Clearwater is pleased to participate in the Digital Health Market NYC Symposium, hosted by the Center for Telehealth & e-Health Law (CTeL) and Nixon Peabody LLP.
ADSO Summit 2026 | June 15–17, 2026 | Chicago, IL
Clearwater looks forward to engaging with industry leaders on the evolving cybersecurity and compliance landscape impacting physician groups, ambulatory organizations, and dental platforms.
Agentic AI in Healthcare: Navigating Regulatory Uncertainty and Building Governance That Lasts
AHLA’s Speaking of Health Law | Sponsored by Clearwater Artificial intelligence in healthcare has crossed a threshold. The question for CISOs, compliance officers, and health system counsel is no longer whether agentic AI will enter clinical and administrative...
Advisory for AI-Driven Vulnerability Discovery
Published April 29, 2026 Anthropic’s Project Glasswing signals a structural shift in vulnerability discovery. AI models are finding and enabling the exploitation of software flaws faster than human teams can respond. Anthropic’s Project Glasswing signals an...
Advisory for Microsoft Teams Helpdesk Impersonation Attacks
Published April 24, 2026 Microsoft has recently warned of an increase in real‑world cyberattacks abusing Microsoft Teams external chat to impersonate IT helpdesk personnel. In these incidents, attackers pose as trusted internal support staff and persuade users to...
HIPAA Security Rule Enforcement: Where Things Stand in 2026
Update — July 2026: The Department of Health and Human Services (HHS) has pushed final action on the HIPAA Security Rule overhaul to at least July 2027 in its updated federal agenda, moving ahead separately with HIPAA Privacy Rule changes expected as early as...
Understanding CMS’s Health Technology Ecosystem Initiative: Legal, Policy, and Interoperability Risk
AHLA’s Speaking of Health Law | Sponsored by Clearwater The CMS Health Technology Ecosystem Initiative signals a broader shift in how health data is expected to move across providers, payers, networks, and consumer-facing tools. In this episode of AHLA Speaking of...
SQL Injection in OpenEMR Identified and Recommendations
This post documents a blind time-based SQL injection in the PostCalendar module discoveredin OpenEMR 8.0.0. The SQL Injection is exploitable by an authenticated admin user and illustrates how a single determined attacker with a valid session can move from nuisance to...
Mythos and Like AI Tools Raise Stakes for Healthcare Cyber
Experts Warn of Faster and Higher Volume Attacks, Rising Patient Safety Worries
Identity Under Pressure: Why Access Management Is Now a Patient Safety Issue in Healthcare
For years, healthcare cyber risk was framed around the perimeter. Firewalls. Endpoints. Network defenses. The digital equivalent of locked doors and reinforced windows. That model no longer reflects how healthcare operates. Care now runs across cloud platforms, EHRs,...