Verizon Releases Inaugural Breach Impact Study
Verizon Business has released the findings from its inaugural Breach Impact Study, which focuses on the financial impact of data breaches. The BIS report is from the same authoring team as the Verizon Data Breach Investigations Report and was produced in partnership with CyberAcuView. The report is based on an analysis of around 70,000 U.S. cyber insurance claims, including 38,000 claims where the policies paid out. The data spans from January 2019 to October 2025. In contrast to many data breach cost reports, the report is based on median claim amounts rather than averages, which are susceptible to skewing. In 2019, the median financial impact was around $60,000, rising by 80% to $110,000 in 2025, with data breach costs outpacing inflation, which was around 23% over the period of the study. More than half of paid-out claims exceeded $83,000, with 10% having an impact of $920,000 or more. The most extreme 2.5% of cases exceeded $5 million in losses. The report shows that data breach costs almost doubled between 2019 and 2025, with business interruption the single largest loss...
HHS Provides Update on its Artificial Intelligence RFI
The Department of Health and Human Services (HHS) has provided an update on how it plans to accelerate the adoption of artificial intelligence (AI) in clinical care settings. AI has tremendous potential for improving efficiency in healthcare, achieving better patient outcomes, and lowering healthcare costs for Americans; however, there are risks associated with AI implementation in healthcare. The HHS issued a Request for Information (RFI) in December 2025 on how AI tools can be used to deflate healthcare costs, as part of the Make America Healthy Again initiative. HHS Secretary Robert F. Kennedy Jr. sought broad public input on how the HHS could use its regulatory, reimbursement, and research & development levers to enable AI adoption to propel the U.S. healthcare system forward. The HHS sought information on how digital health and software regulatory frameworks should evolve to account for AI-driven tools while maintaining patient safety; whether reimbursement structures could be simplified and better aligned to support the use of efficient, deflationary technologies; and...
Take the Guesswork out of HIPAA Compliance for Small Practices
Removing guesswork from HIPAA compliance means replacing assumptions about what a practice has covered with a documented process that maps directly to the requirements of the HIPAA Privacy Rule, the HIPAA Security Rule, and the HIPAA Breach Notification Rule. Small practices frequently operate on inherited assumptions: a predecessor set up a policy years ago, a staff member attended a training session at some point, or a binder was purchased and filled out once. None of those assumptions can be verified on demand, and an inability to verify is treated the same as noncompliance during a regulatory review. A defined process removes that ambiguity by producing evidence rather than relying on memory or informal practice. The Uncertainty Small Practices Face Under HIPAA Owners and office managers at small practices commonly cannot answer basic questions about their own compliance status without checking multiple sources or guessing. Common uncertainty includes whether the Security Risk Analysis on file reflects the practice’s current systems, whether every staff member has...
Security Researcher Identifies Quintet of Bugs in Toolkit Used in DICOM Medical Imaging Software
A quintet of vulnerabilities has been identified in a DICOM toolkit – OFFIS DCMTK – that is extensively used in medical imaging software. DICOM (Digital Imaging and Communications in Medicine) is the universal technical standard used to store, transmit, print, and display medical imaging data and is used by virtually all medical imaging devices. Since the toolkit is used in many medical imaging software solutions, the vulnerabilities are significant. Successful exploitation of the vulnerabilities could expose patient information, disrupt DICOM storage or worklist services, exhaust service memory, crash imaging services, or cause DCMTK-based clients to write files outside the intended output directory. The vulnerabilities were identified by independent security researcher Abhinav Agarwal, who reported them to the U.S. Cybersecurity and Infrastructure Agency (CISA) and the vendor in May 2026. Agarwal identified the vulnerabilities using standard subscriptions to Claude and ChatGPT, then manually reviewed and confirmed the findings. One of the vulnerabilities is rated critical with a...
Medtronic Notifies 3.8M Individuals About April 2026 Cyberattack
Medtronic has started issuing notifications to individuals affected by an April 2026 cyberattack. The ShinyHunters threat group claimed responsibility for the cyberattack and alleges that more than 9 million records containing personally identifiable information (PII) were stolen. Medtronic explained in the notification letters that it learned about the intrusion on April 15, 2026, when suspicious activity was identified within certain corporate IT systems. Assisted by leading third-party cybersecurity experts, Medtronic confirmed unauthorized access to certain IT systems from April 13 to April 19, 2026. The medical devices manufactured by Medtronic collect patient data. The review of that data confirmed that names, contact information, dates of birth, Social Security numbers, and health-related information may have been impacted. At the time of issuing the notification letters, Medtronic said it was unaware of any release of the stolen data on the public Internet. Medtronic confirmed that it takes privacy and security seriously and had implemented many safeguards to protect its...



