Nexus Intelligence
What is changing in healthcare AI, and why it matters. Eight lenses — threats, healthcare breach intelligence (Canada · United States · Caribbean), regulation, workforce, crisis, biosecurity, quantum risk, and the sovereignty movement — each item separated into the source fact, Nexus analysis, and the review it should trigger.
Public terminal. Sourced items are stated as the cited source reports them; analysis blocks are Nexus editorial inference and are labelled as such. Signed-in workspaces add organization-specific intelligence preferences and link items to your own controls.
How to read this terminal: labels, sources, and the threat-level method
What kind of statement is this?
- FACT
- A reported event or published document, stated as the cited source reports it.
- INFERENCE
- Nexus analysis of what the facts mean for healthcare AI governance. Reasoned, attributable, revisable.
- FORECAST
- A forward-looking expectation. Never presented as a fact; always attributed to Nexus analysis.
Each card separates the source fact (what the cited source reports) from Nexus analysis (what we think it means) and a recommended review (what a governance team should check). Analysis is editorial and attributable to Nexus; it is never presented as fact.
How urgent is it?
- FLASH
- A discrete, dated event with direct healthcare impact (breach, ransomware, regulation in force, outbreak). Recency-weighted into the threat level for 90 days.
- PRIORITY
- Material development or standing condition that should reach the governance agenda this cycle. Weighted into the threat level for 90 days at a lower rate than FLASH.
- ROUTINE
- Background context, standing facts, or slow-moving trends. Never moves the threat level.
Where is it in its life?
- LIVE
- Published by the daily collection agent since the last editorial refresh. Live items are collected and de-duplicated automatically; editorial review has not yet been recorded.
- ACTIVE
- Currently tracked. The situation is ongoing or its consequences are still unfolding.
- RESOLVED
- Closed by the source, or auto-resolved after 14 days without an update. Kept for the historical record, collapsed by default.
- STALE
- No update from any source in 30 days. Treat the details as possibly out of date.
How can I verify it?
- PRIMARY SOURCE
- Linked directly to the regulator, agency, vendor disclosure, or standards body that originated the information.
- SECONDARY SOURCE
- Linked to reputable reporting about the event rather than the originating body.
- SOURCE LINKED
- A source link is provided; primary/secondary tier has not been recorded for this item.
- SOURCE CITED · NO LINK
- The source is named but no link is recorded. Verify with the named source before acting.
- NEXUS TRACKING
- Derived from Nexus's own workforce or signal collection rather than an external publication.
- HUMAN REVIEWED
- An editor has reviewed the item against its source.
- REVIEW PENDING
- Collected automatically; editorial review has not yet been recorded.
Confidence scores, validation status, and human-review state appear only when a feed genuinely records them. When they are absent, they are absent — Nexus does not invent them.
How is the threat level calculated?
- FLASH within 7 days: 3 points · FLASH within 90 days: 2 points · older FLASH: 0.5
- PRIORITY within 90 days: 1 point · older PRIORITY: 0.25
- ROUTINE: 0 points
- CRITICAL
- Three or more FLASH items inside the last 7 days — a live cluster, right now.
- ELEVATED
- At least one FLASH item inside 7 days, or a weighted score of 8 or more. The news-rich resting state.
- GUARDED
- Weighted score of 3 or more with no FLASH in the last 7 days.
- LOW
- Weighted score below 3.
The threat level is an editorial urgency gauge over items in this terminal. It is not a probability, not a prediction, and not calibrated against incident outcomes. Use it to decide what to read first, not whether you are safe.
Healthcare Breach Intelligence
Canada · United States · Caribbean
Evidence-backed breach records normalized for trend analysis while keeping each jurisdiction's own terminology. Reporting regimes differ: U.S. PHI reporting is structured through HHS OCR; Canadian reporting is distributed across federal and provincial sources; Caribbean reporting is jurisdiction-specific and fragmented.
| Organization | Where | Affected | Data (jurisdiction term) | Type | Disclosed | Verification |
|---|---|---|---|---|---|---|
| XsolisBusiness associate · AI utilization-management vendorReported to OCR in June 2026 as affecting almost 1.4 million individuals (business-associate report). Incident date not publicly established by the sources on file; the count is 'almost 1.4M' per the secondary source.NEXUS ANALYSIS · INFERENCE An AI vendor's breach becomes its hospital customers' breach; custodianship does not transfer with the data. | TNUnited States · United States · HIPAA Breach Notification Rule | 1,400,000 | PHIprotected health information (PHI) | Hacking / IT incidentthird party | 2026-06 | source verifiedHIPAA Journal — June 2026 healthcare data breach report (secondary) ↗collected 2026-09-09 · verified 2026-09-10 |
| Hospital Caribbean Medical Center (Fajardo)Hospital · Community hospitalHospital press release dated 2026-02-08; 'The Gentlemen' ransomware group claimed responsibility on 2026-02-17. Puerto Rico is Caribbean geographically but reports under HIPAA — the regime is not the same as independent Caribbean states. | Puerto RicoCaribbean · Puerto Rico (U.S. territory) · HIPAA Breach Notification Rule | 92,000 | PHIprotected health information (PHI) | Ransomware | 2026-02-08 | source verifiedHIPAA Journal — Hospital Caribbean Medical Center (secondary) ↗collected 2026-09-09 · verified 2026-09-10 |
| TriZetto Provider Solutions (Cognizant)Business associate · Revenue cycle managementDescribed as the largest breach report filed with OCR in 2026 to date (February 2026). The affected count is not on file in Nexus and is left null rather than estimated. | NJUnited States · United States · HIPAA Breach Notification Rule | Not available | PHIprotected health information (PHI) | Hacking / IT incidentthird party | 2026-02 | source verifiedTechTarget — biggest healthcare breaches reported to OCR in 2026 (secondary) ↗collected 2026-09-09 · verified 2026-09-10 |
Methodology, sources, and coverage limitations
Reporting regimes
- CANADA
- Distributed: mandatory breach reporting exists federally (PIPEDA) and under provincial health-privacy statutes (e.g., Ontario PHIPA, Alberta HIA, Newfoundland and Labrador PHIA), but there is no single public registry. Records come from federal/provincial commissioners, government disclosures, and organization statements, so counts are less complete and less comparable.
- UNITED STATES
- Structured: HIPAA-covered entities and business associates must report breaches of protected health information affecting 500+ individuals to HHS OCR, which publishes them on the breach portal. Counts, entity type, breach type, and information location are comparable across records.
- CARIBBEAN
- Jurisdiction-specific and fragmented: data-protection laws (e.g., Jamaica 2020, Barbados 2019, Trinidad and Tobago 2011 partially proclaimed) differ in scope, terminology, and enforcement; several regulators are new. Puerto Rico and the U.S. Virgin Islands fall under HIPAA/HHS OCR. Public disclosure is often via press or ministry statements, so coverage is incomplete and terminology is preserved per jurisdiction.
Nexus normalizes each record to one analytic category (`data_type`) for counting only, and keeps the source jurisdiction's own terminology on the record. A data class is never inferred from the victim being a healthcare organization; when it is not publicly established the record says UNKNOWN_NOT_DISCLOSED.
Verification states
- SOURCE_VERIFIED
- Source verified
- EDITORIAL
- Editorially seeded — source not yet re-verified
- REGISTRY_LISTED
- Listed in an official registry (registry-level link)
- SOURCE_UNREACHABLE
- Source could not be reached at last check
- UNVERIFIED
- Unverified
Verification: 3 incident pages verified · 0 registry-level · 0 editorial · 0 unreachable at last check (in filter).
Coverage limitations
- This is not a complete registry. United States records at registry scale arrive through the HHS OCR CSV adapter; until an export is imported, U.S. coverage is the editorially seeded set.
- Canadian reporting is distributed across federal and provincial commissioners with no single public list; counts are less complete and less comparable than U.S. counts.
- Caribbean records are jurisdiction-specific and few. Puerto Rico and the U.S. Virgin Islands report under HIPAA; independent states report under their own data-protection laws, several of which are new or partially proclaimed.
- Affected-individual counts are as publicly reported and may be revised by the source; unknown counts are null and excluded from totals and medians.
- A period filter excludes records with no disclosure, incident, or publication date.
- Percentages are suppressed when fewer than five records are in the filter.
Sources implemented
- United States — HHS OCR breach portal (CSV export adapter; registry-level), HHS OCR enforcement announcements and organization disclosures (editorial records).
- Canada — federal and provincial privacy commissioners, provincial government disclosures, organization notices (editorial records; no single public registry exists).
- Caribbean — HHS OCR for U.S. territories; ministry/press statements for independent states (editorial records; regulator statements recorded where located).