Nexus Intelligence
What is changing in healthcare AI, and why it matters. Eight lenses — threats, healthcare breach intelligence (Canada · United States · Caribbean), regulation, workforce, crisis, biosecurity, quantum risk, and the sovereignty movement — each item separated into the source fact, Nexus analysis, and the review it should trigger.
Public terminal. Sourced items are stated as the cited source reports them; analysis blocks are Nexus editorial inference and are labelled as such. Signed-in workspaces add organization-specific intelligence preferences and link items to your own controls.
How to read this terminal: labels, sources, and the threat-level method
What kind of statement is this?
- FACT
- A reported event or published document, stated as the cited source reports it.
- INFERENCE
- Nexus analysis of what the facts mean for healthcare AI governance. Reasoned, attributable, revisable.
- FORECAST
- A forward-looking expectation. Never presented as a fact; always attributed to Nexus analysis.
Each card separates the source fact (what the cited source reports) from Nexus analysis (what we think it means) and a recommended review (what a governance team should check). Analysis is editorial and attributable to Nexus; it is never presented as fact.
How urgent is it?
- FLASH
- A discrete, dated event with direct healthcare impact (breach, ransomware, regulation in force, outbreak). Recency-weighted into the threat level for 90 days.
- PRIORITY
- Material development or standing condition that should reach the governance agenda this cycle. Weighted into the threat level for 90 days at a lower rate than FLASH.
- ROUTINE
- Background context, standing facts, or slow-moving trends. Never moves the threat level.
Where is it in its life?
- LIVE
- Published by the daily collection agent since the last editorial refresh. Live items are collected and de-duplicated automatically; editorial review has not yet been recorded.
- ACTIVE
- Currently tracked. The situation is ongoing or its consequences are still unfolding.
- RESOLVED
- Closed by the source, or auto-resolved after 14 days without an update. Kept for the historical record, collapsed by default.
- STALE
- No update from any source in 30 days. Treat the details as possibly out of date.
How can I verify it?
- PRIMARY SOURCE
- Linked directly to the regulator, agency, vendor disclosure, or standards body that originated the information.
- SECONDARY SOURCE
- Linked to reputable reporting about the event rather than the originating body.
- SOURCE LINKED
- A source link is provided; primary/secondary tier has not been recorded for this item.
- SOURCE CITED · NO LINK
- The source is named but no link is recorded. Verify with the named source before acting.
- NEXUS TRACKING
- Derived from Nexus's own workforce or signal collection rather than an external publication.
- HUMAN REVIEWED
- An editor has reviewed the item against its source.
- REVIEW PENDING
- Collected automatically; editorial review has not yet been recorded.
Confidence scores, validation status, and human-review state appear only when a feed genuinely records them. When they are absent, they are absent — Nexus does not invent them.
How is the threat level calculated?
- FLASH within 7 days: 3 points · FLASH within 90 days: 2 points · older FLASH: 0.5
- PRIORITY within 90 days: 1 point · older PRIORITY: 0.25
- ROUTINE: 0 points
- CRITICAL
- Three or more FLASH items inside the last 7 days — a live cluster, right now.
- ELEVATED
- At least one FLASH item inside 7 days, or a weighted score of 8 or more. The news-rich resting state.
- GUARDED
- Weighted score of 3 or more with no FLASH in the last 7 days.
- LOW
- Weighted score below 3.
The threat level is an editorial urgency gauge over items in this terminal. It is not a probability, not a prediction, and not calibrated against incident outcomes. Use it to decide what to read first, not whether you are safe.
Healthcare Breach Intelligence
Canada · United States · Caribbean
Evidence-backed breach records normalized for trend analysis while keeping each jurisdiction's own terminology. Reporting regimes differ: U.S. PHI reporting is structured through HHS OCR; Canadian reporting is distributed across federal and provincial sources; Caribbean reporting is jurisdiction-specific and fragmented.
Largest incidents in filter
| Organization | Where | Affected | Data (jurisdiction term) | Type | Disclosed | Verification |
|---|---|---|---|---|---|---|
| Change Healthcare (UnitedHealth Group)Business associate · Claims clearinghouse / revenue cycle | TNUnited States · United States · HIPAA Breach Notification Rule | 192,700,000 | PHIprotected health information (PHI) | Ransomwarethird party | 2024-02-21 | source unreachableHHS OCR — Change Healthcare cybersecurity incident FAQ ↗collected 2026-09-09 · verified 2026-09-10 |
| WelltokBusiness associate · Patient engagement platform | COUnited States · United States · HIPAA Breach Notification Rule | 8,493,379 | PHIprotected health information (PHI) | Third-party / supply chainthird party · Progress Software (MOVEit Transfer) | 2023-11 | registry listedHHS OCR breach portal (Welltok, Inc.) ↗collected 2026-09-09 · verified 2026-09-10 |
| ESO SolutionsBusiness associate · EMS / fire software vendor | TXUnited States · United States · HIPAA Breach Notification Rule | 2,700,000 | PHIprotected health information (PHI) | Ransomwarethird party | 2023-12 | registry listedHHS OCR breach portal (ESO Solutions) ↗collected 2026-09-09 · verified 2026-09-10 |
| XsolisBusiness associate · AI utilization-management vendor | TNUnited States · United States · HIPAA Breach Notification Rule | 1,400,000 | PHIprotected health information (PHI) | Hacking / IT incidentthird party | 2026-06 | source verifiedHIPAA Journal — June 2026 healthcare data breach report (secondary) ↗collected 2026-09-09 · verified 2026-09-10 |
Methodology, sources, and coverage limitations
Reporting regimes
- CANADA
- Distributed: mandatory breach reporting exists federally (PIPEDA) and under provincial health-privacy statutes (e.g., Ontario PHIPA, Alberta HIA, Newfoundland and Labrador PHIA), but there is no single public registry. Records come from federal/provincial commissioners, government disclosures, and organization statements, so counts are less complete and less comparable.
- UNITED STATES
- Structured: HIPAA-covered entities and business associates must report breaches of protected health information affecting 500+ individuals to HHS OCR, which publishes them on the breach portal. Counts, entity type, breach type, and information location are comparable across records.
- CARIBBEAN
- Jurisdiction-specific and fragmented: data-protection laws (e.g., Jamaica 2020, Barbados 2019, Trinidad and Tobago 2011 partially proclaimed) differ in scope, terminology, and enforcement; several regulators are new. Puerto Rico and the U.S. Virgin Islands fall under HIPAA/HHS OCR. Public disclosure is often via press or ministry statements, so coverage is incomplete and terminology is preserved per jurisdiction.
Nexus normalizes each record to one analytic category (`data_type`) for counting only, and keeps the source jurisdiction's own terminology on the record. A data class is never inferred from the victim being a healthcare organization; when it is not publicly established the record says UNKNOWN_NOT_DISCLOSED.
Verification states
- SOURCE_VERIFIED
- Source verified
- EDITORIAL
- Editorially seeded — source not yet re-verified
- REGISTRY_LISTED
- Listed in an official registry (registry-level link)
- SOURCE_UNREACHABLE
- Source could not be reached at last check
- UNVERIFIED
- Unverified
Verification: 2 incident pages verified · 2 registry-level · 0 editorial · 1 unreachable at last check (in filter).
Coverage limitations
- This is not a complete registry. United States records at registry scale arrive through the HHS OCR CSV adapter; until an export is imported, U.S. coverage is the editorially seeded set.
- Canadian reporting is distributed across federal and provincial commissioners with no single public list; counts are less complete and less comparable than U.S. counts.
- Caribbean records are jurisdiction-specific and few. Puerto Rico and the U.S. Virgin Islands report under HIPAA; independent states report under their own data-protection laws, several of which are new or partially proclaimed.
- Affected-individual counts are as publicly reported and may be revised by the source; unknown counts are null and excluded from totals and medians.
- A period filter excludes records with no disclosure, incident, or publication date.
- Percentages are suppressed when fewer than five records are in the filter.
Sources implemented
- United States — HHS OCR breach portal (CSV export adapter; registry-level), HHS OCR enforcement announcements and organization disclosures (editorial records).
- Canada — federal and provincial privacy commissioners, provincial government disclosures, organization notices (editorial records; no single public registry exists).
- Caribbean — HHS OCR for U.S. territories; ministry/press statements for independent states (editorial records; regulator statements recorded where located).