U.S. federal authorities and industry officials are urging hospitals and clinics to address a critical flaw in BeyondTrust Remote Support and Privileged Remote Access software, which if exploited, could give an attacker a foothold inside a corporate network. The U.S. Department of Health and Human Services in an alert Thursday warned healthcare and public health sector organizations to review and address the vulnerability in light of rising cyberattacks targeting those entities.
In 2025, the frequency of healthcare data breaches more than doubled. However, the number of patient records exposed has significantly decreased, indicating a shift in the data breach landscape, according to a new report from Fortified Health Security.
Healthcare organizations are increasingly being targeted in email attacks, research shows, and Microsoft 365 is often the weakest link. More than half (52%) of all healthcare email breaches last year involved the Microsoft 365 business email platform, up from 43% the year before. According to research from Paubox, there were 107 such attacks in the first half of this year.
The healthcare landscape has undergone massive digital transformation since 1996 when the Health Insurance Portability and Accountability Act (HIPAA) was first enacted. We now face a surge in sophisticated cyberattacks powered by artificial intelligence (AI). According to recent data, nearly half of healthcare organizations experienced a higher volume of attacks than just a year ago, but only 29% feel prepared for AI-driven threats like deepfakes and synthetic identity fraud.