Samwise Healthcare IT Newsletter
Monday, August 3, 2026
ShinyHunters Hack of DentaQuest Triggers Notifications to 15 Million Patients
DentaQuest, the dental and vision benefits administrator owned by Canada's Sun Life Financial, is notifying roughly 15 million patients that their personal and health information was stolen in a May hack claimed by extortion gang ShinyHunters. The breach is on track to rank as the largest U.S. healthcare data incident of 2026, and the fourth-largest in the history of federal HIPAA breach reporting. ShinyHunters published an alleged 234-gigabyte sample of the data after DentaQuest declined to pay a ransom. The stolen records include names, addresses, dates of birth, Social Security numbers, and health insurance details. Affected patients span Texas, Massachusetts, South Carolina, and other states.
Sources: GovInfoSecurity
Survey: 88% of Healthcare IT Leaders Say Infrastructure Is Not AI-Ready
A survey of 300 healthcare IT professionals by enterprise cloud software company Nutanix found that 88 percent say their current infrastructure is not fully prepared to support on-premises artificial intelligence workloads. Published July 31, the report found that healthcare organizations are deploying AI pilots faster than their data foundations, network capacity, and governance frameworks can reliably support. Concerns about shadow AI — staff using unapproved AI tools — ranked among the top worries cited by respondents. Authors concluded that governance, containerization, and hybrid cloud infrastructure will determine whether AI pilots evolve into durable enterprise programs rather than stalling in proof-of-concept phases.
Sources: Healthcare IT News
MaineHealth Cuts 83 IT and Analytics Positions in AI-Driven Reorganization
MaineHealth is eliminating 83 positions in its information technology and analytics departments as part of a reorganization intended to consolidate three operational teams into one. The Portland, Maine-based health system is cutting 56 IT roles and 27 of 63 analytics positions, while creating 36 redesigned analytics roles for which affected employees may apply. No patient-facing positions are included. MaineHealth spokesperson John Porter attributed the restructuring to changing federal reimbursement policies and the growing role of artificial intelligence in automating functions previously handled by large support teams. Affected staff will receive transition support as the consolidation is completed over four to six weeks.
Sources: Healthcare IT News
Healthcare Tops All Industries in Data Breach Costs for 13th Straight Year: IBM Report
Healthcare recorded an average data breach cost of $6.64 million in 2026, marking the industry's 13th consecutive year as the costliest sector for breaches, according to IBM's annual Cost of a Data Breach Report released July 29. The figure is down 10.5 percent from $7.42 million in 2025, though analysts note the decline partly reflects lower-severity incidents compared to prior-year mega-breaches. Globally, average breach costs across all industries rose 12 percent to $4.99 million. Attackers continued to target patient personally identifiable information, which commands premium prices for identity theft and insurance fraud. Financial services ranked second at $6.29 million per breach.
Sources: Becker's Hospital Review
HIPAA Security Rule Overhaul Pushed to Mid-2027 After Nearly 5,000 Public Comments
Federal regulators have pushed the finalization of a major overhaul to the HIPAA Security Rule to July 2027, according to an updated regulatory agenda published by the U.S. Office of Management and Budget. The proposed rule, originally issued by HHS in January 2025, would eliminate the distinction between required and addressable implementation specifications, mandate encryption of electronic protected health information at rest and in transit, and require multi-factor authentication organization-wide. HHS had previously indicated a May 2026 target for a final rule. Healthcare organizations, hospitals, and industry groups submitted nearly 5,000 public comments opposing various provisions, citing compliance costs and operational disruption.
Sources: Fierce Healthcare
CMS Finalizes 2.3% Hospital Inpatient Pay Increase for Fiscal Year 2027
The Centers for Medicare and Medicaid Services on July 31 finalized an inpatient hospital payment rate increase of 2.3 percent for fiscal year 2027, affecting acute care and long-term care facilities nationwide. The final rule reflects a 3.2 percent annual market basket update offset by a 0.9 percentage point productivity adjustment, and is expected to result in a $2.1 billion overall year-over-year increase in hospital payments plus roughly $779 million in additional payments tied to inpatient cases involving new medical technologies. CMS also updated a mandatory payment model for joint replacements, delaying the start of its expanded Comprehensive Care for Joint Replacement initiative to January 1, 2028.
Sources: Becker's Hospital Review
PeaceHealth to Hand Off IT Support Services to Tech Mahindra Starting November
PeaceHealth, the Vancouver, Washington-based health system operating 10 hospitals across three states, will transition several IT support services to global IT firm Tech Mahindra and its U.S. healthcare subsidiary, The HCI Group, beginning in November. The health system said the move is designed to modernize IT services, improve system reliability, and give caregivers faster technical support. PeaceHealth will retain control of IT strategy, cybersecurity oversight, and vendor decisions, with patient data continuing to be hosted in the United States and on-site IT support remaining across all facilities. The organization has not yet finalized how many internal IT caregivers will be affected by the transition.
Sources: Becker's Hospital Review
Hospital Software Vendor Craneware Reports Data Theft Affecting Subset of 147M Patient Records
Craneware, the Edinburgh-based software vendor whose financial and pharmacy management tools are used by approximately 2,000 U.S. hospitals and health systems, disclosed July 20 that unauthorized actors accessed and exfiltrated a subset of its data environment, including employee records and a portion of customer and partner data. Craneware's 2021 acquisition of Sentry gave it custody of records linked to an estimated 147 million patients. The company told investigators that a minority of that total patient record count was affected, though the precise scope has not been quantified. External cybersecurity specialists confirmed the incident has been contained, with no disruption to customer operations or services.
Sources: Becker's Hospital Review
Curated by JD · samwise.agency

Leave a Reply
You must be logged in to post a comment.