<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Healthcare on CuraSec</title><link>https://curasec.metacog.co.kr/tags/healthcare/</link><description>Recent content in Healthcare on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Wed, 02 Sep 2026 15:05:08 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/healthcare/index.xml" rel="self" type="application/rss+xml"/><item><title>Aesto Health data breach exposes 9.5 million patient records</title><link>https://curasec.metacog.co.kr/insights/2026-09-02-aesto-health-says-data-breach-affects-over-9-5-million-patie/</link><pubDate>Wed, 02 Sep 2026 15:05:08 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-09-02-aesto-health-says-data-breach-affects-over-9-5-million-patie/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>SOC/IR — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Leader — Plan:&lt;/strong> A 9.5-million-patient breach at a healthcare services company is sector-level news; audit your vendor inventory for any Aesto Health dependency, confirm HIPAA BAA status, and assess whether downstream data exposure requires notification review.&lt;/li>
&lt;/ul></description></item><item><title>Novocure data breach exposes 1,400+ cancer patient records</title><link>https://curasec.metacog.co.kr/insights/2026-09-01-novocure-data-breach-affects-more-than-1-400-cancer-patients/</link><pubDate>Tue, 01 Sep 2026 15:28:52 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-09-01-novocure-data-breach-affects-more-than-1-400-cancer-patients/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> Healthcare sector breach with limited technical detail; no IOCs, TTPs, or detection artifacts published — monitor for follow-on disclosure with actionable indicators.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> A healthcare cyberattack exposing patient PII is a sector-relevant signal; if Novocure is a vendor or partner, confirm exposure and review their incident communications, but at 1,400 affected this is unlikely to be board-level.&lt;/li>
&lt;/ul></description></item><item><title>Nutex Health hospital operator confirms data stolen in cyberattack</title><link>https://curasec.metacog.co.kr/insights/2026-08-26-hospital-operator-nutex-health-says-data-stolen-in-cyberatta/</link><pubDate>Wed, 26 Aug 2026 11:42:13 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-26-hospital-operator-nutex-health-says-data-stolen-in-cyberatta/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>SOC/IR — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> A healthcare-sector peer breach involving exfiltrated data from hospital systems — useful context for board briefings on sector risk and a prompt to verify any Nutex Health service or data-sharing relationships your organization holds.&lt;/li>
&lt;/ul></description></item><item><title>SickKids data breach exposes employee and applicant PII via third-party flaw</title><link>https://curasec.metacog.co.kr/insights/2026-08-21-sickkids-data-breach-exposes-employee-and-job-applicant-info/</link><pubDate>Fri, 21 Aug 2026 11:38:25 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-21-sickkids-data-breach-exposes-employee-and-job-applicant-info/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>SOC/IR — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> A third-party software flaw exposed HR-category data (employee and applicant records) at a major hospital with no patient-record impact — a useful reference case for vendor risk assessments covering HR/recruiting platforms, particularly in healthcare.&lt;/li>
&lt;/ul></description></item><item><title>CareCloud data breach exposes 3.7 million patient records</title><link>https://curasec.metacog.co.kr/insights/2026-08-20-healthtech-firm-carecloud-data-breach-impacts-3-7-million-pa/</link><pubDate>Thu, 20 Aug 2026 11:39:11 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-20-healthtech-firm-carecloud-data-breach-impacts-3-7-million-pa/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> Large-scale healthcare breach worth noting for sector awareness, but no IOCs, TTPs, or detection surface are provided in this disclosure.&lt;/li>
&lt;li>&lt;strong>Leader — Act:&lt;/strong> If CareCloud is a vendor in your ecosystem, request their incident report and assess PHI exposure; healthcare CISOs should also brief leadership given HIPAA breach notification obligations and potential board or customer questions at this scale.&lt;/li>
&lt;/ul></description></item><item><title>Unlimited Technology Systems breach affects 3.8M healthcare records</title><link>https://curasec.metacog.co.kr/insights/2026-08-09-unlimited-technology-systems-breach-impacts-3-8-million-peop/</link><pubDate>Sun, 09 Aug 2026 11:41:42 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-09-unlimited-technology-systems-breach-impacts-3-8-million-peop/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> No IOCs or TTPs published; breach occurred in October 2025 with delayed disclosure — useful context on healthcare software supply-chain exposure but no detection action available.&lt;/li>
&lt;li>&lt;strong>Leader — Act:&lt;/strong> If your organization uses Unlimited Technology Systems or any of their healthcare software products, confirm exposure this week and request an incident report; the 3.8M-record scale and healthcare data sensitivity may trigger notification obligations or customer questions.&lt;/li>
&lt;/ul></description></item><item><title>MCBS medical billing data breach exposes 1.26M patient records</title><link>https://curasec.metacog.co.kr/insights/2026-07-28-data-breach-at-medical-billing-firm-mcbs-affects-1-26-millio/</link><pubDate>Tue, 28 Jul 2026 13:01:43 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-28-data-breach-at-medical-billing-firm-mcbs-affects-1-26-millio/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> No IOCs or TTPs published; this breach offers no immediate detection surface, but it reinforces the pattern of healthcare billing vendors as high-value targets worth monitoring for sector-specific threat campaigns.&lt;/li>
&lt;li>&lt;strong>Leader — Act:&lt;/strong> If your organization uses MCBS or similar third-party medical billing vendors, confirm whether you are among the 1.26M affected and request an incident attestation letter; this breach carries HIPAA notification obligations and may prompt patient or board inquiries.&lt;/li>
&lt;/ul></description></item><item><title>China-Nexus JadeProx Deploys New TriBack Loader Against Gov/Healthcare</title><link>https://curasec.metacog.co.kr/insights/2026-07-24-china-nexus-jadeprox-uses-new-triback-loader-in-government-a/</link><pubDate>Fri, 24 Jul 2026 12:43:46 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-24-china-nexus-jadeprox-uses-new-triback-loader-in-government-a/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> A newly documented Windows loader from a China-nexus cluster, but no specific vulnerable software, patch, or configuration action is identified — useful for understanding adversary tradecraft in government and healthcare environments.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> Group-IB&amp;rsquo;s exposure of the JadeProx cluster and TriBack Loader provides actor-profile and malware-family context, but the summary lacks published IOCs or ATT&amp;amp;CK-mapped TTPs needed to build or tune detections immediately.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> China-nexus targeting of government and healthcare sectors in Asia and Latin America is worth tracking for sector-risk awareness, but no vendor breach or imminent regulatory trigger warrants same-week leadership action.&lt;/li>
&lt;/ul></description></item><item><title>Abbott Laboratories probes two cyber incidents amid extortion claims</title><link>https://curasec.metacog.co.kr/insights/2026-07-18-abbott-probes-two-cyber-incidents-amid-extortion-claims/</link><pubDate>Sat, 18 Jul 2026 11:51:11 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-18-abbott-probes-two-cyber-incidents-amid-extortion-claims/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> Active investigation at a major healthcare vendor with confirmed unauthorized access and extortion claims, but no IOCs, TTPs, or ATT&amp;amp;CK-mappable behaviors have been published yet — nothing actionable to hunt or detect on today.&lt;/li>
&lt;li>&lt;strong>Leader — Act:&lt;/strong> Abbott confirmed unauthorized access to Exact Sciences legacy systems in its Cancer Diagnostics division and is probing a separate LabCentral portal breach with data-theft claims; if your organization uses Abbott lab or diagnostics services, confirm your exposure this week and request a written attestation of incident scope from your account contact.&lt;/li>
&lt;/ul></description></item><item><title>2026 HIPAA Security Rule Update Overview</title><link>https://curasec.metacog.co.kr/insights/2026-07-13-2026-hipaa-security-rule-update/</link><pubDate>Mon, 13 Jul 2026 13:18:50 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-13-2026-hipaa-security-rule-update/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> If you operate in a HIPAA-covered environment, review the updated Security Rule requirements this quarter and identify any new technical safeguards or control gaps to address before enforcement deadlines.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Leader — Act:&lt;/strong> Healthcare or health-data leaders should read the updated rule now, map changes to your current compliance posture, and brief legal/compliance on any new obligations or deadline-driven gaps before they surface in your next audit.&lt;/li>
&lt;/ul></description></item></channel></rss>