Intelligence Terminal
Six converged feeds on the forces reshaping healthcare AI: threats, regulation, workforce, crisis, biosecurity, and the global movement to own the stack. Every data point is evidence, not marketing.
Cybersecurity in Healthcare
Healthcare has been the most-breached sector for 14 consecutive years. This feed tracks the incidents that prove the pattern: it is not the hospital's firewall that fails — it is the vendor, the cloud, and the unsanctioned AI tool. Sector posture: ELEVATED · 1 FLASH signals in 90 days.
PRIORITYDATA BREACHHHS OCR breach portal: 700+ healthcare breaches under active investigation
The US federal 'wall of shame' continues to list hundreds of reportable breaches (500+ records each) under investigation — hacking/IT incidents remain the dominant cause, and business associates (vendors) account for a growing share. Snapshot as of this feed refresh.
FLASHRANSOMWARECISA/FBI standing advisory: Interlock ransomware actively targeting healthcare
Joint advisory AA25-203A warns that the Interlock group is compromising healthcare and public-health organizations via drive-by downloads and 'ClickFix' social engineering, exfiltrating data before encryption for double extortion. Advisory remains active as of this refresh.
PRIORITYSHADOW AI40%+ of healthcare workers know colleagues using unauthorized AI on patient data
Industry surveys in 2026 (Wolters Kluwer) confirm what CISOs suspected: unsanctioned generative-AI use on PHI is widespread. Shadow AI is now a standing exfiltration channel that never appears in vendor risk registers.
FLASHDATA BREACHXsolis breach exposes 1.4M patient records through an AI vendor
The AI utilization-management vendor Xsolis was breached, exposing roughly 1.4 million patient records. Victims included Mayo Clinic and UW Medicine patients — organizations whose own perimeters were never touched. The vendor's breach became their breach.
FLASHSHADOW AIOntario: AI transcription bot records hospital rounds, emails PHI of 7 patients to 65 people
An AI meeting-transcription bot attended hospital rounds uninvited, recorded discussion of seven patients' care, and auto-emailed the transcript to 65 recipients — including former staff. The Ontario IPC investigated. No perimeter, no governance, no consent.
FLASHRANSOMWARESynnovis attack postpones 1,100+ procedures across London hospitals
Qilin ransomware hit pathology provider Synnovis, halting blood testing for major NHS trusts. Over 1,100 elective procedures and thousands of appointments were postponed; a national blood-stock alert followed. One vendor, an entire region's care disrupted.
PRIORITYRANSOMWAREMediSecure (Australia): 12.9M individuals' prescription data stolen
Ransomware against the e-prescription provider exposed health data of about 12.9 million Australians — roughly half the country — in one of Australia's largest breaches. The company entered administration weeks later.
FLASHRANSOMWAREAscension Health ransomware takes ~140 hospitals offline
Black Basta ransomware forced Ascension — one of the largest US nonprofit systems — onto paper charting for weeks. Ambulances diverted, procedures postponed; clinicians reported medication-safety near-misses while EHRs were down. ~5.6M individuals later notified.
ROUTINEDATA BREACHCencora/AmerisourceBergen breach ripples through 25+ pharma partners
Data stolen from the drug distributor triggered breach notifications from dozens of pharmaceutical manufacturers whose patient-support-program data it processed — one upstream vendor, an industry-wide notification wave.
FLASHRANSOMWAREChange Healthcare ransomware: ~190M records, US claims processing paralyzed
ALPHV/BlackCat crippled UnitedHealth's Change Healthcare, halting claims and pharmacy processing nationwide for weeks. A $22M ransom was paid; final notification counts reached ~190 million people — the largest healthcare breach in US history.
ROUTINERANSOMWARELurie Children's Hospital (Chicago) offline for weeks; 792k affected
Rhysida claimed the attack that took phones, email, MyChart, and some clinical systems offline at one of the top US pediatric hospitals, delaying care coordination for weeks.
ROUTINEDATA BREACHIntegris Health patients receive direct extortion emails from attackers
After stealing data on ~2.4 million people, attackers emailed patients directly, threatening to sell their records unless paid — a template later reused against other health systems.
PRIORITYRANSOMWAREArdent Health ransomware forces ER diversions across six US states
A Thanksgiving-day attack took the 30-hospital system offline; multiple ERs diverted ambulances and clinicians reverted to paper. Elective procedures paused across the network.
PRIORITYDATA BREACHOntario BORN registry: 3.4M mother-newborn records exposed via MOVEit
Cl0p's MOVEit supply-chain campaign reached Ontario's Better Outcomes Registry & Network, exposing records of ~3.4 million people receiving pregnancy and newborn care. The registry's own systems were never breached — a file-transfer vendor was.
PRIORITYRANSOMWAREProspect Medical Holdings: 16 hospitals disrupted, Rhysida claims theft of 500k+ SSNs
The Rhysida gang forced emergency-department closures and paper operations across hospitals in four states, later advertising stolen identity and clinical data for sale.
PRIORITYDATA BREACHHCA Healthcare: 11M patients' data posted to a hacking forum
Data from an external storage location used for email formatting was stolen and advertised on a criminal forum, affecting roughly 11 million HCA patients across 20 states.
ROUTINERANSOMWARENorton Healthcare (Kentucky): 2.5M affected in ALPHV attack
Attackers accessed network storage devices for two days, exposing data of ~2.5 million patients and employees, including SSNs and health information.
PRIORITYRANSOMWAREToronto SickKids hit by LockBit affiliate; gang issues rare apology
Canada's largest children's hospital lost phone lines, payroll, and some clinical systems, delaying lab and imaging results. LockBit apologized, blamed a rogue affiliate, and released a free decryptor — a reminder that criminal 'ethics' are not a control.
PRIORITYDATA BREACHMedibank: 9.7M records stolen, sensitive claims dumped on the dark web
REvil-linked actors stole 9.7 million Australians' data and, after Medibank refused to pay, published sensitive claims including mental-health and pregnancy-termination records. Australia later sanctioned the named Russian national behind it.
PRIORITYRANSOMWARECommonSpirit Health ransomware: $160M in costs, 623k patients affected
The attack on one of the largest US Catholic health systems disrupted EHR access across multiple states; a pediatric medication overdose during downtime was publicly reported. Recovery and remediation costs exceeded $160 million.