CYBERCHAIN TechnologiesNEXUSBook a Confidential DiscussionSign in

Intelligence Terminal

Six converged feeds on the forces reshaping healthcare AI: threats, regulation, workforce, crisis, biosecurity, and the global movement to own the stack. Every data point is evidence, not marketing.

THREAT LEVEL: ELEVATED1 FLASH signal past 7 days · 13 active tracked threats · 6 fused feeds

Cybersecurity in Healthcare

Healthcare has been the most-breached sector for 14 consecutive years. This feed tracks the incidents that prove the pattern: it is not the hospital's firewall that fails — it is the vendor, the cloud, and the unsanctioned AI tool. Sector posture: ELEVATED · 1 FLASH signals in 90 days.

THE PATTERNThird parties and cloud dependencies dominate this feed. Xsolis, Change Healthcare, Synnovis, BORN, Cencora — none of the victims were breached through their own front door. Zero egress removes the entire class.
PRIORITYDATA BREACHHHS OCR breach portal: 700+ healthcare breaches under active investigation

The US federal 'wall of shame' continues to list hundreds of reportable breaches (500+ records each) under investigation — hacking/IT incidents remain the dominant cause, and business associates (vendors) account for a growing share. Snapshot as of this feed refresh.

SOURCE: HHS Office for Civil Rightsprimary source ↗REGION: US#hhs#breach-portal#vendors
FLASHRANSOMWARECISA/FBI standing advisory: Interlock ransomware actively targeting healthcare

Joint advisory AA25-203A warns that the Interlock group is compromising healthcare and public-health organizations via drive-by downloads and 'ClickFix' social engineering, exfiltrating data before encryption for double extortion. Advisory remains active as of this refresh.

SOURCE: CISA AA25-203Aprimary source ↗REGION: US#cisa#ransomware#double-extortion
PRIORITYSHADOW AI40%+ of healthcare workers know colleagues using unauthorized AI on patient data

Industry surveys in 2026 (Wolters Kluwer) confirm what CISOs suspected: unsanctioned generative-AI use on PHI is widespread. Shadow AI is now a standing exfiltration channel that never appears in vendor risk registers.

SOURCE: Wolters Kluwer 2026REGION: GLOBAL#shadow-ai#phi#governance-gap
FLASHDATA BREACHXsolis breach exposes 1.4M patient records through an AI vendor

The AI utilization-management vendor Xsolis was breached, exposing roughly 1.4 million patient records. Victims included Mayo Clinic and UW Medicine patients — organizations whose own perimeters were never touched. The vendor's breach became their breach.

SOURCE: Breach disclosure, January 2026REGION: USAFFECTED: Xsolis, Mayo Clinic, UW Medicine#ai-vendor#third-party#cloud-ai
FLASHSHADOW AIOntario: AI transcription bot records hospital rounds, emails PHI of 7 patients to 65 people

An AI meeting-transcription bot attended hospital rounds uninvited, recorded discussion of seven patients' care, and auto-emailed the transcript to 65 recipients — including former staff. The Ontario IPC investigated. No perimeter, no governance, no consent.

SOURCE: Ontario IPCREGION: CA#shadow-ai#phipa#transcription#ipc
FLASHRANSOMWARESynnovis attack postpones 1,100+ procedures across London hospitals

Qilin ransomware hit pathology provider Synnovis, halting blood testing for major NHS trusts. Over 1,100 elective procedures and thousands of appointments were postponed; a national blood-stock alert followed. One vendor, an entire region's care disrupted.

SOURCE: NHS EnglandREGION: EUAFFECTED: Synnovis, Guy's and St Thomas', King's College Hospital#ransomware#qilin#pathology#nhs
PRIORITYRANSOMWAREMediSecure (Australia): 12.9M individuals' prescription data stolen

Ransomware against the e-prescription provider exposed health data of about 12.9 million Australians — roughly half the country — in one of Australia's largest breaches. The company entered administration weeks later.

SOURCE: Australian National Cyber Security CoordinatorREGION: APACAFFECTED: MediSecure#ransomware#e-prescriptions
FLASHRANSOMWAREAscension Health ransomware takes ~140 hospitals offline

Black Basta ransomware forced Ascension — one of the largest US nonprofit systems — onto paper charting for weeks. Ambulances diverted, procedures postponed; clinicians reported medication-safety near-misses while EHRs were down. ~5.6M individuals later notified.

SOURCE: Ascension / HHS OCRREGION: USAFFECTED: Ascension Health#ransomware#black-basta#patient-safety
ROUTINEDATA BREACHCencora/AmerisourceBergen breach ripples through 25+ pharma partners

Data stolen from the drug distributor triggered breach notifications from dozens of pharmaceutical manufacturers whose patient-support-program data it processed — one upstream vendor, an industry-wide notification wave.

SOURCE: SEC filing / public notificationsREGION: USAFFECTED: Cencora#supply-chain#pharma
FLASHRANSOMWAREChange Healthcare ransomware: ~190M records, US claims processing paralyzed

ALPHV/BlackCat crippled UnitedHealth's Change Healthcare, halting claims and pharmacy processing nationwide for weeks. A $22M ransom was paid; final notification counts reached ~190 million people — the largest healthcare breach in US history.

SOURCE: UnitedHealth Group / HHS OCRREGION: USAFFECTED: Change Healthcare, UnitedHealth Group#ransomware#alphv#clearinghouse#systemic-risk
ROUTINERANSOMWARELurie Children's Hospital (Chicago) offline for weeks; 792k affected

Rhysida claimed the attack that took phones, email, MyChart, and some clinical systems offline at one of the top US pediatric hospitals, delaying care coordination for weeks.

SOURCE: Lurie Children'sREGION: USAFFECTED: Ann & Robert H. Lurie Children's Hospital#ransomware#pediatrics
ROUTINEDATA BREACHIntegris Health patients receive direct extortion emails from attackers

After stealing data on ~2.4 million people, attackers emailed patients directly, threatening to sell their records unless paid — a template later reused against other health systems.

SOURCE: Integris HealthREGION: USAFFECTED: Integris Health#extortion#patient-contact
PRIORITYRANSOMWAREArdent Health ransomware forces ER diversions across six US states

A Thanksgiving-day attack took the 30-hospital system offline; multiple ERs diverted ambulances and clinicians reverted to paper. Elective procedures paused across the network.

SOURCE: Ardent Health ServicesREGION: USAFFECTED: Ardent Health Services#ransomware#er-diversion
PRIORITYDATA BREACHOntario BORN registry: 3.4M mother-newborn records exposed via MOVEit

Cl0p's MOVEit supply-chain campaign reached Ontario's Better Outcomes Registry & Network, exposing records of ~3.4 million people receiving pregnancy and newborn care. The registry's own systems were never breached — a file-transfer vendor was.

SOURCE: BORN OntarioREGION: CAAFFECTED: BORN Ontario#moveit#cl0p#supply-chain#phipa
PRIORITYRANSOMWAREProspect Medical Holdings: 16 hospitals disrupted, Rhysida claims theft of 500k+ SSNs

The Rhysida gang forced emergency-department closures and paper operations across hospitals in four states, later advertising stolen identity and clinical data for sale.

SOURCE: Public reportingREGION: USAFFECTED: Prospect Medical Holdings#ransomware#rhysida
PRIORITYDATA BREACHHCA Healthcare: 11M patients' data posted to a hacking forum

Data from an external storage location used for email formatting was stolen and advertised on a criminal forum, affecting roughly 11 million HCA patients across 20 states.

SOURCE: HCA HealthcareREGION: USAFFECTED: HCA Healthcare#data-breach#external-storage
ROUTINERANSOMWARENorton Healthcare (Kentucky): 2.5M affected in ALPHV attack

Attackers accessed network storage devices for two days, exposing data of ~2.5 million patients and employees, including SSNs and health information.

SOURCE: Norton HealthcareREGION: USAFFECTED: Norton Healthcare#ransomware#alphv
PRIORITYRANSOMWAREToronto SickKids hit by LockBit affiliate; gang issues rare apology

Canada's largest children's hospital lost phone lines, payroll, and some clinical systems, delaying lab and imaging results. LockBit apologized, blamed a rogue affiliate, and released a free decryptor — a reminder that criminal 'ethics' are not a control.

SOURCE: SickKids / public reportingREGION: CAAFFECTED: Hospital for Sick Children#ransomware#lockbit#pediatrics
PRIORITYDATA BREACHMedibank: 9.7M records stolen, sensitive claims dumped on the dark web

REvil-linked actors stole 9.7 million Australians' data and, after Medibank refused to pay, published sensitive claims including mental-health and pregnancy-termination records. Australia later sanctioned the named Russian national behind it.

SOURCE: Medibank / Australian GovernmentREGION: APACAFFECTED: Medibank#extortion#dark-web#sanctions
PRIORITYRANSOMWARECommonSpirit Health ransomware: $160M in costs, 623k patients affected

The attack on one of the largest US Catholic health systems disrupted EHR access across multiple states; a pediatric medication overdose during downtime was publicly reported. Recovery and remediation costs exceeded $160 million.

SOURCE: CommonSpirit HealthREGION: USAFFECTED: CommonSpirit Health#ransomware#downtime-costs