NEXUSBY CYBERCHAIN TECHNOLOGIES

Nexus Intelligence

What is changing in healthcare AI, and why it matters. Eight lenses — threats, healthcare breach intelligence (Canada · United States · Caribbean), regulation, workforce, crisis, biosecurity, quantum risk, and the sovereignty movement — each item separated into the source fact, Nexus analysis, and the review it should trigger.

Public terminal. Sourced items are stated as the cited source reports them; analysis blocks are Nexus editorial inference and are labelled as such. Signed-in workspaces add organization-specific intelligence preferences and link items to your own controls.

THREAT LEVEL: CRITICAL3 FLASH signals past 7 days · 16 active tracked items (180 days) · 7 feedsEditorial urgency gauge, not a probability · how it is calculated
How to read this terminal: labels, sources, and the threat-level method

What kind of statement is this?

FACT
A reported event or published document, stated as the cited source reports it.
INFERENCE
Nexus analysis of what the facts mean for healthcare AI governance. Reasoned, attributable, revisable.
FORECAST
A forward-looking expectation. Never presented as a fact; always attributed to Nexus analysis.

Each card separates the source fact (what the cited source reports) from Nexus analysis (what we think it means) and a recommended review (what a governance team should check). Analysis is editorial and attributable to Nexus; it is never presented as fact.

How urgent is it?

FLASH
A discrete, dated event with direct healthcare impact (breach, ransomware, regulation in force, outbreak). Recency-weighted into the threat level for 90 days.
PRIORITY
Material development or standing condition that should reach the governance agenda this cycle. Weighted into the threat level for 90 days at a lower rate than FLASH.
ROUTINE
Background context, standing facts, or slow-moving trends. Never moves the threat level.

Where is it in its life?

LIVE
Published by the daily collection agent since the last editorial refresh. Live items are collected and de-duplicated automatically; editorial review has not yet been recorded.
ACTIVE
Currently tracked. The situation is ongoing or its consequences are still unfolding.
RESOLVED
Closed by the source, or auto-resolved after 14 days without an update. Kept for the historical record, collapsed by default.
STALE
No update from any source in 30 days. Treat the details as possibly out of date.

How can I verify it?

PRIMARY SOURCE
Linked directly to the regulator, agency, vendor disclosure, or standards body that originated the information.
SECONDARY SOURCE
Linked to reputable reporting about the event rather than the originating body.
SOURCE LINKED
A source link is provided; primary/secondary tier has not been recorded for this item.
SOURCE CITED · NO LINK
The source is named but no link is recorded. Verify with the named source before acting.
NEXUS TRACKING
Derived from Nexus's own workforce or signal collection rather than an external publication.
HUMAN REVIEWED
An editor has reviewed the item against its source.
REVIEW PENDING
Collected automatically; editorial review has not yet been recorded.

Confidence scores, validation status, and human-review state appear only when a feed genuinely records them. When they are absent, they are absent — Nexus does not invent them.

How is the threat level calculated?

  • FLASH within 7 days: 3 points · FLASH within 90 days: 2 points · older FLASH: 0.5
  • PRIORITY within 90 days: 1 point · older PRIORITY: 0.25
  • ROUTINE: 0 points
CRITICAL
Three or more FLASH items inside the last 7 days — a live cluster, right now.
ELEVATED
At least one FLASH item inside 7 days, or a weighted score of 8 or more. The news-rich resting state.
GUARDED
Weighted score of 3 or more with no FLASH in the last 7 days.
LOW
Weighted score below 3.

The threat level is an editorial urgency gauge over items in this terminal. It is not a probability, not a prediction, and not calibrated against incident outcomes. Use it to decide what to read first, not whether you are safe.

Healthcare Breach Intelligence

Canada · United States · Caribbean

Evidence-backed breach records normalized for trend analysis while keeping each jurisdiction's own terminology. Reporting regimes differ: U.S. PHI reporting is structured through HHS OCR; Canadian reporting is distributed across federal and provincial sources; Caribbean reporting is jurisdiction-specific and fragmented.

RECORDS 25 (8 CA · 14 US · 3 Caribbean)LAST INGESTION no automated ingestion yet · editorial set collected 2026-09-09LAST VERIFICATION 2026-09-10 05:20 UTC · 9 incident pages verifiedSOURCE SET HHS OCR breach portal (6) · HHS OCR — Change Healthcare cybersecurity incident FAQ (1) · Ascension — network interruption update (1) · HIPAA Journal — Blue Shield of California impermissible disclosure to Google Ads (1) · +16COVERAGE not a complete registry — see limitations below

California executive view

What a California health system, health plan, or licensed facility should take from the current record set. Figures are FACT computed from California records in the store (All records); the regulatory stack is reference material verified 2026-09-10; the linkage is INFERENCE. Not legal advice.

California prospect path →
California records
1
FACT · of 1 U.S. records in period · share suppressed — fewer than 5 U.S. records
Californians affected (with counts)
147,267
FACT · 1 of 1 records carry a published count; counts are national totals reported by the organization, not California-resident counts
Confirmed medical information / PHI
1
FACT · 0 not publicly established
Tracking-technology disclosures
0
FACT · disclosures with no attacker (analytics / advertising tags)
Ransomware
1
share suppressed — fewer than 5 records
Third-party
0
share suppressed — fewer than 5 records
Largest California incident
Scripps Health
147,267 · 2021-06
Verification
1 verified · 0 registry
0 unreachable at last check · 0 editorial

California records in period · FACT

OrganizationWhereAffectedData (jurisdiction term)TypeDisclosedVerification
Scripps HealthHealth system · San Diego hospital systemSystems were offline for roughly four weeks with EHR downtime procedures; Scripps stated the core Epic record was not compromised. A class settlement of $3.5 million followed.CAUnited States · United States · HIPAA · California CMIA, Civil Code § 1798.82, Health & Safety Code § 1280.15147,267PII + PHIprotected health information (HIPAA) · medical information (CMIA / H&S § 1280.15)Ransomware2021-06source verifiedHIPAA Journal — Scripps Health ransomware attack notifications (secondary)collected 2026-09-09 · verified 2026-09-10

California regulatory stack · reference, verified 2026-09-10

Confidentiality of Medical Information Act (CMIA)

California Civil Code § 56 et seq. · California Attorney General; private right of action

Term: medical information

State medical-privacy statute that applies to providers, health plans, contractors, and businesses organized to maintain medical information — broader than HIPAA's covered-entity model.

  • Preserve the confidentiality of medical information, including when disclosed to contractors and technology vendors.
  • Statutory damages are available to individuals for negligent release, so exposure is not limited to regulator penalties.

California breach-notification law with Attorney General sample notice

California Civil Code § 1798.82 (and § 1798.29 for agencies) · California Attorney General (publishes the breach list)

Term: personal information (includes medical information and health insurance information)

Requires notice to affected California residents and, when more than 500 residents are affected, submission of a sample notice to the Attorney General, who publishes the breach list.

  • Notify affected California residents in the most expedient time possible and without unreasonable delay.
  • Submit the sample notice to the Attorney General when a single breach affects more than 500 California residents.
  • Use the statute's content requirements for the notice (what happened, what information, what you are doing, what they can do).

Health facility breach reporting to CDPH

California Health & Safety Code § 1280.15 · California Department of Public Health (CDPH)

Term: medical information (unlawful or unauthorized access, use, or disclosure)

Licensed clinics, health facilities, home health agencies, and hospices must report unlawful or unauthorized access to, or use or disclosure of, a patient's medical information to CDPH and the affected patient within 15 business days of detection; CDPH may assess administrative penalties.

  • Detect and report within 15 business days — a shorter clock than HIPAA's 60 days for licensed facilities.
  • Report insider snooping and misdirected disclosures, not only external attacks.

California Consumer Privacy Act as amended by the CPRA

California Civil Code § 1798.100 et seq. · California Privacy Protection Agency; California Attorney General

Term: personal information; sensitive personal information

Consumer privacy law with exemptions for medical information governed by CMIA and protected health information governed by HIPAA — but which still reaches non-exempt data such as website, marketing, and workforce information held by covered businesses.

  • Map which data sets fall inside the CMIA/HIPAA exemptions and which do not (web analytics, marketing, employee data often do not).
  • Honour consumer rights and the private right of action for breaches of non-encrypted personal information.

HIPAA Privacy, Security, and Breach Notification Rules (federal)

45 CFR Parts 160 and 164 · HHS Office for Civil Rights

Term: protected health information (PHI)

Applies alongside the California instruments; a California breach of PHI affecting 500+ individuals is reported to HHS OCR and listed on the federal breach portal.

  • Risk analysis covering AI and third-party systems; business-associate agreements for every vendor touching ePHI.
  • Breach notification to HHS OCR within 60 days for 500+ individuals; annual log for smaller breaches.

Obligation → governance domains → controls → action · INFERENCE

OBLIGATION · REFERENCE

Two notification clocks: CDPH 15 business days (licensed facilities) and HIPAA 60 days; AG sample notice above 500 residents.

POTENTIALLY AFFECTED GOVERNANCE DOMAINS · INFERENCE

Incident response · Incident notification · Breach assessment

RECOMMENDED ACTION

Put the CDPH clock, the AG filing threshold, and the HHS clock into one incident runbook with named owners; rehearse it with a tabletop that includes an AI or vendor-originated incident.

OBLIGATION · REFERENCE

Tracking technologies on member and patient web properties disclose medical information without an attacker (Kaiser 2024, Blue Shield of California 2025).

POTENTIALLY AFFECTED GOVERNANCE DOMAINS · INFERENCE

Web and app governance · Consent · Third-party data access

RECOMMENDED ACTION

Inventory analytics and advertising tags on patient-facing properties, confirm what each transmits, and treat each vendor as a CMIA contractor with terms to match.

OBLIGATION · REFERENCE

CMIA reaches contractors and technology vendors holding medical information; HIPAA requires business-associate agreements.

POTENTIALLY AFFECTED GOVERNANCE DOMAINS · INFERENCE

Vendor risk management · Third-party AI and data access · Data residency

RECOMMENDED ACTION

List every vendor and AI tool processing medical information, confirm the agreement in place, and record where the data is hosted and by which sub-processors.

OBLIGATION · REFERENCE

§ 1280.15 counts unauthorized access by workforce members — snooping is reportable.

POTENTIALLY AFFECTED GOVERNANCE DOMAINS · INFERENCE

Access controls · Audit logging · Workforce training

RECOMMENDED ACTION

Verify role-based access and audit logging on the record system, and that staff training names snooping as a reportable breach.

Five questions for a California executive

  1. 1
    Which of our systems and vendors hold medical information under CMIA, and which of those also hold PHI under HIPAA?
  2. 2
    If a breach were detected today, who files the CDPH report inside 15 business days, and who files the AG sample notice?
  3. 3
    What do our web and mobile analytics tags transmit, and to whom?
  4. 4
    Which AI tools have staff adopted on their own, and what medical information have they seen?
  5. 5
    Can we produce evidence — not assertions — that these controls operated last quarter?
COVERAGE · CALIFORNIA
  • California records come from HHS OCR listings and organization notices; the California Attorney General breach list (oag.ca.gov) is cited as a registry but is not yet ingested automatically, so California coverage is incomplete.
  • CDPH § 1280.15 reports are not published as a searchable registry; CDPH enforcement actions are not yet integrated.
  • Nexus's readiness engine was built for Canadian healthcare; the California control mappings here are editorial, not computed applicability.
Methodology, sources, and coverage limitations

Reporting regimes

CANADA
Distributed: mandatory breach reporting exists federally (PIPEDA) and under provincial health-privacy statutes (e.g., Ontario PHIPA, Alberta HIA, Newfoundland and Labrador PHIA), but there is no single public registry. Records come from federal/provincial commissioners, government disclosures, and organization statements, so counts are less complete and less comparable.
UNITED STATES
Structured: HIPAA-covered entities and business associates must report breaches of protected health information affecting 500+ individuals to HHS OCR, which publishes them on the breach portal. Counts, entity type, breach type, and information location are comparable across records.
CARIBBEAN
Jurisdiction-specific and fragmented: data-protection laws (e.g., Jamaica 2020, Barbados 2019, Trinidad and Tobago 2011 partially proclaimed) differ in scope, terminology, and enforcement; several regulators are new. Puerto Rico and the U.S. Virgin Islands fall under HIPAA/HHS OCR. Public disclosure is often via press or ministry statements, so coverage is incomplete and terminology is preserved per jurisdiction.

Nexus normalizes each record to one analytic category (`data_type`) for counting only, and keeps the source jurisdiction's own terminology on the record. A data class is never inferred from the victim being a healthcare organization; when it is not publicly established the record says UNKNOWN_NOT_DISCLOSED.

Verification states

SOURCE_VERIFIED
Source verified
EDITORIAL
Editorially seeded — source not yet re-verified
REGISTRY_LISTED
Listed in an official registry (registry-level link)
SOURCE_UNREACHABLE
Source could not be reached at last check
UNVERIFIED
Unverified

Verification: 1 incident pages verified · 3 registry-level · 0 editorial · 0 unreachable at last check (in filter).

Coverage limitations

  • This is not a complete registry. United States records at registry scale arrive through the HHS OCR CSV adapter; until an export is imported, U.S. coverage is the editorially seeded set.
  • Canadian reporting is distributed across federal and provincial commissioners with no single public list; counts are less complete and less comparable than U.S. counts.
  • Caribbean records are jurisdiction-specific and few. Puerto Rico and the U.S. Virgin Islands report under HIPAA; independent states report under their own data-protection laws, several of which are new or partially proclaimed.
  • Affected-individual counts are as publicly reported and may be revised by the source; unknown counts are null and excluded from totals and medians.
  • A period filter excludes records with no disclosure, incident, or publication date.
  • Percentages are suppressed when fewer than five records are in the filter.

Sources implemented

  • United States — HHS OCR breach portal (CSV export adapter; registry-level), HHS OCR enforcement announcements and organization disclosures (editorial records).
  • Canada — federal and provincial privacy commissioners, provincial government disclosures, organization notices (editorial records; no single public registry exists).
  • Caribbean — HHS OCR for U.S. territories; ministry/press statements for independent states (editorial records; regulator statements recorded where located).