by Lisa Munro | Sep 11, 2025 | Blog
If you’ve been tracking New York’s hospital cybersecurity rules, you know the clock has already been ticking. Last October (2024), hospitals were forced to tighten their response times with a new 72-hour cyber incident reporting rule. That change is already reshaping...
by Lisa Munro | Aug 28, 2025 | Blog
How clever text inputs can turn your AI assistants into security vulnerabilities By Philip Burnham, PNPTPrincipal Consultant, Technical Testing Services Introduction: Why Prompt Injection Matters in Healthcare Healthcare organizations are rapidly deploying AI chatbots...
by admin | Aug 19, 2025 | Blog
By Porter Throckmorton, CRTO, OSCP, CBBH, PNPT, eWPTSenior Consultant, Technical Testing Services It is likely you have seen the number 1 in an alert box if you have ever had a penetration test performed on your web application. The alerted number is the most common...
by Kim Singletary | Aug 4, 2025 | Blog
A review of OCR Enforcement Findings from 2025 (March-July) OCR’s latest enforcement push is driving healthcare organizations to conduct a thorough review of their HIPAA risk analysis to find any weaknesses or gaps — before the agency does. OCR Risk Analysis update...
by Lisa Munro | Jun 2, 2025 | Blog
Late last year, the US Department of Health and Human Services (HHS) introduced a more prescriptive regulatory framework for the HIPAA Security Rule, which comes at a critical time. As the industry faces unprecedented numbers of breach-related sensitive record...
by Lisa Munro | May 19, 2025 | Blog
By Fabian Crespo, OSEP, OSCP, CRTOPrincipal Consulting, Technical Testing In our Clearwater Monthly Cyber Briefings, we often emphasize that today’s cyberattacks don’t always begin with a high-profile perimeter breach. More often, they start quietly, with a single...