Nexus Intelligence
What is changing in healthcare AI, and why it matters. Eight lenses — threats, healthcare breach intelligence (Canada · United States · Caribbean), regulation, workforce, crisis, biosecurity, quantum risk, and the sovereignty movement — each item separated into the source fact, Nexus analysis, and the review it should trigger.
Public terminal. Sourced items are stated as the cited source reports them; analysis blocks are Nexus editorial inference and are labelled as such. Signed-in workspaces add organization-specific intelligence preferences and link items to your own controls.
How to read this terminal: labels, sources, and the threat-level method
What kind of statement is this?
- FACT
- A reported event or published document, stated as the cited source reports it.
- INFERENCE
- Nexus analysis of what the facts mean for healthcare AI governance. Reasoned, attributable, revisable.
- FORECAST
- A forward-looking expectation. Never presented as a fact; always attributed to Nexus analysis.
Each card separates the source fact (what the cited source reports) from Nexus analysis (what we think it means) and a recommended review (what a governance team should check). Analysis is editorial and attributable to Nexus; it is never presented as fact.
How urgent is it?
- FLASH
- A discrete, dated event with direct healthcare impact (breach, ransomware, regulation in force, outbreak). Recency-weighted into the threat level for 90 days.
- PRIORITY
- Material development or standing condition that should reach the governance agenda this cycle. Weighted into the threat level for 90 days at a lower rate than FLASH.
- ROUTINE
- Background context, standing facts, or slow-moving trends. Never moves the threat level.
Where is it in its life?
- LIVE
- Published by the daily collection agent since the last editorial refresh. Live items are collected and de-duplicated automatically; editorial review has not yet been recorded.
- ACTIVE
- Currently tracked. The situation is ongoing or its consequences are still unfolding.
- RESOLVED
- Closed by the source, or auto-resolved after 14 days without an update. Kept for the historical record, collapsed by default.
- STALE
- No update from any source in 30 days. Treat the details as possibly out of date.
How can I verify it?
- PRIMARY SOURCE
- Linked directly to the regulator, agency, vendor disclosure, or standards body that originated the information.
- SECONDARY SOURCE
- Linked to reputable reporting about the event rather than the originating body.
- SOURCE LINKED
- A source link is provided; primary/secondary tier has not been recorded for this item.
- SOURCE CITED · NO LINK
- The source is named but no link is recorded. Verify with the named source before acting.
- NEXUS TRACKING
- Derived from Nexus's own workforce or signal collection rather than an external publication.
- HUMAN REVIEWED
- An editor has reviewed the item against its source.
- REVIEW PENDING
- Collected automatically; editorial review has not yet been recorded.
Confidence scores, validation status, and human-review state appear only when a feed genuinely records them. When they are absent, they are absent — Nexus does not invent them.
How is the threat level calculated?
- FLASH within 7 days: 3 points · FLASH within 90 days: 2 points · older FLASH: 0.5
- PRIORITY within 90 days: 1 point · older PRIORITY: 0.25
- ROUTINE: 0 points
- CRITICAL
- Three or more FLASH items inside the last 7 days — a live cluster, right now.
- ELEVATED
- At least one FLASH item inside 7 days, or a weighted score of 8 or more. The news-rich resting state.
- GUARDED
- Weighted score of 3 or more with no FLASH in the last 7 days.
- LOW
- Weighted score below 3.
The threat level is an editorial urgency gauge over items in this terminal. It is not a probability, not a prediction, and not calibrated against incident outcomes. Use it to decide what to read first, not whether you are safe.
Healthcare Breach Intelligence
Canada · United States · Caribbean
Evidence-backed breach records normalized for trend analysis while keeping each jurisdiction's own terminology. Reporting regimes differ: U.S. PHI reporting is structured through HHS OCR; Canadian reporting is distributed across federal and provincial sources; Caribbean reporting is jurisdiction-specific and fragmented.
| Organization | Where | Affected | Data (jurisdiction term) | Type | Disclosed | Verification |
|---|---|---|---|---|---|---|
| XsolisBusiness associate · AI utilization-management vendorReported to OCR in June 2026 as affecting almost 1.4 million individuals (business-associate report). Incident date not publicly established by the sources on file; the count is 'almost 1.4M' per the secondary source.NEXUS ANALYSIS · INFERENCE An AI vendor's breach becomes its hospital customers' breach; custodianship does not transfer with the data. | TNUnited States · United States · HIPAA Breach Notification Rule | 1,400,000 | PHIprotected health information (PHI) | Hacking / IT incidentthird party | 2026-06 | source verifiedHIPAA Journal — June 2026 healthcare data breach report (secondary) ↗collected 2026-09-09 · verified 2026-09-10 |
| TriZetto Provider Solutions (Cognizant)Business associate · Revenue cycle managementDescribed as the largest breach report filed with OCR in 2026 to date (February 2026). The affected count is not on file in Nexus and is left null rather than estimated. | NJUnited States · United States · HIPAA Breach Notification Rule | Not available | PHIprotected health information (PHI) | Hacking / IT incidentthird party | 2026-02 | source verifiedTechTarget — biggest healthcare breaches reported to OCR in 2026 (secondary) ↗collected 2026-09-09 · verified 2026-09-10 |
| Blue Shield of CaliforniaHealth plan / insurer · Nonprofit health planSharing ran from April 2021 to January 2024 per the notice; discovered 2025-02-11; no SSNs, driver's licence numbers, or banking information involved per Blue Shield.NEXUS ANALYSIS · INFERENCE The largest U.S. health-plan disclosure of 2025 required no intrusion. Governance of web tags is a privacy control, and under CMIA the advertising vendor is a contractor. | CAUnited States · United States · HIPAA Breach Notification Rule · California CMIA and Civil Code § 1798.82 | 4,700,000 | PHIprotected health information (HIPAA) · medical information (CMIA) | Unauthorized access / disclosurethird party · Google (Analytics / Ads) | 2025-04-09 | source verifiedHIPAA Journal — Blue Shield of California impermissible disclosure to Google Ads (secondary) ↗collected 2026-09-09 · verified 2026-09-10 |
| AscensionHealth system · Multi-state hospital systemBlack Basta ransomware forced paper charting across ~140 hospitals; ambulance diversions and postponed procedures were reported. | MOUnited States · United States · HIPAA Breach Notification Rule | 5,599,699 | PHIprotected health information (PHI) | Ransomware | 2024-12 | source verifiedAscension — network interruption update (official notice) ↗collected 2026-09-09 · verified 2026-09-10 |
| Kaiser Foundation Health PlanHealth plan / insurer · Integrated health planOnline tracking technologies transmitted member information to third-party vendors. Kaiser stated the data did not include usernames, passwords, SSNs, or financial information.NEXUS ANALYSIS · INFERENCE No attacker was involved: analytics and advertising tags disclosed member information by configuration. Under CMIA that is a contractor-disclosure question, not only a HIPAA one. | CAUnited States · United States · HIPAA Breach Notification Rule · California CMIA and Civil Code § 1798.82 | 13,400,000 | PHIprotected health information (HIPAA) · medical information (CMIA) | Unauthorized access / disclosurethird party | 2024-04 | registry listedHHS OCR breach portal (Kaiser Foundation Health Plan, Inc.) ↗collected 2026-09-09 · verified 2026-09-10 |
| Change Healthcare (UnitedHealth Group)Business associate · Claims clearinghouse / revenue cycleALPHV/BlackCat ransomware disrupted U.S. claims and pharmacy processing for weeks. OCR's posted count was revised upward during 2025; the figure here is the last published portal figure known to Nexus.NEXUS ANALYSIS · INFERENCE A single clearinghouse became a systemic dependency for the whole sector; the breach reached organizations whose own perimeters were never touched. | TNUnited States · United States · HIPAA Breach Notification Rule | 192,700,000 | PHIprotected health information (PHI) | Ransomwarethird party | 2024-02-21 | source unreachableHHS OCR — Change Healthcare cybersecurity incident FAQ ↗collected 2026-09-09 · verified 2026-09-10 |
| Norton HealthcareHealth system · Regional hospital system | KYUnited States · United States · HIPAA Breach Notification Rule | 2,500,000 | PHIprotected health information (PHI) | Ransomware | 2023-12 | registry listedHHS OCR breach portal (Norton Healthcare) ↗collected 2026-09-09 · verified 2026-09-10 |
| ESO SolutionsBusiness associate · EMS / fire software vendor | TXUnited States · United States · HIPAA Breach Notification Rule | 2,700,000 | PHIprotected health information (PHI) | Ransomwarethird party | 2023-12 | registry listedHHS OCR breach portal (ESO Solutions) ↗collected 2026-09-09 · verified 2026-09-10 |
| WelltokBusiness associate · Patient engagement platformMOVEit Transfer zero-day (Cl0p) exploited at a business associate serving many health plans. | COUnited States · United States · HIPAA Breach Notification Rule | 8,493,379 | PHIprotected health information (PHI) | Third-party / supply chainthird party · Progress Software (MOVEit Transfer) | 2023-11 | registry listedHHS OCR breach portal (Welltok, Inc.) ↗collected 2026-09-09 · verified 2026-09-10 |
Methodology, sources, and coverage limitations
Reporting regimes
- CANADA
- Distributed: mandatory breach reporting exists federally (PIPEDA) and under provincial health-privacy statutes (e.g., Ontario PHIPA, Alberta HIA, Newfoundland and Labrador PHIA), but there is no single public registry. Records come from federal/provincial commissioners, government disclosures, and organization statements, so counts are less complete and less comparable.
- UNITED STATES
- Structured: HIPAA-covered entities and business associates must report breaches of protected health information affecting 500+ individuals to HHS OCR, which publishes them on the breach portal. Counts, entity type, breach type, and information location are comparable across records.
- CARIBBEAN
- Jurisdiction-specific and fragmented: data-protection laws (e.g., Jamaica 2020, Barbados 2019, Trinidad and Tobago 2011 partially proclaimed) differ in scope, terminology, and enforcement; several regulators are new. Puerto Rico and the U.S. Virgin Islands fall under HIPAA/HHS OCR. Public disclosure is often via press or ministry statements, so coverage is incomplete and terminology is preserved per jurisdiction.
Nexus normalizes each record to one analytic category (`data_type`) for counting only, and keeps the source jurisdiction's own terminology on the record. A data class is never inferred from the victim being a healthcare organization; when it is not publicly established the record says UNKNOWN_NOT_DISCLOSED.
Verification states
- SOURCE_VERIFIED
- Source verified
- EDITORIAL
- Editorially seeded — source not yet re-verified
- REGISTRY_LISTED
- Listed in an official registry (registry-level link)
- SOURCE_UNREACHABLE
- Source could not be reached at last check
- UNVERIFIED
- Unverified
Verification: 4 incident pages verified · 4 registry-level · 0 editorial · 1 unreachable at last check (in filter).
Coverage limitations
- This is not a complete registry. United States records at registry scale arrive through the HHS OCR CSV adapter; until an export is imported, U.S. coverage is the editorially seeded set.
- Canadian reporting is distributed across federal and provincial commissioners with no single public list; counts are less complete and less comparable than U.S. counts.
- Caribbean records are jurisdiction-specific and few. Puerto Rico and the U.S. Virgin Islands report under HIPAA; independent states report under their own data-protection laws, several of which are new or partially proclaimed.
- Affected-individual counts are as publicly reported and may be revised by the source; unknown counts are null and excluded from totals and medians.
- A period filter excludes records with no disclosure, incident, or publication date.
- Percentages are suppressed when fewer than five records are in the filter.
Sources implemented
- United States — HHS OCR breach portal (CSV export adapter; registry-level), HHS OCR enforcement announcements and organization disclosures (editorial records).
- Canada — federal and provincial privacy commissioners, provincial government disclosures, organization notices (editorial records; no single public registry exists).
- Caribbean — HHS OCR for U.S. territories; ministry/press statements for independent states (editorial records; regulator statements recorded where located).