Report Reveals Worrying Abuses of Agentic AI by Cybercriminals
Cybercriminals have been abusing agentic AI to perform sophisticated cyberattacks at scale, incorporating AI tools throughout all stages of their operations. Agentic AI tools have significantly lowered the bar for hackers, allowing individuals with few technical skills to conduct complex attacks that would otherwise require extensive training over several years and a team of operators. A new threat intelligence report from Anthropic highlights the extent to which its own language model (LLM) and AI assistant, Claude, has been abused, even with sophisticated safety and security measures in place to protect against misuse. The cybercriminal schemes identified by Anthropic have targeted businesses around the world, including U.S. healthcare providers. Examples of misuses of Claude code include: A campaign allowing large-scale theft of data from healthcare providers, emergency services, religious institutions, and the government A large-scale fraudulent employment scheme conducted by a North Korean threat actor to secure jobs at Western companies The creation and subsequent sale of...
HHS Announces Crackdown on Information Blocking in Healthcare
The Department of Health and Human Services (HHS) has announced it will start cracking down on healthcare entities that engage in information blocking. On September 3, 2025, HHS Secretary Robert F. Kennedy Jr. directed the HHS to increase resources dedicated to the enforcement of the health data information blocking provisions of the 21st Century Cures Act. The 21st Century Cures Act of 2016 established penalties, termed disincentives, for healthcare entities that engage in information blocking practices, which is “any practice that interferes with, prevents, or materially discourages access, exchange, or use of electronic health information.” The disincentive for information blocking by developers of certified health IT, Health Information Exchanges (HIEs), and Health Information Networks (HINs) is a civil monetary penalty of up to $1 million, which took effect on September 1, 2023. Developers with products certified under the ONC Health IT Certification Program could have their certifications terminated and be banned from the Certification Program. In 2023, the HHS proposed a...
Morris Hospital Agrees to $1.36M Class Action Data Breach Settlement
Morris Hospital & Healthcare Centers has agreed to settle a consolidated class action lawsuit that alleged negligence for failing to prevent an April 2023 data breach that affected 248,943 individuals. Under the terms of the settlement agreement, Morris Hospital will establish a $1,361,571.77 settlement fund to cover attorneys’ fees, legal expenses, and benefits for the class members. In April 2023, Morris Hospital identified unauthorized access to its network. Hackers had access to the personal and protected health information of current and former patients, employees, and their dependents and beneficiaries. The Royal ransomware group was behind the attack and posted the stolen data on its data leak site. Several class action lawsuits were filed in response to the data breach, which were consolidated into a single lawsuit in the Circuit Court of the Thirteenth Judicial Circuit, Grundy County, Illinois – In re: Morris Hospital Data Breach Litigation. In addition to negligence, the lawsuit asserted claims of negligence per se, breach of fiduciary duty, breach of implied...
Business Associate Hacking Incident Affects Keys Pathology Patients
A cyberattack on a business associate has resulted in unauthorized access to the protected health information of patients of Keys Pathology Associates in Texas. Assisted Living patients of Pharmacy Service in Wisconsin and the American Association of Critical-Care Nurses in California have also announced data breaches. Keys Pathology Associates, Texas In July 2025, Keys Pathology Associates in Marathon, Texas, reported a hacking-related data breach to the HHS’ Office for Civil Rights that affected up to 20,000 individuals. The Maine Attorney General has now been notified, and the breach report indicates fewer individuals were affected than the initial estimate: 13,756 individuals, including 26 Maine residents. The incident did not occur at Keys Pathology, but rather at a business associate that Keys Pathology used for billing services. The vendor, Genesis Billing Services in North Carolina, was provided with patient data, which was maintained on a third-party server outside the control of Keys Pathology. Keys Pathology was notified by its vendor on May 27, 2025, that an...
Two Disability Service Providers Announce Data Breaches Affecting 8,100 Patients
Two providers of disability services have announced security incidents. The cyberattacks on Reimagine Network in California and the Center for Disability Services in New York have affected more than 8,100 individuals. Reimagine Network, California Reimagine Network, a Santa Ana, California-based provider of disability services, recently reported a data breach to the HHS’ Office for Civil Rights that has affected up to 4,799 individuals. Network disruption was experienced on June 23, 2025, indicative of a cyberattack. Third-party cybersecurity experts were engaged to investigate and confirmed unauthorized network access and the potential exfiltration of files containing sensitive patient data. The file review was completed on August 6, 2025, and notification letters have now been sent to all potentially affected individuals. The types of information involved vary from individual to individual and may include names plus one or more of the following: address, phone number, date of birth, Social Security number, diagnosis/conditions, medications, and health insurance information. IT...



