π₯ The Oncology Institute confirms patient data access from vendor breach π
Initial disclosure November 3, 2025, updated May 20, 2026 π Unauthorized system-level access to patient environments identified π 100+ clinics across 5 states serve 2M patients
#DataSecurity #PatientPrivacy #Healthcare #DataBreach π
https://www.defensorum.com/the-oncology-institute-patients-data-breach/
Exposure of The Oncology Institute Patients' Data Linked to Third-Party Vendor Breach - Defensorum
The Oncology Institute confirmed that patient data was potentially accessed following unauthorized access to its systems related to a cybersecurity incident at a third-party vendor affecting healthcare data processing and related services. SEC Filing Disclosure and Initial Incident Findings The Oncology Institute, a publicly traded cancer care provider operating more than 100 clinics across California, ... Read more
DefensorumβοΈ Delta Home Health Care owner sentenced in
#Medicare fraud case π΅ Fraudulent billing at center of investigationπ° Illegal kickbacks and referral scheme tied to false claims
#Healthcare #Compliance #DOJ π
https://www.defensorum.com/delta-home-health-care-medicare-fraud-and-illegal-kickback-scheme/
Delta Home Health Care Owner Convicted in Medicare Fraud and Illegal Kickback Scheme - Defensorum
Ruby Scott, owner and operator of Delta Home Health Care LLC in Michigan, was convicted by a federal jury on charges related to healthcare fraud and illegal healthcare kickbacks connected to a scheme that caused more than $1.6 million in losses to the Medicare program. Scott, 55, of Farmington Hills, Michigan, was found guilty in ... Read more
Defensorumπ¨ Former
#Nuance employee accessed 1.2M+
#Geisinger patient records after termination β οΈ Exposed data included names, DOBs, medical record numbers & patient admission details π Case highlights risks of weak offboarding controls
#DataBreach #Healthcare #CyberSecurity #HIPAA #Privacyπ
https://www.defensorum.com/nuance-communications-employee-data-breach/
Nuance Communications Employee Sentenced for Data Breach Violation - Defensorum
A former employee of Nuance Communications has been sentenced for illegally accessing and copying the sensitive data of approximately 1.2 million Geisinger Health System patients after he was terminated from employment. Max Vance, 46 years old, now known as Andre J. Burk of El Cajon, California, worked as a principal healthcare engineer for Nuance Communications, ... Read more
Defensorumπ¨ AI discovers 38 OpenEMR vulnerabilities including two CVSS 10.0 critical flaws π₯ Platform serves 100,000+ HIPAA providers, 200M patients globally π» Remote code execution and unauthenticated access possible π‘οΈ All issues remediated before exploitation
#PatientData #Healthcare #CyberSecurity π
https://www.defensorum.com/ai-vulnerabilities-openemr/
AI Finds 38 Vulnerabilities in OpenEMR Platform - Defensorum
An automated analysis of the OpenEMR electronic medical records platform identified 38 previously unknown vulnerabilities, including two highest severity vulnerabilities rated CVSS 10.0, with potential impact on patient data integrity, system access, and server-level compromise. Vulnerability Findings The analysis identified 39 vulnerabilities that are included in the GitHub Security Advisory vulnerabilities for Q1, 2026. The ... Read more
Defensorumπ¨
#OPM proposal requires monthly claims-level data from 65 carriers π 8M+ federal employees, retirees, families affected β οΈ
#HIPAA Minimum Necessary Rule compliance concerns raised π₯ Proposal lacks clear limitations on
#PHI data elements
#Compliance #DataPrivacy #RegulatoryRisk #PrivacyRule π
https://www.defensorum.com/opm-health-data-collection-hipaa/
OPM Health Data Collection Proposal Raises HIPAA Compliance and Privacy Concerns - Defensorum
The Office of Personnel Management proposal to collect claims-level health insurance data for federal employees and retirees has generated sustained criticism due to privacy risks, potential violations of the HIPAA Privacy Rule, and concerns about data misuse and insufficient safeguards. Proposal Scope and Data Collection Requirements A December 12, 2025 notice outlines a request to ... Read more
Defensorumπ₯
#HSCC releases 109-page AI risk management guidance for healthcare π€ Addresses third-party AI tools in EHRs and remote monitoring π Framework scales across organizations of all sizes π Updates to
#HIPAA training programs recommended
#AI #Healthcare #CyberSecurity #Compliance π
https://www.defensorum.com/hscc-guidance-third-party-ai-risks-healthcare/
HSCC Guidance on Managing Third Party AI Risks Issued to Healthcare Organizations - Defensorum
The Health Sector Coordinating Council Cybersecurity Working Group has issued a 109-page guidance document to assist healthcare organizations in managing risks associated with third-party artificial intelligence tools and AI-related supply chains. Guidance Scope And Purpose The document, titled Health Industry Third-Party AI Risk and Supply Chain Transparency Guide, addresses the growing reliance of healthcare organizations ... Read more
Defensorumπ₯ Concord Orthopaedics settles breach affecting 72,815 patients π³ SSNs, driver's licenses, insurance information exposed π Five lawsuits consolidated with 12 class representatives β οΈ Settlement provides medical data monitoring for all eligible individuals
#DataBreach #Healthcare #PatientRights π
https://www.defensorum.com/concord-orthopaedics-data-breach-lawsuit/
Concord Orthopaedics Settles Class Action Data Breach Lawsuit - Defensorum
Concord Orthopaedics Professional Association has agreed to a settlement to resolve consolidated class action litigation arising from a November 2024 cybersecurity incident that involved unauthorized access to the personal and protected health information (PHI) of 72,815 individuals. Incident Overview Concord Orthopaedics Professional Association, based in New Hampshire, identified unauthorized access to its computer network on ... Read more
Defensorumπ₯ Healthcare organizations face ransomware threat from
#NetScaler flaws β οΈ Dual NetScaler vulnerabilities disclosed same week π¨ CVE-2026-3055 vulnerability scores CVSS 9.3 π CVE-2026-4368 race condition scores CVSS 7.7 π± Remote access and VPN services at elevated risk π Covered entities must treat remediation as high priority
#Healthcare #CyberSecurity #Network π
https://www.defensorum.com/citrix-vulnerabilities-netscaler-adc-netscaler-gateway/
Citrix Disclosed Vulnerabilities Affecting NetScaler ADC and NetScaler Gateway - Defensorum
Citrix disclosed a vulnerability tracked as CVE-2026-3055 in NetScaler ADC and NetScaler Gateway that can produce a memory overread whenever the application is configured as a SAML identity provider and that has a CVSS v4 severity score of 9.3. Details of the Vulnerability The flaw occurs in NetScaler ADC and NetScaler Gateway when configuring them ... Read more
Defensorumπ₯
#Deaconess Health System reports
#MediCopy vendor breach π Unauthorized access to cloud file-sharing platform π’ MediCopy manages ROI requests for 18-hospital system π³ SSNs, medical records, insurance information downloaded π³ Credit monitoring and identity theft protection offered
#Healthcare #DataProtection #HIPAA π
https://www.defensorum.com/medicopy-data-breach-deaconess-health-system/
MediCopy Data Breach Impacts Deaconess Health System - Defensorum
Deaconess Health System reported a data breach involving patient information shared with a third-party vendor, MediCopy, following unauthorized access to a cloud-based file-sharing platform. Incident Overview Deaconess Health System, based in Evansville, Indiana, disclosed a security incident affecting certain patients of Deaconess Union County Hospital in Morganfield, Kentucky and Deaconess Henderson Hospital in Henderson, Kentucky. ... Read more
Defensorumπ¨
#CISA issues emergency guidance after 12 PB deleted from 200K devices π» Iran-linked
#Handala group exploited
#Microsoft #Intune admin controls π±
#Windows devices, laptops, mobile phones targeted for deletion
#CyberSecurity #CloudSecurity #ZeroTrust π
https://www.defensorum.com/cisa-administrative-controls-microsoft-intune/
CISA Recommends Strict Administrative Controls of Microsoft Intune - Defensorum
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued guidance instructing U.S. organizations to strengthen administrative controls in Microsoft Intune following a cyberattack on Stryker Corporation that involved data exfiltration and substantial data deletion. Incident Overview The incident involved Stryker Corporation, a U.S.-based medical technology company. A threat actor known as Handala is behind ... Read more
Defensorum