Field notes from the edge.
What our engineers learned this week. Hands-on technical deep-dives, postmortems, and strategy frameworks.
AIBusiness Associates Face Increased Regulatory Scrutiny as Vendor Breaches Soar
Healthcare third-party vendor breaches have surged dramatically, with business associate involvement in breaches rising from 20% (2009-2017) to 43% in early 2026, prompting increased regulatory scrutiny from HHS OCR. Vendors present attractive targets for threat actors due to their access to multiple healthcare clients' data, with 65% of affected individuals in 2025 breaches involving business ass
PHI Compromised in Cyber Incidents at Medenet; United Medical Doctors; Stewart Home & School
Three healthcare-related organizations have disclosed cybersecurity incidents compromising protected health information (PHI). Medenet, a Florida revenue cycle management provider, United Medical Doctors in California, and Kentucky's Stewart Home & School all experienced unauthorized access to their systems, with incidents ranging from December 2025 to March 2026, affecting thousands of individual
Senator Seeks Answers from NYC Health & Hospitals About 1.8M Record Breach
Senate HELP Committee Chair Senator Bill Cassidy is demanding answers from NYC Health + Hospitals regarding a data breach affecting 1.8 million individuals, where unauthorized access persisted for nearly three months through a third-party vendor compromise. The breach, discovered in February 2026, exposed sensitive patient data including Social Security numbers, medical records, and geolocation in
Henderson & Walton Women’s Center Settles Class Action Data Breach Lawsuit
Henderson & Walton Women's Center has agreed to settle a class action lawsuit following a 2022 email account breach that exposed personal and protected health information of 34,306 patients. The unauthorized access occurred over a three-day period in February 2022, compromising names, dates of birth, identification numbers, and medical information. While denying wrongdoing, the healthcare provider
HSCC Issues Guidance on Cyber Governance Frameworks for Secure AI implementation
The Health Sector Coordinating Council (HSCC) has released comprehensive guidance to help healthcare CISOs establish cybersecurity governance frameworks for secure AI implementation. The 87-page framework addresses AI-specific cyber risks including data poisoning, model drift, and bias, while providing practical tools for managing AI systems throughout their lifecycle from assessment to decommissi
Family Medicine Centers Pays $2.15M to Resolve Data Breach Lawsuit
Family Medicine Centers (FMC Services, LLC) has agreed to a $2.15 million settlement to resolve consolidated class action lawsuits stemming from a July 2022 data breach that exposed personal and health information of approximately 234,000-267,000 individuals. The breach involved unauthorized access to network systems containing Social Security numbers, birth dates, addresses, and protected health