Healthcare Cybersecurity

Medusa Ransomware Group Has Attacked 500+ Critical Infrastructure Orgs

CISA, the Department of Health and Human Services (HHS), and the Federal Bureau of Investigation (FBI) have issued an updated cybersecurity advisory about the Medusa ransomware-as-a-service (RaaS) group, which has now claimed more than 500 critical infrastructure victims.

When the cybersecurity advisory was first issued in March 2025, the authorizing agencies determined that Medusa had conducted more than 300 attacks on critical infrastructure entities between 2021 and February 2025. The Medusa ransomware operation emerged in June 2021 and initially operated as a closed ransomware group, with the developers conducting all aspects of the operation, including development, ransomware campaigns, and ransom negotiations.

In early 2023, Medusa morphed into a RaaS operation, using affiliates to conduct attacks for a percentage of the ransom payments. The group also launched a data leak site in 2023 and adopted double extortion tactics, issuing threats to publish stolen data to pressure victims into paying to prevent data leaks as well as to obtain the keys to decrypt data. Since the transformation into a RaaS group, attacks have increased substantially, with the developers and the group’s affiliates conducting attacks. In a little over a year, the group has claimed more than 200 victims in critical infrastructure sectors, compared to 300 in the previous four years.

Affiliates are given various levels of control based on their experience and profitability, with newer and less experienced affiliates having lower levels of trust. For instance, the developers retain control of important aspects of campaigns such as ransom negotiations for newer and less experienced affiliates. The developers recruit initial access brokers (IABs) on cybercriminal forums to provide access to victims’ networks, typically paying between $100 and $1 million to the IAB for access.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

While some RaaS groups have a policy of not attacking healthcare organizations, that is certainly not true of Medusa, which has frequently attacked the healthcare and public health (HPH) sector. While the group is largely believed to operate opportunistically, conducting attacks by focusing on organizations with unpatched, remotely exploitable software vulnerabilities, the high percentage of victims in the HPH sector could indicate targeting of the sector.

Medusa attacks typically start with phishing or the exploitation of unpatched vulnerabilities. The group incorporates exploits for recently announced vulnerabilities into it arsenal. For instance, the CVE-2026-1731 BeyondTrust vulnerability started to be exploited soon after it was announced in February 2026, and the CVE-2025-10035 Fortra GoAnywhere vulnerability was also rapidly exploited. The authoring agencies have observed the group incorporating new exploits within 24 hours of a vulnerability being announced and, in some cases, has started exploiting vulnerabilities in the week prior to an announcement.  No evidence has been found to indicate that the group develops its own exploits; rather, the group is believed to obtain exploits from unknown sources, potentially IABs, exploiting them before victims have the time to patch.

Medusa actors use living-of-the-land techniques, hiding their malicious activities by using legitimate tools to support credential access, data exfiltration, and ransomware deployment. Remote monitoring and management software and remote access services such as Remote Desktop Protocol are also used.

The key actions that HPH sector organizations should take to prevent attacks are to mitigate known vulnerabilities rapidly, ensuring all software, firmware, and operating systems are kept patched and up to date. Networks should be segmented to restrict lateral movement within the network, and network traffic should be filtered to prevent unknown or untrusted origins from accessing remote services on internal systems.

March 13, 2025: Critical Infrastructure Entities Warned About Medusa Ransomware as Victim Count Hits 300

A warning has been issued about the Medusa ransomware-as-a-service (RaaS) group, which has now claimed more than 300 victims in critical infrastructure sectors including healthcare, education, and manufacturing. The group has been active since June 2021 when it started as a closed group, before adopting the RaaS model, where affiliates are recruited to conduct attacks for a percentage of any ransom payments they generate.

Around two years after the group formed, Medusa launched a data leak site where victims are named and stolen data is published if the ransom is not paid. This double extortion method, where the ransom must be paid to obtain the decryption keys and prevent the publication of stolen data, is common among RaaS groups, although in the case of Medusa, its core members have retained control of ransom negotiations.

According to the joint cybersecurity alert from the Cybersecurity and Infrastructure Security Agency (CISA), the Federal Bureau of Investigation (FBI), and the Multi-State Information Sharing and Analysis Center (MS-ISAC), the Medusa developers recruit initial access brokers (IABs) on cybercriminal forums and marketplaces and incentivize them to work solely with Medusa. The authoring agencies have observed affiliates using phishing to obtain credentials to access victims’ networks, as well as exploiting unpatched software vulnerabilities, including last year’s ScreenConnect vulnerability CVE-2024-1709 and the Fortinet EMS SQL injection vulnerability CVE-2023-48788.

Once access to a victim’s network has been gained, Medusa actors use living off the land techniques for user, system, network, and file system enumeration, including legitimate tools such as Advanced IP Scanner, SoftPerfect Network Scanner, PowerShell, Windows Command Prompt, and Ingress Tool Transfer capabilities, as well as Windows Management Instrumentation (WMI) for querying system information.

The authoring agencies have observed Medusa actors using several different PowerShell detection evasion techniques, and they are known to hide their activities by deleting the PowerShell command line history. Endpoint detection and response tools are disabled by using vulnerable or signed drivers to kill processes, and legitimate remote access software is often used to evade detection and assist with lateral movement, along with Remote Desktop Protocol (RDP) and PsExec. Rclone is used to facilitate data exfiltration, and the encryptor is deployed across the network using tools such as Sysinternals PsExec, PDQ Deploy, and BigFix. Windows Defender and other security tools are also disabled on specific targets, backup processes are terminated, and shadow copies are deleted to prevent restoration of encrypted files without paying the ransom. Victims are given 48 hours to make contact to negotiate the ransom payment, with Medusa actors also known to reach out to victims via phone or email. There has been at least one instance where a further ransom demand was issued after the initial payment was made, where the affiliate behind the attack claimed not to have been paid.

The cybersecurity alert shares indicators of Compromise (IOCs), known MITRE ATT&CK tactics and techniques, and recommended mitigations, the most important of which are mitigating known vulnerabilities promptly, segmenting networks to restrict lateral movement, filtering network traffic to prevent unknown or untrusted origins from accessing remote services on internal systems, implementing multifactor authentication for webmail, VPNs, and all accounts that access critical systems, and educating the workforce about phishing identification and avoidance.

The post Medusa Ransomware Group Has Attacked 500+ Critical Infrastructure Orgs appeared first on The HIPAA Journal.

Critical Vulnerabilities Identified in Popular Consumer Fertility Device

Vulnerabilities have been identified in two consumer health and wellness devices – The Mira Hormone Monitor, a popular fertility tracking device, and the Pulsetto Vagus Nerve Stimulator. Vulnerabilities in the former could result in sensitive data exposure and data manipulation. The latter has a vulnerability that poses a safety risk to users.

Mira Hormone Monitor & Mira Android App

Multiple vulnerabilities have been identified in the Mira Hormone Monitor and its associated Android app that could expose sensitive health data, cause a denial-of-service condition, and allow an unauthorized individual to take control of user accounts and manipulate data, potentially resulting in failed fertility treatments, missed fertility windows, or unwanted pregnancies.

The vulnerabilities were identified by a team of researchers at Northeastern University SPQR Lab. The research was partly funded by the Department of Health and Human Services’ Advanced Research Projects Agency for Health (ARPA-H) through a grant issued under the Universal Patching and Remediation for Autonomous Defense program. The vulnerabilities were reported to the device manufacturer, Quanovate Tech, which has taken steps to address the vulnerabilities.

The researchers conducted a full-chain security assessment of the Mira Ultra 5 fertility hormone analyzer and associated Android app and cloud infrastructure. The researchers identified 20 vulnerabilities in the device, app, and cloud infrastructure, including two critical vulnerabilities. The most serious vulnerabilities could be exploited by an attacker to gain read and write access to reproductive health profiles, resulting in forgery, deletion, or destruction of health information, and to gain control of cloud accounts and access hormone record information and account settings.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

Key Vulnerabilities

The vulnerabilities include weak or missing authentication, transmission of user data to third parties through analytics code and SDKs, hard-coded API keys, a lack of rate-limiting/IP-throttling, and publicly accessible firmware. The vulnerabilities affect Mira Monitor Firmware 1.7.1.47 and Mira Android App 4.5.15.4.

Vulnerability CVSS v3.1 Base Score CVSS v4.0 Base Score Outcome of Successful Exploitation
CVE-2026-68067 9.8 (Critical) 9.8 (Critical) Gain control of cloud accounts and access hormone record information and account settings.
CVE-2026-67568 9.1 (Critical) 9.3 (Critical) Gain read and write access to reproductive health profiles, resulting in forgery, deletion, or destruction of health information.
CVE-2026-66875 8.8 (High) 8.7 (High) Extract stored hormone measurements; denial-of-service; passively track the user.
CVE-2026-67558 7.4 (High) 8.2 (High) Capture live session token information; inject forged hormone measurements into the victim’s cloud record and clinical trend view.
CVE-2026-66098 6.5 (Medium) 7.1 (High) Denial-of-service; disrupt ovulation tracking and fertility monitoring workflow.
CVE-2026-66832 6.5 (Medium) 6.9 (Medium) Obtain live session token.
CVE-2026-66340 5.3 (Medium) 6.9 (Medium) Brute force access to user account
CVE-2026-64934 4.3 (Medium) 5.3 (Medium) Submission of arbitrary firmware version strings for their own device; evade vendor-side vulnerable-fleet analytics; suppress security update prompts to the user; misrepresent patch-adoption metrics.

The researchers coordinated with the device manufacturer and CISA and previewed the findings after Quanovate had completed two rounds of remediation. Quanovate has released updates to fix these vulnerabilities, and users should upgrade to the latest firmware/app versions: iOS v3.5.18 / Android v4.5.18. Firmware v01.07.01.53 is updated via the app when the device is connected. No evidence has been found of any actual or attempted exploitation of the vulnerabilities.

Pulsetto Vagus Nerve Stimulator

A high-severity vulnerability has been identified in the firmware of the Pulsetto Vagus Nerve Stimulator. Successful exploitation could allow an attacker to disable electrical safety mechanisms or modify other stimulation output settings.

The issue is due to the firmware accepting hidden commands over its Bluetooth Low Energy (BLE) interface. The commands are sent without authorization or encryption and are never issued by the companion mobile application; however, they are fully processed when the device is powered on.

The vulnerability is tracked as CVE-2026-18844 and affects all current versions. The vulnerability has been assigned a CVSS v3.1 base score of 8.1, and a v4.0 base score of 7.2.  The vulnerability was identified by researcher and security author A.C. Buglione, who reported the vulnerability to CISA.  CISA reached out to Pulsetto regarding the vulnerability but did not receive a response. CISA has therefore advised users to contact Pulsetto directly for information on how the issue can be remediated.

The post Critical Vulnerabilities Identified in Popular Consumer Fertility Device appeared first on The HIPAA Journal.

Healthcare Orgs Warned About Gunra Ransomware Attacks

CISA, the FBI, and international partners have issued a joint cybersecurity advisory about the Gunra ransomware-as-a-service (RaaS) operation, which is targeting government and critical infrastructure entities, including healthcare organizations, and organizations in other sectors. The group has conducted attacks in the Americas, Europe, Middle East, Africa, and Asia-Pacific, with attacks accelerating in 2026.

Gunra ransomware was first identified as a financially motivated threat group in April 2025; however, in 2026, it transitioned into a RaaS group. The group is attempting to recruit experienced affiliates from other groups by offering an 80% cut of any generated ransoms, as well as initial access brokers who can deliver enterprise-scale footholds.

The group primarily targets Windows systems and uses advanced encryption methods. In late 2025, the group also developed a Linux variant of its encryptor to allow cross-platform targeting. The encryptor is based on leaked Conti ransomware source code. The group engages in double extortion attacks, stealing sensitive data before encrypting files. After file encryption, victims receive a ransom note in each affected directory and are required to initiate negotiations via a Tor-based negotiation panel. Victims are provided with unique login credentials to access the negotiation panel and are given between 5 and 10 days to commence negotiations.

The group has been observed gaining access to victims’ networks by exploiting known vulnerabilities in Internet-facing devices, including firewalls and VPN appliances, such as the CVE-2024-55591 and CVE-2025-24472 authentication bypass vulnerabilities in FortiOS/FortiProxy. The group has also been observed exploiting Secure Shell (SSH) access control vulnerabilities in internet-facing VPN gateways.

Multiple stealth and defense impairment techniques are used to hinder detection and analysis. Data collected and exfiltrated includes business-critical documents, databases, personally identifiable information (PII), and internal email communications, including from Microsoft OneDrive and SharePoint. The stolen data is used as leverage to pressure victims into paying the ransom. Threats are issued to publish or sell the stolen data on a dedicated dark web data leak site if the ransom is not paid. The group’s data leak site currently lists more than 30 worldwide victims.

The #StopRansomware cybersecurity advisory recommends taking immediate action to reduce the risk of an attack, including prioritizing patching for known exploited vulnerabilities, especially vulnerabilities in VPNs and RDP-exposed infrastructure. Networks should be segmented to hamper lateral movement from initially compromised devices to other organizational systems, and immutable backups should be created and stored in physically separate, segmented locations to ensure data can be recovered without paying the ransom.

Full details of the group’s tactics, techniques, and procedures (TTPs), Indicators of Compromise (IoC), and recommended mitigations are detailed in the cybersecurity advisory.

The post Healthcare Orgs Warned About Gunra Ransomware Attacks appeared first on The HIPAA Journal.

California Child Care Company Discovers 9-Year Employee Data Leak

A data breach has recently been announced by Child Care Resource Center that shows how even well-intentioned employee practices can result in the exposure of sensitive data. Child Care Resource Center is a California-based non-profit organization, and while it does not appear to be a HIPAA-covered entity, similar data breaches have occurred at entities subject to the HIPAA Rules.

Child Care Resource Center recently learned that one of its employees had been forwarding internal files containing personal data to an external email account. While sending emails containing internal data outside the organization could indicate data theft, in this case, Child Care Resource Center was satisfied that the files were being emailed in an effort to fulfil tasks associated with the employee’s role.

The employee had been emailing data to the external email account for many years before their actions were discovered. The investigation determined that the first instance occurred on October 4, 2016, and continued until October 15, 2025. It took until June 3, 2026, to complete the investigation and review the data involved. The affected individuals are now being notified and have been offered complimentary credit monitoring and identity theft protection services.

The breach notification letter sent to the California Attorney General does not state the exact types of data involved, nor the number of affected individuals; however, considering the practice spanned 9 years, it could be an extensive data breach. When files are forwarded to an external email account, the company loses control of the data and is unable to protect the information against unauthorized access.

In this case, the company found no evidence to suggest unauthorized data access, nor that any information had been misused. Since unauthorized data access cannot be ruled out in these circumstances, breach notifications are required. Child Care Resource Center said it has implemented additional safeguards to prevent similar incidents in the future.

Healthcare organizations can reduce the risk of incidents such as this by providing regular security awareness and HIPAA training, emphasizing the risks associated with emailing or otherwise copying data to complete work duties out of the office. Technical security measures should be configured to either block the emailing of internal data to external email accounts or, if not practical, to ensure that email security solutions are configured to flag anomalous behavior and closely monitor alerts for potential data security incidents.

The post California Child Care Company Discovers 9-Year Employee Data Leak appeared first on The HIPAA Journal.

CISA Issues Updated Guidance on Minimum Elements of an SBOM

The U.S. Cybersecurity and Infrastructure Security Agency (CISA), Federal Bureau of Investigation (FBI), National Security Agency (NSA), and 15 international cybersecurity authorities have published joint guidance on the minimum elements of a Software Bill of Materials (SBOM). An SBOM is a detailed list of software components, including open-source libraries and hidden dependencies, together with the creators or vendors associated with those components.

Software supply chains are often large and complex, and vendors can be slow to release patches to address vulnerabilities, especially when those vulnerabilities affect third-party components. Cybercriminals target software supply chains as they often have ample time to exploit vulnerabilities before patches are released. Keeping up to date with vendor patches is important; however, simply applying vendor patches does not guarantee that the software is secure. If an SBOM is obtained from a software vendor, users will be able to identify vulnerable or risky components long before patches are released by vendors, allowing them to implement temporary solutions to protect against software supply chain attacks.

In 2021, the National Telecommunications and Information Administration (NTIA) published guidance on the minimum elements for an SBOM, and the latest guidance replaces that document, incorporating stakeholder feedback obtained following the publication of draft guidance in 2025. “SBOM tooling has advanced, driven by the growing number of organizations generating, sharing, consuming, and analyzing SBOMs,” wrote the authoring agencies. “These advancements enable organizations requesting SBOMs to demand more information about their supply chain and software components than they could have in 2021.”

The latest guidance applies to all software solutions, although additional requirements may be necessary for certain types of software, such as AI-based software systems and software-as-a-service (SaaS) solutions in cloud environments. The authoring agencies recommend using the guidance to ensure that their SBOMs include the minimum requirements and then assessing each software solution to determine if any further efforts are required to improve software transparency.

The update includes an additional ten data fields, updates to eight components to clarify scope and specify expectations, and five minor updates to improve information quality and align the guidance with the latest technical developments. The guidance is aimed at organizations that produce, procure, or operate software, and will allow them to better understand the makeup of their software components and supply chains and make more risk-informed decisions.

The post CISA Issues Updated Guidance on Minimum Elements of an SBOM appeared first on The HIPAA Journal.

Health-ISAC Warns of Increasing ShinyHunters Healthcare Data Theft Attacks

Health sector organizations have been warned about an increase in successful attacks by the ShinyHunters threat group. In contrast to ransomware actors, ShinyHunters conducts supply chain and identity attacks, targeting cloud SaaS and storage platforms. The group is focused on cloud-scale data exfiltration, with initial access typically achieved by voice-based social engineering (vishing) to reset passwords, MFA, or enroll new devices, according to a recent Health-ISAC cybersecurity alert.

Once account access is gained, they log in to the organization’s Okta, Microsoft Entra, or Google SSO dashboard, which lists all applications the account holder has access to, such as Microsoft 365, Salesforce, Dropbox, Google Drive, and other third-party platforms.  Data is rapidly exfiltrated, and victims are advised about the data theft. ShinyHunters demands a ransom payment to prevent the stolen data from being leaked on the group’s dark web data leak site.

In recent months, ShinyHunters has conducted successful attacks on several healthcare and medtech companies, including the medical device manufacturers Medtronic and iRhythm, and OneMedical, DentaQuest, AdaptHealth, and Him & Hers. Health-ISAC explained that in a recent attack on a health sector organization, ShinyHunters claimed to have conducted vishing attacks on multiple employees, allowing a Microsoft Entra account to be compromised and a significant amount of company data to be exfiltrated from SaaS and internal platforms such as Microsoft 365 and SharePoint.

Health-ISAC has shared practical, high-impact recommendations for healthcare and medtech companies to improve defenses against these types of campaigns, the most important of which involves breaking the attack chain between the vishing call and the SSO account takeover. Helpdesk and IAM support workflows can be hardened by requiring out-of-band identity proofing for any password or MFA reset, or device reenrollment. Procedures should be implemented that require verification of the request by a callback to a previously verified number, and manager approval for any privileged user. It should not be possible to perform the password/MFA reset or device re-enrolment on the same inbound call.

To harden MFA security against reset abuse, phishing-resistant MFA (FIDO2/WebAuthn security keys or equivalent) should be implemented for admins and high-risk groups, and ideally for all users. SMS/voice MFA and weak fallback methods should be disabled or tightly restricted, and strict controls should be implemented for MFA factor registration.

Since the target is SSO, which provides the keys to the kingdom, Health-ISAC recommends classifying these systems as Tier 0 – the most critical company assets. As such, MFA and compliant devices should be required for accessing sensitive cloud services, legacy authentication should be blocked, administrative portals should be limited to managed devices, and geo-velocity/impossible travel checks implemented.

Extortion is only possible with data exfiltration, so it is vital to closely monitor logs for signs of account takeover and large-scale data access. Health-ISAC recommends centralizing Microsoft Entra sign-in logs, audit logs, and SaaS audit logs into an SIEM and configuring alerts for new device enrolments, MFA factor registration OAuth reset events, new OAuth apps or unusual consent grants, unusual bulk downloads, atypical API calls, and new forwarding rules and mailbox delegation changes.

Healthcare employees may be familiar with traditional phishing attacks, but less familiar with vishing. Vishing should be incorporated into security awareness training programs, and consider running vishing simulations on the workforce, especially on individuals with privileged accounts, helpdesk IT staff, new hires, and remote workers.

Health-ISAC recommends a 30- to 60-day time frame for implementing the recommendations, starting with phishing-resistant MFA for high-risk users, strengthening helpdesk reset procedures, and enforcing conditional access policies. In addition, tabletop exercises should be conducted for containing compromised cloud accounts (token/session revocation).

The post Health-ISAC Warns of Increasing ShinyHunters Healthcare Data Theft Attacks appeared first on The HIPAA Journal.

Global Data Breach Cost Rises 12% to Almost $5 Million

The IBM 2026 Cost of a Data Breach Study shows data breach costs have risen by 12% in a year to almost $5 million, with the United States facing the highest breach costs. In 2026, the average cost of a data breach in the United States was $11.5 million – more than double the average global data breach cost. Healthcare continues to face the highest breach costs, with an average cost of $6.64 million per incident, although healthcare data breach costs have fallen by 10.5% year-over-year from a global average of $7.42 million in 2025. Data breach costs increased in all sectors represented in the study, with the rise largely driven by increases in detection, escalation, and lost business costs.

In healthcare, 59% of breaches were malicious or criminal attacks, 26% were due to IT failures, and 13% were due to human error. Across all sectors, phishing (voice and SMS phishing) accounted for 17% of breaches and was the most common initial access vector and had an average breach cost of $5.9 million. The next most common vectors were supply chain compromise, abuse of valid accounts, drive-by compromise attacks, and social engineering.

For the first time in five years, the average time to identify and contain a breach increased, rising 2.5% from 2025. The attack vectors that proved most difficult to identify and contain were removable media and supply chain compromises, as they do not show up in malware scans or inbound traffic. Breaches involving either of these attack vectors took an average of 258 days to identify and resolve, compared to an average of 247 days across all attack types.

Attackers have embraced AI tools in all areas of their attacks, including scanning for vulnerabilities, crafting phishing and social engineering lures, and automating attacks at scale. There has been a 56% year-over-year increase in AI-driven attacks, with one in four organizations having experienced an AI-driven breach in the past year.

AI deepfake and impersonation accounted for 45% of AI-driven attacks, with AI-generated malware becoming more common, accounting for 19% of AI-generated attacks. AI-generated phishing or other communications accounted for 17% of attacks. AI-driven attacks have an increased financial impact, adding around $1 million to average data breach costs. Most AI-driven attacks targeted critical infrastructure, with the financial services and energy sectors the most targeted.

There has also been an increase in shadow AI incidents – AI applications used by employees that have not been approved for use. Incidents more than doubled to 43% of security incidents this year from 20% last year. IBM notes a lack of governance policies to mitigate or manage the risk to AI, with only around one third of organizations having a strict approval for deploying AI tools. The average breach cost was $5.39 million, and one in five of these breaches resulted in a regulatory fine.

There is growing concern about new threats from frontier AI models. Out of all breached organizations, 85% of organizations that were aware of frontier models said they were increasing their security spending to combat the threat. IBM notes that experts believe that AI will favor attackers over defenders by 31.7% within two years, highlighting the pressing need for speed in security.

While organizations are adopting AI for security, most are only using AI agents for detection and containment. Only a small fraction use AI agents for vulnerability management. That means exposures are available for exploitation for much longer, and given that attackers are using AI tools for vulnerability discovery, this is one of the key areas where organizations can make significant security gains. IBM recommends leveraging AI to analyze exposures, enforce policies, and coordinate detection and containment with minimal human intervention.

Ransomware attacks have continued to increase due to ransomware-as-a-service. Over the past 12 months, 39% of breached organizations said they experienced at least one ransomware attack, up from 24% in 2023 – a 62.5% increase over the past four years.  Attackers are increasingly threatening public shaming and data leaks to pressure victims into paying, rather than simply encrypting files. In 2026, 41% of ransomware attacks included brand reputation threats, such as data leaks and public shaming, with 35% of attacks targeting employee data and health records.

The post Global Data Breach Cost Rises 12% to Almost $5 Million appeared first on The HIPAA Journal.

Study of Healthcare Websites Shows Widespread and Risky Use of Tracking and Analytics Tools

A recent analysis of healthcare websites has revealed that the majority use marketing and analytics tools that could potentially disclose sensitive data to third parties. The study was jointly conducted by Piwik PRO, a privacy-first web analytics platform provider, and Verified Data, an automated audit platform that helps organizations verify analytics accuracy, data quality, and privacy compliance.

Healthcare organizations have faced increased scrutiny of their use of website tracking and analytics tools in recent years, after studies revealed these tools were being routinely used on healthcare websites, in some cases on authenticated pages, and were disclosing sensitive data to third parties. These tools collect and transmit information to third parties about website use, which may include protected health information – personally identifiable health information that HIPAA requires regulated entities to protect. Major HIPAA breaches have been reported to the HHS’ Office for Civil Rights (OCR) related to these tools, including by Advocate Aurora Health, Kaiser Permanente, Novant Health, and Atrium Health.

Patients are increasingly taking legal action over the use of these tools by healthcare providers. Over the past two years, dozens of lawsuits have resulted in settlements to resolve alleged privacy violations. Piwik PRO reports that more than $100 million was paid out in settlements between 2023 and 2025 to resolve healthcare privacy violations due to tracking and analytics tools such as Meta Pixel, Google Analytics, and Microsoft Advertising code.

The Piwik PRO/Verified Data study findings are published in the healthcare website tracking report, Are healthcare companies one audit away from a compliance crisis? The study involved scans of 59 websites of major U.S. hospitals and clinics to assess tracking, consent, and data compliance. The study did not investigate whether protected health information was being disclosed to third parties; rather, it looked for the presence of and behavior of tracking scripts, cookies, advertising pixels, and consent systems.

Concerningly, almost three-quarters (73%) of scanned healthcare websites had active advertising or marketing trackers, even when the Global Privacy Control (GPC) opt-out signal was running. GPC is a browser-based signal that communicates the user’s preference to opt out of the sale or sharing of their personal data to website operators. More than two-thirds of sites (69%) used marketing or advertising cookies, which strongly suggests that data is routed to third-party platforms. The narrow spread between the tracking figure and cookie figure suggests some trackers are likely operating without cookies, which means cookie blocking would not fully prevent exposure. The researchers identified 75 unique tracking tools across the 59 scanned sites, including Google Analytics, Meta Pixel, Microsoft Advertising and session replay technologies.

Over the years, The HIPAA Journal has observed improved education about HIPAA, with patients now having a much better understanding of what HIPAA protects, what it does not, and the rights HIPAA gives them. Patients expect privacy when they visit their healthcare providers, and those expectations extend to their providers’ digital presence. When they visit a healthcare website and search for information about sensitive health matters, book appointments, or disclose their information in forms, they expect that information to be kept private and not be disclosed to third parties such as social media companies and advertising networks, yet these tools have been doing that for years.

“This isn’t a story about reckless marketers or bad intentions. Healthcare organizations often inherit their analytics setup rather than actively choose it. Google Analytics became the default for many because it was free, established, and widely understood. The challenge today is scope creep. What began as website analytics has evolved into broader behavioral ad targeting platforms,” explained Magdalena Pawlitko, Head of Global Sales at Piwik PRO. “In regulated sectors such as healthcare, that creates greater compliance risk and requires much closer scrutiny of how data gathering tools are configured and governed.”

The problem for healthcare providers is that these tools provide important and useful features. While there are regulations governing the use of these tools, healthcare providers do not have to call a halt to their digital marketing campaigns, but they do need to assess their strategy and ensure that they have the right infrastructure in place to ensure compliance and protect patient privacy.

“Patients expect that their health-related behavior stays private when they visit a hospital website. “Meeting that expectation is entirely possible with the right setup – and organizations that get there aren’t just reducing their legal risk. They’re building something more valuable: a digital presence their patients can actually trust. said Brian Clifton, founder of Verified Data and digital analytics and privacy expert.

If not done so already, the researchers recommend that healthcare organizations conduct an audit of their current tracking setup, ensure that advertising pixels on web pages that are PHI-adjacent are removed, that they enforce opt-out signals at the tag management layer, replace non-compliant analytics with a purpose-built platform, and ensure they have compliant infrastructure in place. In addition, the researchers recommend making compliance a standing requirement, rather than a one-off review, ensuring that all compliance-related decisions are fully documented.

The post Study of Healthcare Websites Shows Widespread and Risky Use of Tracking and Analytics Tools appeared first on The HIPAA Journal.

Accenture Confirms Intrusion After Hacker Claims 35GB Data Breach

Accenture, one of the world’s largest consulting firms, has confirmed it has experienced a security breach, shortly after a hacker claimed to have breached its systems and exfiltrated 35GB of data from the company. Accenture has confirmed that it identified the source of the intrusion and remediated the incident, and that it had no impact on its financial position or operations.

Accenture provides professional services to help businesses and governments solve complex problems and assist them with the implementation of new technologies, cloud migrations, along with managed services to help them run day-to-day business processes. Its client list includes many Fortune 500 companies.

On July 6, 2026, a cybercriminal hacker with the handle “888” added a post titled “Accenture Data Breach” to a cybercrime forum claiming to have stolen 35 GB of data including source code, RSA keys, SSH keys, Azure Personal Access Tokens (PATs), Azure Storage access keys, configuration files, and other data. The hacker was offering the data for sale, requesting payment in the Monero digital currency. The post included a screenshot as proof of data theft.

While Accenture has confirmed that there was an intrusion, the company has not stated whether the attacker’s claims are genuine or provided any further information about the nature of the incident. This is not the first time the hacker has attempted to sell data stolen from Accenture, having listed data for sale that had been stolen in a third-party incident in 2024.

In that instance, the hacker claimed to be selling sensitive data, including the personally identifiable information of more than 30,000 employees, although Accenture said at the time that the hacker’s claims were vastly exaggerated, and only included the data of around three of its employees. The latest data theft claim may also have been exaggerated; however, if genuine, the highly sensitive nature of the stolen data will be a major cause of concern, potentially impacting the company’s clients and partners.

The post Accenture Confirms Intrusion After Hacker Claims 35GB Data Breach appeared first on The HIPAA Journal.