Hidden Signs of a Healthcare Data Breach

Healthcare data breaches can be costly, difficult to resolve, and dangerous for patients. Yet despite the best preventative practices, breaches can still happen, underscoring the critical need for prompt detection and response. As healthcare organizations are responsible for safeguarding private patient data, swiftly identifying signs of a data breach is essential. If such sensitive information […]

Data Breach Lawsuits on the Rise: Is Your Healthcare Organization Prepared?

  In addition to the rise in cyber attacks against hospitals and health systems, another alarming trend is the rise in lawsuits against healthcare organizations following a breach. Some recent examples include: While these are some of the higher-profile lawsuits in the industry, organizations of all sizes are facing legal action for data exposure. Lawsuits stem […]

February 2026 CISO Brief: Privacy Deadlines, Clinical Impact, and Persistent Attack Paths

As healthcare organizations move closer to the February 16, 2026, compliance deadline for the updated 42 CFR Part 2 requirements, they are doing so in an environment defined by persistent ransomware activity, slow remediation of known exploited vulnerabilities, expanding clinical attack surfaces, and growing use of unmanaged technologies. This month’s Brief focuses on how these […]

Preparation Changes Outcomes In Ransomware Attacks

In our latest webinar, we conducted a Red Team/Blue Team post-mortem on a real ransomware attack that occurred last year at Frederick Health Medical Group in Maryland. The system has more than 4,000 clinicians and staff across 25 locations. The Frederick Health attack exposed more than 900,000 patient records and hampered operations for a number […]

Healthcare Data Privacy: What Industry Signals Reveal About Deeper Cybersecurity Risk

During Data Privacy Week, healthcare leaders have the chance to go beyond awareness messaging. They can closely examine how patient data is accessed, shared, and protected. Healthcare data privacy often focuses on compliance through policies, training, and regulations. However, the real risk comes from how data flows across systems, vendors, and people in the interconnected […]

2026 Horizon Report: The New Reality of Healthcare Cybersecurity

Healthcare cybersecurity has entered a new phase. The era of isolated, headline-grabbing mega-breaches is giving way to something more demanding and more dangerous: constant disruption. In 2025, healthcare organizations experienced significantly more cyber incidents than the year before, yet those breaches affected fewer patient records overall. On the surface, that might sound like progress. In […]

When Cyber Threats Hit Rural Hospitals: Lessons from the Front Lines

A savvy CEO leads a rural hospital through a cybersecurity crisis Cybersecurity attacks on rural hospitals are no longer a question of “if,” but “when.” For Mount Desert Island Hospital in Bar Harbor, Maine, that moment came during Chrissi Maguire’s tenure as CEO. A longtime financial and operational leader turned hospital chief, Maguire had to […]

5 Ways to Strengthen the Cyber Conversation with CFOs

Cybersecurity isn’t just a technical conversation anymore; it’s a financial one. In healthcare, the cost of cyber risk is measured not only in terms of breached records or downtime, but also in canceled procedures, delayed reimbursements, and long-term reputational damage. When patient safety and solvency are both at stake, CISOs and CFOs must operate as […]

CISO Brief: A Look Back at Healthcare Cybersecurity in 2025, A Year Defined by Disruption

As 2025 comes to a close, it’s impossible not to view the year through a wide-angle lens. Healthcare cybersecurity in 2025 did not follow a clean, predictable arc. Instead, it delivered a series of sharp turns, unexpected pivots, and both hard-earned wins and hard-learned lessons. If 2024 felt volatile, 2025 reaffirmed that volatility is now the default operating […]

Inside a Healthcare Ransomware Battle: How Preparation Saved Patients

With 25 years in cybersecurity, including experience at the Department of Defense and National Security Agency, Phil Alexander has seen the full spectrum of cyber threats. Since founding his consultancy and working extensively with healthcare organizations, he’s gained unique insights into the industry’s specific vulnerabilities and the most effective strategies to address them. His experience […]