Healthcare Cybersecurity

Many Medical Devices Incapable of Supporting Transition to Post-Quantum Cryptography

An analysis of medical devices indicates that healthcare organizations face a significant risk of future quantum-enabled attacks, as only a small percentage are capable of supporting a transition to post-quantum cryptography (PQC). The analysis was conducted by cybersecurity firm Forescout on more than 2.5 million Internet of Medical Things (IoMT) devices used by more than 50 healthcare delivery organizations. The findings are published in its October 2026 PQC in Healthcare Report.

Quantum computers vastly surpass the computational ability of standard computers as they process information using quantum states. They are capable of tackling complex problems that even today’s supercomputers are unable to solve. A problem tackled by a quantum computer may take minutes or hours compared to millennia by today’s most powerful computers. One such application would be cracking today’s encryption models.

Quantum computers are still under development, but Google has predicted that advances currently being made could render current encryption methods obsolete in the next five years, potentially as early as 2029. While it may appear that there is no immediate risk, encrypted data could potentially be harvested now for decryption later when quantum computing has sufficiently advanced. Forescout warns that the risk is greater in healthcare due to the long-term value of healthcare data, compared to data such as account numbers and payment card information which can be easily changed.

According to the analysis, only 6% of IoMT devices and 16% of operational technology (OT) devices use SSH implementations that support PQC. These devices are relied on by healthcare organizations for a range of functions; however, the lowest percentage of IoMT devices capable of supporting PQC are those used for providing patient care. By comparison, around 50% of IT devices are capable of supporting PQC.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

PQC involves the use of new cryptographic algorithms capable of protecting against attacks from quantum computers; however, healthcare is particularly exposed because many medical devices in use are not capable of supporting PQC, including systems and devices that contain large volumes of highly sensitive healthcare data such as electronic medical records (EMRs), Picture Archiving and Communications Systems (PACS), and devices used for patient care such as patient monitors, imaging systems, infusion pumps, and lab equipment.

These systems and devices tend to have long lifecycles; however, they also have limited paths for upgrading, including upgrades to support new cryptographic standards. Many of these devices and systems are also exposed to the Internet, which makes them vulnerable to attack. The researchers identified 5,500 Internet-exposed systems, including EMRs and PACS. Overall, out of all exposed medical information systems, only 31% supported TLS 1.3 – the only TLS version capable of supporting standardized PDC. The analysis found that 6% of PACS supported TLS 1.3, falling to 33% for EMRs, and 13% for laboratory management systems.

The key to protecting data against quantum-enabled attacks is preparation. “PQC migration is not simply an encryption upgrade project,” said Daniel dos Santos, VP of Research at Forescout. “Healthcare providers need to understand which assets store, process, and transport their most sensitive data, which systems can realistically be upgraded, and where compensating controls will be required. Our research shows that the devices least prepared for the transition are often the same devices healthcare organizations depend on most for delivering patient care. Visibility into those assets and the data they handle is essential for building a practical migration strategy.”

Forescout recommends that healthcare organizations start preparing now by creating a comprehensive and accurate inventory of all systems and devices, including IT, OT, IoT, and IoMT devices, along with data types and connections, prioritizing internet-exposed connections. All assets should be assessed to determine if they are capable of supporting PQC, and any assets that are not should be prioritized for upgrades or compensating controls, especially Internet-exposed connections such as patient portals, external-facing APIs, VPN gateways, and inter-organization data exchange. TLS 1.3 should be enforced, where possible. Any systems that cannot be upgraded should be segmented and isolated, and PDQ readiness should be incorporated into governance, procurement, and risk management processes. ForeScout also recommends ensuring that vendors understand PQC roadmaps if they have not offered alternatives, as well as timelines for migration to PQC.

The post Many Medical Devices Incapable of Supporting Transition to Post-Quantum Cryptography appeared first on The HIPAA Journal.

Citrix Patches Third Actively Exploited NetScaler Zero Day

Citrix has released another patch for a zero day vulnerability under active exploitation, just a few days after patches were released for two other actively exploited zero day flaws. Like the previous two zero day flaws, the latest vulnerability affects Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway appliances. The former is often used to provide cloud applications to employees, while the latter is commonly used as an SSL VPN to provide single sign-on to remote workers.

The previously patched two zero-days can lead to remote code execution; however, the latest vulnerability is believed to only allow an attacker to crash the system, with repeated attacks resulting in denial of service. Citrix explained that it has observed targeted attacks on unmitigated NetScaler systems and has yet to determine the impact on the integrity of customer data. Security researchers have found evidence that threat actors are chaining one of the earlier RCE zero day flaws – CVE-2026-8877 – with the latest vulnerability.

The vulnerability is tracked as CVE-2026-88779 and is rated high severity, with a CVSS v4.0 severity score of 8.7. The flaw is a memory overflow vulnerability in SAML that affects customer-managed deployments configured as a SAML Service Provider (SAML SP / SAML IdP). Citrix also warned that Secure Private Access Hybrid deployments using NetScaler instances are also affected by the vulnerability. Citrix-managed cloud services and Citrix-managed Adaptive Authentication have been automatically updated with the fixed version.

Patches to fix the vulnerability were issued on October 4, 2026. Users who have already patched the previous two zero days will also need to apply the latest fix to protect against exploitation. Citrix is urging all customers with vulnerable appliances to upgrade to the fixed version as soon as possible. Further information can be found in the Citrix security bulletin.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

Vulnerable versions:

  • Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1 prior to 14.1-73.41
  • Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1 prior to 13.1-64.28
  • Citrix NetScaler ADC FIPS prior to 14.1-73.41 FIPS
  • Citrix NetScaler ADC FIPS and NDcPP prior to 13.1-37.282

Patched versions:

  • NetScaler ADC / NetScaler Gateway versions 14.1-73.41 and later 14.1 releases
  • NetScaler ADC / NetScaler Gateway versions 13.1-64.28 and later 13.1 releases
  • NetScaler ADC 14.1-FIPS 14.1-73.41 FIPS and later 14.1-FIPS releases
  • NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1-37.282 and later 13.1-FIPS and 13.1-NDcPP releases

The post Citrix Patches Third Actively Exploited NetScaler Zero Day appeared first on The HIPAA Journal.

Citrix Patches Actively Exploited NetScaler ADC & NetScaler Gateway Vulnerabilities

Two critical zero-day vulnerabilities in Citrix NetScaler ADC (formerly Citrix ADC) and Citrix NetScaler Gateway (formerly Citrix Gateway) are under active exploitation and require immediate patching. The vulnerabilities are part of a batch of eight flaws detailed in a Citrix security bulletin issued on September 27, 2026. Six of the vulnerabilities are rated high severity, with CVSS v4.0 severity scores between 7.0 and 8.8. The critical flaws have a CVSS base score of 9.5.

  • CVE-2026-88771 is a critical remote code execution vulnerability due to improper input validation. Successful exploitation can allow an attacker to execute arbitrary commands. The vulnerability affects all Citrix NetScaler ADC and Citrix NetScaler Gateway deployments.
  • CVE-2026-88772 is a critical memory overflow vulnerability that can lead to remote code execution or denial of service. The vulnerability is present if DTLS configuration is enabled on NetScaler ADC or NetScaler Gateway. It is enabled by default on VPN vServer.

The six remaining vulnerabilities are as follows:

  • CVE-2026-88775; CVE-2026-88776 & CVE-2026-88777 – (CVSS 8.8) – Memory overflow vulnerabilities leading to unpredictable or erroneous behavior or denial of service.
  • CVE-2026-88778 (CVSS 8.8) – TCP Initial Sequence Number (ISN) prediction flaw.
  • CVE-2026-88774 (CVSS 7.0) – Feature policy bypass (improper HTTP URL-based expression usage).

The vulnerabilities affect the following Citrix NetScaler ADC and Citrix NetScaler Gateway versions:

  • Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1 BEFORE 14.1-73.37
  • Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1 BEFORE 13.1-64.23
  • Citrix NetScaler ADC FIPS BEFORE 14.1-73.37 FIPS
  • Citrix NetScaler ADC FIPS and NDcPP BEFORE 13.1-37.279

Software updates have already been applied to fix the vulnerabilities in Citrix-managed cloud services and Citrix-managed Adaptive Authentication. Patches need to be applied to fix the vulnerabilities in customer-managed Citrix NetScaler ADC and Citrix NetScaler Gateway deployments. Since two of the vulnerabilities are under active exploitation, customers are urged to upgrade as soon as possible. The extent to which the flaws are being exploited has not been disclosed.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

The updated versions with the vulnerabilities fixed are:

  • Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1-73.37 and later releases
  • Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1-64.23 and later releases of 13.1
  • Citrix NetScaler ADC 14.1-FIPS 14.1-73.37 FIPS and later releases of 14.1-FIPS
  • Citrix NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1.37.279 and later releases of 13.1-FIPS and 13.1-NDcPP

The post Citrix Patches Actively Exploited NetScaler ADC & NetScaler Gateway Vulnerabilities appeared first on The HIPAA Journal.

OpenAI Agent Hacks Australian Medicare Portal

An artificial intelligence (AI) agent developed by OpenAI gained unauthorized access to an Australian Medicare statistics reporting service portal and obtained non-public data. The same AI agent also accessed three other government systems as part of its autonomous research activities: the web portals of the Australian Institute of Health and Welfare, the Victorian Department of Health, and the New South Wales Bureau of Crime Statistics and Research.

An AI agent is an autonomous system that uses an AI model to plan, make decisions, and execute tasks to solve complex problems in response to a prompt from a user or different AI system. In this case, the AI agent was part of an internal model used by OpenAI’s research team for conducting internet-based research into healthcare spending.

While attempting to compile health and medical statistics, the AI agent encountered certain blocks preventing access to data. While the AI agent had no authority to access non-public data, it successfully circumvented the blocks to access data in the Medicare statistics database and also wrote data to the server.

The incident occurred in June 2026; however, OpenAI learned about the issue in August, when in-depth checks of the AI agent’s activity identified actions that were not intended. According to OpenAI, no evidence was found to indicate any patient records were accessed. The data accessed was limited to aggregate health statistics and internal file names. OpenAI informed the Australian government about the incident on September 10, 2026. OpenAI is conducting an extensive review of “misaligned model activity,” and the investigation is ongoing. OpenAI said it is committed to transparency and will share what it learns as the investigation continues.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

“The Medicare Statistics Reporting Portal is a public-facing statistics portal that contains non-sensitive Medicare information relating to data and statistics such as spending. No personal information is believed to have been accessed at this stage, but investigations are ongoing,” Australia Prime Minister Anthony Albanese said. “Evidence currently available is there is no broader compromise to the Services Australia network. Nonetheless, this situation is obviously unacceptable.”

OpenAI has been criticized for the delay in notifying the Australian government. The notice was only received on September 10, and then it was sent to an infrequently checked public mailbox. The Australian Signals Directorate’s Cyber Security Centre found out about the incident on September 15, 2026.

The government has launched a taskforce to conduct an immediate review into the incident to determine whether existing processes are sufficient for responding to AI-related cyber threats, and to assess cybersecurity controls on public-facing websites and apps to determine how they can be improved to counter AI-related threats.

There is growing concern among researchers and tech leaders that advances in artificial intelligence are happening too quickly, and there are insufficient guardrails in place. The AI models currently being developed have demonstrated that they are able to circumvent security measures to gain access to protected data, including exploiting system vulnerabilities to complete the assigned tasks. If a human did the same, it would be considered hacking, and that individual would likely face criminal charges. The law has yet to be tested when the actor is an autonomous AI agent, although it is unlikely that there will be any charges against OpenAI since the data access was unintentional and not malicious.

The post OpenAI Agent Hacks Australian Medicare Portal appeared first on The HIPAA Journal.

77% of Ransomware Groups Are Targeting the Healthcare Sector

A new analysis of ransomware activity reveals broad, consistent targeting pressure across the United States. Ransomware activity is not limited to any specific industry, with all sectors attacked to varying degrees. The analysis was conducted by the AI-driven cybersecurity and threat intelligence platform provider Anomali, with the findings published in its US Ransomware Industry Targeting Report. Anomali observed ransomware targeting across 8 industry sectors by 200 distinct ransomware entities, with its analysis showing that technology was the most targeted sector, followed by manufacturing and healthcare.

Anomali looked at ransomware targeting across eight industry sectors – technology, manufacturing, healthcare, financial services, government public services, construction, education, and energy. There was in excess of 50% observed targeting presence in all eight sectors, with technology companies targeted by 172 of the 200 ransomware entities (86%), followed by manufacturing with 166 (83%), and healthcare in third place with 154 (77%).

The healthcare sector has long been an attractive target for ransomware groups as it is a high-pressure extortion environment combining patient care, protected health information, insurance, payments, and clinical operations, which provides multiple points of leverage for extortion. The healthcare industry is reliant on continuous access to patient data, and any attack that prevents access creates a significant safety risk. There is pressure on victims to recover rapidly, which increases the likelihood of a ransom being paid. Further, a sprawling attack surface, including legacy systems and devices that cannot be patched, makes attacks easier than in many other sectors.

While there are many potential entry points, the most common are unpatched VPNs, firewalls, edge devices, and other internet-facing applications, and these are likely to remain the most high-value entry points into healthcare environments. Internet-facing exposure should be closed before ransomware groups are able to exploit it, focusing on VPNs, firewalls, edge devices, backup platforms, RMM tools, and externally reachable applications.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

Anomali recommends treating identity as the primary ransomware boundary and ensuring that phishing-resistant multifactor authentication is implemented for remote access, administrators, SSO, VPN, and privileged service accounts. Exposed RDP should be removed, reviews should be conducted to identify stale accounts, and there should be continuous monitoring for credential exposure and anomalous logins.

File encryption causes significant disruption to healthcare operations, so a rapid recovery is essential. Offline, immutable backups should be created for all critical systems and data, and restoration procedures should be tested under ransomware conditions. Anomali has seen evidence that EDR evasion is becoming a common part of the affiliate playbook and predicts increased use of EDR-killing tools by adversaries over the coming year. Anomali recommends enabling EDR tamper protections, preserving centralized logs, and monitoring PowerShell, RMM, and exfiltration behavior, and rehearsing legal, communications, regulatory, and law-enforcement decisions before an extortion deadline.

“Healthcare organizations face an especially difficult ransomware threat because attackers know that patient care cannot simply pause while systems are restored. As ransomware groups broaden their targeting and reuse the same tactics across industries, healthcare leaders need real-time threat intelligence that helps them identify emerging activity earlier, prioritize the risks most likely to affect their environment and respond before an intrusion disrupts patient care,” Patrick Holt, head of product at Anomali, told the HIPAA Journal.

The post 77% of Ransomware Groups Are Targeting the Healthcare Sector appeared first on The HIPAA Journal.

Cybersecurity Awareness Month 2026: Critical Infrastructure Urged to Adopt Cybersecurity 3Rs

October is Cybersecurity Awareness Month, a global effort to promote online safety and digital security. Launched in 2024 by the National Cybersecurity Alliance and the Cybersecurity and Infrastructure Security Agency (CISA), the aim is to teach individuals and organizations practical steps to improve resilience to cyber threats. The general theme this year is Don’t Make It Easy for Them, which focuses on everyday digital safety habits that everyone should adopt to improve online safety and security, such as using strong, unique passwords, implementing multifactor authentication (MFA), learning to recognize and avoid phishing, and keeping operating systems, software, applications, and devices up to date.

A dual theme of this year’s Cybersecurity Awareness Month is strengthening critical infrastructure cybersecurity. Securing the nation’s critical infrastructure is a top national security priority under the White House March 2026 Cyber Strategy for America. As the United States celebrates the semiquincentennial anniversary of the nation’s founding, a rallying cry has been issued to future-proof the nation’s critical infrastructure and secure it for the next 250 years.

Critical infrastructure relies heavily on internet-connected systems and devices. Internet access improves efficiency, but it also introduces risks, as Internet-exposed systems, software, and devices can potentially be remotely attacked by cybercriminal actors, hacktivists, and hostile nation-states. Financially motivated criminal threat actors attack vulnerable systems and hold systems and data to ransom; hacktivists may target critical infrastructure in response to governmental policies; and nation-state actors steal intellectual property to accelerate their own economic growth and technological dominance, and conduct destructive attacks to further their nations’ political priorities. Critical infrastructure owners and operators need to defend against these attacks and ensure they can recover quickly should an attack succeed.

The 3Rs of Cybersecurity – Reduce, Replace, Recover

This Cybersecurity Awareness Month, critical infrastructure owners and operators have been requested to practice the 3Rs of cybersecurity – Reduce, Replace, Recover – to improve cyber resilience. Critical infrastructure should improve their efforts to reduce the attack surface by ensuring that systems are kept up to date, patches are applied promptly, and obsolete software and devices are upgraded or replaced before they reach end of life. Plans also need to be developed, implemented, maintained, and practiced to ensure operations can be sustained in the event of a cyber incident and that they can recover quickly from a successful attack.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

While the threat landscape is constantly evolving, CISA points out that it isn’t fundamentally changing; rather, it is scaling. Threat actors constantly search for vulnerabilities to exploit, as has been the case for many years; however, vulnerabilities are being discovered in record numbers. Total published Common Vulnerabilities and Exposures (CVE) this year exceeded last year’s total by the end of August 2026.

Artificial intelligence is accelerating the discovery of software vulnerabilities and is helping threat actors to exploit vulnerabilities far more quickly, including mass exploitation through automation. Since defenders can easily get overwhelmed with the sheer number of vulnerabilities that require remediation, the key approach is to patch smarter, not harder. Vulnerabilities need to be assessed, and remediation efforts prioritized, ensuring that the most critical vulnerabilities are addressed first, such as those listed in the Known Exploited Vulnerability (KEV) Catalog.

When software and devices reach end-of-life, security updates and patches come to an end. Continued use of end-of-life software and devices presents threat actors with opportunities to exploit unaddressed vulnerabilities to gain access to networks and sensitive data. Critical infrastructure owners and operators need to know when support will end for their software and devices and plan to upgrade or replace software, firmware, and hardware devices before support comes to an end. This is especially important for any technology devices or software on the boundary of the network that are accessible from the public internet. Guidance on mitigating risk for end-of-life software and devices is available in BOD 26-02.

It is essential that operations can be sustained in the event of a cyber incident and that a rapid and full recovery is possible. Critical infrastructure owners and operators need to fortify their systems and invest in isolation and recovery capabilities. Vital systems must be isolated from harm and must be capable of continuing to operate in an isolated state, while compromised systems are recovered. CI Fortify is an allied initiative designed to ensure that critical infrastructure entities can continue to operate in the event of geopolitical cyber conflict, through the implementation of resilient OT environments capable of surviving extended isolation and cyber compromise.

All Businesses Should Take Steps to Improve Their Security Posture

Critical infrastructure is supported by a diverse range of businesses, and vendors in the supply chain that are directly or indirectly involved with critical infrastructure are often targeted by threat actors, as they are often a weak link in the security chain. This Cybersecurity Awareness Month, CISA is encouraging all businesses to assess their security posture and implement key cybersecurity best practices, starting with basic, high-impact measures to defend their networks and data:

  • Provide phishing education to the workforce
  • Strengthen password requirements
  • Implement multifactor authentication
  • Update business software and patch promptly

With those foundational security requirements in place, businesses should expand their security capabilities by implementing the following measures:

  • Log system activity on all business systems
  • Back up business data
  • Encrypt data at rest and in transit
  • Develop and implement an incident response plan
  • Report all cyber incidents to CISA
  • Prepare for system disruptions

The post Cybersecurity Awareness Month 2026: Critical Infrastructure Urged to Adopt Cybersecurity 3Rs appeared first on The HIPAA Journal.

Democratic Senators Reintroduce the Health Infrastructure Security and Accountability Act

On September 17, 2026, two Democratic Senators reintroduced the Health Infrastructure Security and Accountability Act, which seeks to improve cybersecurity standards for the U.S. healthcare system and make funds available to help rural and underserved hospitals invest in essential cybersecurity measures.

The bill was reintroduced by Sens. Mark R. Warner (D-VA) and Ron Wyden (D-OR), following its initial introduction in the 118th Congress 2D Session on September 25, 2024. When the bill was first introduced, 394 large hacking-related healthcare data breaches had been reported to the Department of Health and Human Services Office for Civil Rights (OCR), involving the protected health information of 43 million Americans.

At the time, the senators explained that cyberattacks are delaying and disrupting patient care, harming patient health and national security, and putting Americans at risk of identity theft and fraud. “These hacks are entirely preventable and are the direct result of lax cybersecurity practices by health care providers and their business partners,” explained the Senators.

The situation has only worsened in the two years since the bill was first introduced. The OCR breach portal lists year-to-date figures (Jan 1 – Aug 31) of 426 hacking-related breaches, involving the protected health information of 73 million Americans. That’s an 8% increase in hacking-related data breaches and a 70% increase in affected individuals.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

On January 24, 2024, OCR published two sets of voluntary cybersecurity performance goals (CPGs) for the healthcare and public health (HPH) sector – Essential and Enhanced – that consist of high-impact measures that should be adopted by healthcare organizations to strengthen and mature their cybersecurity programs. As predicted by OCR at the time, voluntary goals alone would not be enough to drive the behavioral changes needed across the sector to improve cybersecurity.

The CPGs were followed by a proposed update to the HIPAA Security Rule, which mandates significant additional cybersecurity requirements. The proposed update has proven hugely unpopular, with industry groups and health systems calling for the proposed rule to be scrapped. A final rule has been delayed until July 2027, although a final decision about whether a final rule will actually be released has yet to be made by the Trump administration. Part of the problem, especially for rural and other low-resource healthcare providers, is a lack of funding to make the necessary cybersecurity improvements, which is something that the Health Infrastructure Security and Accountability Act seeks to address.

“As cybercriminals ramp up their attacks on hospitals and health care providers, it’s becoming increasingly clear that voluntary standards are not enough to protect Americans’ health, safety, and privacy,” explained Sen. Warner. “This legislation would establish strong, commonsense cybersecurity protocols for health care entities, while also getting resources to rural and underserved hospitals to strengthen their defenses and protect the patients who depend on them.”

As the Senators explained, the U.S. health care system is particularly at risk for cyberattacks due to its size, technological dependence, collection of sensitive personal information, and unique vulnerability to disruptions. Healthcare organizations are viewed as low-hanging fruit, and attacks can be highly profitable for cybercriminals. “The frequency and sophistication of cyberattacks has dramatically increased in every part of the health care system, and will only grow,” said Sen. Wyden. “Our bill creates national cybersecurity standards for health care providers and devotes resources, especially in rural and underserved areas, to ensure every American’s medical information is secure. Congress cannot wait to act until another catastrophic cyberattack compromises the safety and privacy of American families’ most personal information.”

The 2026 Health Infrastructure Security and Accountability Act remains largely unchanged from the 2024 version, other than shifting the timeline forward by two years. The key requirements of the bill are:

  • Mandatory minimum cybersecurity standards for covered entities and business associates, established, enforced, and updated by the HHS. Updates are required at least every two years.
  • Heightened cybersecurity standards for systemically important entities and entities critical to national security.
  • Continuity/recovery plans for all covered entities for technical failures, disruptive cyber events, and natural disasters, and stress tests to evaluate whether the entity has the capabilities to recover essential functions.
  • Written annual statements signed by the chief executive officer and chief information security officer attesting that the company is compliant with applicable security standards.
  • Mandatory annual security risk analyses, including specific assessments of the extent to which the entity is exposed to risk through its business associates.
  • Independent audits of covered entities’ security measures to assess compliance with the HHS’s CPGs.
  • Annual HHS audits of at least 20 HIPAA-regulated entities to assess data security practices, focused on those of systemic importance.
  • Increased financial penalties under HIPAA for failing to meet security requirements – A minimum $500 penalty for no knowledge; $5,000 for reasonable cause; $50,000 for willful neglect (corrected); and $250,000 for willful neglect (uncorrected).
  • A government investment of $1.3 billion to help hospitals strengthen cybersecurity: $800 million in up-front investment for hospitals in rural and underserved urban communities to adopt the essential cybersecurity goals, and $500 million in incentives available to all hospitals to adopt the enhanced CPGs.
  • Medicare accelerated and advanced payments in response to cybersecurity incidents.

The post Democratic Senators Reintroduce the Health Infrastructure Security and Accountability Act appeared first on The HIPAA Journal.

Conti Ransomware Member Sentenced to 4 Years in Jail

A Ukrainian national who deployed Conti ransomware on the networks of at least 12 organizations in the United States and other countries has been sentenced to four years in jail for his role in the attacks. The Conti ransomware group was a major ransomware operation that engaged in double extortion tactics, breaching victims’ networks, stealing sensitive data, and encrypting devices for financial gain. The Conti ransomware operation emerged after the shutdown of the Ryuk ransomware group in 2020 and was active until 2022. During that time, the group conducted ransomware attacks on an estimated 1,000 entities in 31 foreign countries, 47 U.S. states, the District of Columbia, and Puerto Rico.

While some ransomware groups prohibited attacks on healthcare providers, Conti had no such restrictions and actively targeted healthcare organizations. The group reached peak activity in 2021, when many critical infrastructure entities were attacked, including the Health Service Executive in Ireland and many U.S. hospitals, such as Scripps Health in San Diego. According to the U.S. Department of Justice (DoJ), the Conti ransomware group collected an estimated $150 million in ransom payments as of January 2022.

Oleksii Oleksiyovych Lytvynenko, 44, formerly of Cork, Ireland, was arrested in Ireland in July 2023 by the Irish national police and was extradited to the United States last year to face trial. Lytvynenko was accused of being a developer of malicious tools used by the Conti ransomware operation, breaching the networks of at least 12 companies, and exfiltrating and storing stolen data.

Lytvynenko admitted to being a member of the Conti ransomware operation since September 2021, controlling stolen data from eight victims in the United States and four victims in foreign countries, and issuing ransom demands. Lytvynenko was a member of a team run by a co-conspirator and developed loader malware, which was used by the group to load malicious software on victims’ networks. In June 2026, Lytvynenko pleaded guilty to one count of conspiracy to commit wire fraud and has been awaiting sentencing, which could have been a maximum of 20 years in jail. On September 10, 2026, Lytvynenko was sentenced to four years in federal prison.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

“Ransomware attacks like Conti cause real harm to businesses, institutions, and families here at home and around the world,” said U.S. Attorney Braden H. Boucek for the Middle District of Tennessee. “Today’s sentence demonstrates that cybercriminals cannot hide behind borders or a keyboard to escape justice. We are grateful to our law enforcement and international partners whose work made this result possible.”

Four other Conti co-conspirators – Russian nationals Maksim Galochkin, Maksim Rudenskiy, Mikhail Mikhailovich Tsarev, and Andrey Yuryevich Zhuykov – have also been indicted for their role in Conti ransomware attacks and have criminal charges pending in the Middle District of Tennessee.

The post Conti Ransomware Member Sentenced to 4 Years in Jail appeared first on The HIPAA Journal.

Orthanc DICOM Server Vulnerability Can Lead to Denial of Service

A high-severity vulnerability has been identified in Orthanc DICOM Server that could be exploited by an authenticated remote attacker to write past the end of a heap allocation and crash an Orthanc process in a denial-of-service attack.

Orthanc DICOM Server is a free-to-use, standalone, open-source, lightweight DICOM server that is used in both clinical and research environments. It can complement or act as a gateway to existing PACS systems, and was developed to improve interoperability and workflow efficiency.

An integer overflow in a specified pitch and buffer-size computation results in a heap out-of-bounds write when Orthanc decodes a specially crafted PNG or JPEG image file, causing a crash and denial-of-service condition.

The vulnerability is tracked as CVE-2026-87020 and has been assigned a CVSS v3.1 base score of 8.1 and a CVSS v4.0 base score of 7.2. The vulnerability was identified by penetration tester Andrej Tomci, who reported the issue to the Cybersecurity and Infrastructure Security Agency.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

The vulnerability affects all Orthanc DICOM Server prior to 1.13.0. Orthanc has fixed the vulnerability in version 1.13.0. and later versions.  Users are advised to verify the installed Orthanc DICOM Server version and download the latest version if a vulnerable version is in use. It is also recommended to restrict network access to Orthanc instances to trusted hosts only.

The post Orthanc DICOM Server Vulnerability Can Lead to Denial of Service appeared first on The HIPAA Journal.