Defensorum

@defensorum
4 Followers
4 Following
165 Posts
All IT Security News!
Websitehttps://www.defensorum.com/
πŸ₯ The Oncology Institute confirms patient data access from vendor breach πŸ“… Initial disclosure November 3, 2025, updated May 20, 2026 πŸ”’ Unauthorized system-level access to patient environments identified πŸ’Š 100+ clinics across 5 states serve 2M patients #DataSecurity #PatientPrivacy #Healthcare #DataBreach πŸ‘‰ https://www.defensorum.com/the-oncology-institute-patients-data-breach/
Exposure of The Oncology Institute Patients' Data Linked to Third-Party Vendor Breach - Defensorum

The Oncology Institute confirmed that patient data was potentially accessed following unauthorized access to its systems related to a cybersecurity incident at a third-party vendor affecting healthcare data processing and related services. SEC Filing Disclosure and Initial Incident Findings The Oncology Institute, a publicly traded cancer care provider operating more than 100 clinics across California, ... Read more

Defensorum
βš–οΈ Delta Home Health Care owner sentenced in #Medicare fraud case πŸ’΅ Fraudulent billing at center of investigationπŸ’° Illegal kickbacks and referral scheme tied to false claims #Healthcare #Compliance #DOJ πŸ‘‰ https://www.defensorum.com/delta-home-health-care-medicare-fraud-and-illegal-kickback-scheme/
Delta Home Health Care Owner Convicted in Medicare Fraud and Illegal Kickback Scheme - Defensorum

Ruby Scott, owner and operator of Delta Home Health Care LLC in Michigan, was convicted by a federal jury on charges related to healthcare fraud and illegal healthcare kickbacks connected to a scheme that caused more than $1.6 million in losses to the Medicare program. Scott, 55, of Farmington Hills, Michigan, was found guilty in ... Read more

Defensorum
🚨 Former #Nuance employee accessed 1.2M+ #Geisinger patient records after termination ⚠️ Exposed data included names, DOBs, medical record numbers & patient admission details πŸ“‰ Case highlights risks of weak offboarding controls #DataBreach #Healthcare #CyberSecurity #HIPAA #PrivacyπŸ‘‰ https://www.defensorum.com/nuance-communications-employee-data-breach/
Nuance Communications Employee Sentenced for Data Breach Violation - Defensorum

A former employee of Nuance Communications has been sentenced for illegally accessing and copying the sensitive data of approximately 1.2 million Geisinger Health System patients after he was terminated from employment. Max Vance, 46 years old, now known as Andre J. Burk of El Cajon, California, worked as a principal healthcare engineer for Nuance Communications, ... Read more

Defensorum
🚨 AI discovers 38 OpenEMR vulnerabilities including two CVSS 10.0 critical flaws πŸ₯ Platform serves 100,000+ HIPAA providers, 200M patients globally πŸ’» Remote code execution and unauthenticated access possible πŸ›‘οΈ All issues remediated before exploitation #PatientData #Healthcare #CyberSecurity πŸ‘‰https://www.defensorum.com/ai-vulnerabilities-openemr/
AI Finds 38 Vulnerabilities in OpenEMR Platform - Defensorum

An automated analysis of the OpenEMR electronic medical records platform identified 38 previously unknown vulnerabilities, including two highest severity vulnerabilities rated CVSS 10.0, with potential impact on patient data integrity, system access, and server-level compromise. Vulnerability Findings The analysis identified 39 vulnerabilities that are included in the GitHub Security Advisory vulnerabilities for Q1, 2026. The ... Read more

Defensorum
🚨 #OPM proposal requires monthly claims-level data from 65 carriers πŸ“Š 8M+ federal employees, retirees, families affected ⚠️ #HIPAA Minimum Necessary Rule compliance concerns raised πŸ₯ Proposal lacks clear limitations on #PHI data elements #Compliance #DataPrivacy #RegulatoryRisk #PrivacyRule πŸ‘‰https://www.defensorum.com/opm-health-data-collection-hipaa/
OPM Health Data Collection Proposal Raises HIPAA Compliance and Privacy Concerns - Defensorum

The Office of Personnel Management proposal to collect claims-level health insurance data for federal employees and retirees has generated sustained criticism due to privacy risks, potential violations of the HIPAA Privacy Rule, and concerns about data misuse and insufficient safeguards. Proposal Scope and Data Collection Requirements A December 12, 2025 notice outlines a request to ... Read more

Defensorum
πŸ₯ #HSCC releases 109-page AI risk management guidance for healthcare πŸ€– Addresses third-party AI tools in EHRs and remote monitoring πŸ“Š Framework scales across organizations of all sizes πŸ“ Updates to #HIPAA training programs recommended #AI #Healthcare #CyberSecurity #Compliance πŸ‘‰ https://www.defensorum.com/hscc-guidance-third-party-ai-risks-healthcare/
HSCC Guidance on Managing Third Party AI Risks Issued to Healthcare Organizations - Defensorum

The Health Sector Coordinating Council Cybersecurity Working Group has issued a 109-page guidance document to assist healthcare organizations in managing risks associated with third-party artificial intelligence tools and AI-related supply chains. Guidance Scope And Purpose The document, titled Health Industry Third-Party AI Risk and Supply Chain Transparency Guide, addresses the growing reliance of healthcare organizations ... Read more

Defensorum
πŸ₯ Concord Orthopaedics settles breach affecting 72,815 patients πŸ’³ SSNs, driver's licenses, insurance information exposed πŸ“‹ Five lawsuits consolidated with 12 class representatives ⚠️ Settlement provides medical data monitoring for all eligible individuals #DataBreach #Healthcare #PatientRights πŸ‘‰ https://www.defensorum.com/concord-orthopaedics-data-breach-lawsuit/
Concord Orthopaedics Settles Class Action Data Breach Lawsuit - Defensorum

Concord Orthopaedics Professional Association has agreed to a settlement to resolve consolidated class action litigation arising from a November 2024 cybersecurity incident that involved unauthorized access to the personal and protected health information (PHI) of 72,815 individuals. Incident Overview Concord Orthopaedics Professional Association, based in New Hampshire, identified unauthorized access to its computer network on ... Read more

Defensorum
πŸ₯ Healthcare organizations face ransomware threat from #NetScaler flaws ⚠️ Dual NetScaler vulnerabilities disclosed same week 🚨 CVE-2026-3055 vulnerability scores CVSS 9.3 πŸ“Š CVE-2026-4368 race condition scores CVSS 7.7 πŸ“± Remote access and VPN services at elevated risk πŸ’Š Covered entities must treat remediation as high priority #Healthcare #CyberSecurity #Network πŸ‘‰ https://www.defensorum.com/citrix-vulnerabilities-netscaler-adc-netscaler-gateway/
Citrix Disclosed Vulnerabilities Affecting NetScaler ADC and NetScaler Gateway - Defensorum

Citrix disclosed a vulnerability tracked as CVE-2026-3055 in NetScaler ADC and NetScaler Gateway that can produce a memory overread whenever the application is configured as a SAML identity provider and that has a CVSS v4 severity score of 9.3. Details of the Vulnerability The flaw occurs in NetScaler ADC and NetScaler Gateway when configuring them ... Read more

Defensorum
πŸ₯ #Deaconess Health System reports #MediCopy vendor breach πŸ“ Unauthorized access to cloud file-sharing platform 🏒 MediCopy manages ROI requests for 18-hospital system πŸ’³ SSNs, medical records, insurance information downloaded πŸ’³ Credit monitoring and identity theft protection offered #Healthcare #DataProtection #HIPAA πŸ‘‰ https://www.defensorum.com/medicopy-data-breach-deaconess-health-system/
MediCopy Data Breach Impacts Deaconess Health System - Defensorum

Deaconess Health System reported a data breach involving patient information shared with a third-party vendor, MediCopy, following unauthorized access to a cloud-based file-sharing platform. Incident Overview Deaconess Health System, based in Evansville, Indiana, disclosed a security incident affecting certain patients of Deaconess Union County Hospital in Morganfield, Kentucky and Deaconess Henderson Hospital in Henderson, Kentucky. ... Read more

Defensorum
🚨 #CISA issues emergency guidance after 12 PB deleted from 200K devices πŸ’» Iran-linked #Handala group exploited #Microsoft #Intune admin controls πŸ“± #Windows devices, laptops, mobile phones targeted for deletion #CyberSecurity #CloudSecurity #ZeroTrust πŸ‘‰ https://www.defensorum.com/cisa-administrative-controls-microsoft-intune/
CISA Recommends Strict Administrative Controls of Microsoft Intune - Defensorum

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued guidance instructing U.S. organizations to strengthen administrative controls in Microsoft Intune following a cyberattack on Stryker Corporation that involved data exfiltration and substantial data deletion. Incident Overview The incident involved Stryker Corporation, a U.S.-based medical technology company. A threat actor known as Handala is behind ... Read more

Defensorum