it has yet to publicly disclose the types of information compromised in the incident. It is unclear exactly when the attack occurred; however, it appears to have occurred in January 2026. The ShinyHunters threat group claimed responsibility for the attack and the exfiltration of 1 petabyte (1,000 TB) of data.
The threat group communicated with Bleeping Computer, which reported in March 2026 that systems were breached using compromised Google Cloud credentials obtained in the Salesloft Drift breach. While the breach had the potential to be massive, it was recently reported to the HHS’ Office for Civil Rights as involving the protected health information of just 2,641 individuals. TELUS Health said it has implemented additional security safeguards to better safeguard the data within its environment.
The post Midwest Spine and Brain Institute Impacted by Vendor Ransomware Attack appeared first on The HIPAA Journal.
