Healthcare IT Newsletter — Saturday, July 4, 2026

Samwise Healthcare IT Newsletter

Saturday, July 4, 2026

Healthcare IT  ·  Cybersecurity  ·  Policy  ·  AI Analytics  ·  Interoperability
All your morning news, carefully curated and summarized daily
AI/ANALYTICS

AI's Expanding Role in Precision Oncology

AI is accelerating oncology decision-making — but physicians must remain central to patient care, according to Jim Foote, CEO of First Ascent Biomedical. In an ISMG interview, Foote discussed how artificial intelligence is transforming functional precision oncology by processing genomic data and surfacing clinical trial candidates faster than traditional methods allow. AI tools can identify treatment options from complex tumor biology datasets in hours rather than weeks. Foote emphasized the importance of healthcare AI oversight, noting that algorithms must be clinically validated before influencing treatment plans. As AI deepens its role in genomics and precision medicine, health systems face new governance questions that IT and clinical leadership must address together.

Sources: GovInfoSecurity   ✉︎ Email 💬 Text

CYBERSECURITY

FBI Disrupts Widely Used NetNut Residential Proxy Service

The FBI and private-sector partners have disrupted NetNut, described as one of the world's largest residential proxy networks, in an action with direct implications for healthcare cybersecurity. Residential proxy services route malicious traffic through unwitting users' internet connections, allowing cybercriminals to anonymize attacks on healthcare systems and evade IP-based security controls. Google researchers helped identify NetNut's infrastructure as enabling large-scale abuse. The takedown removes a key evasion tool used by threat actors targeting sensitive industries, including health systems and insurers. Healthcare security teams should review logs for connections to NetNut IP ranges, which were commonly used to disguise credential-stuffing campaigns targeting patient portals.

Sources: GovInfoSecurity   ✉︎ Email 💬 Text

CYBERSECURITY

ISMG Editors: Signs of Russia in Jaguar Land Rover Probe

The ISMG Editors' Panel examined new evidence suggesting Russian involvement in the Jaguar Land Rover cyberattack probe, alongside a separate discussion of Scattered Spider's role in the breach investigation. Editors also analyzed U.S. export controls on artificial intelligence, including restrictions affecting Anthropic, and their implications for technology sovereignty. Topics spanned post-quantum cryptography readiness, AI governance frameworks, the risks posed by agentic AI and shadow AI deployments, and the growing security challenge of non-human identities in enterprise systems. The panel's discussion of identity security and least-privilege principles is directly applicable to healthcare, where non-human identities in clinical workflows present expanding and underregulated attack surfaces.

Sources: GovInfoSecurity   ✉︎ Email 💬 Text

POLICY

Lawmaker Probing Pegasus Spyware Infected Using Same Malware

Multiple European lawmakers are calling for a fresh investigation into commercial spyware after a European Parliament committee member who was probing Pegasus was found to have been infected with the same surveillance tool. The revelations intensified calls for EU-wide regulatory action against Israeli-developed spyware platforms. Spyware poses a particular risk to healthcare institutions: clinicians and executives carry devices containing protected health information, and commercial surveillance tools could expose patient data or compromise clinical decision-making. The incident highlights systemic weaknesses in mobile device security governance that health system compliance officers are increasingly expected to address under existing privacy and security regulatory frameworks.

Sources: GovInfoSecurity   ✉︎ Email 💬 Text

CYBERSECURITY

How Renown Health Is Reshaping its Digital ID Strategy

Renown Health is reshaping its digital identity management strategy to reduce friction for clinicians while strengthening security, according to ISMG's HealthSec interview with Steven Ramirez of the Nevada-based health system. The initiative addresses both human and non-human identities, incorporates facial recognition for streamlined clinical access, and prepares the organization for AI-driven workflows. Ramirez described a multi-factor and risk-based authentication approach with particular attention to machine-to-machine credentials as AI agents take on greater roles in clinical operations. Healthcare identity security emerged as a central HealthSec topic, reflecting the sector's persistently high breach rate driven by credential theft and session hijacking targeting clinical staff.

Sources: GovInfoSecurity   ✉︎ Email 💬 Text

POLICY

Telehealth, IVF Services Tracked Visitors Online Without Consent

Australia's Privacy Commissioner has found telehealth provider Medmate and fertility service Monash IVF violated patient privacy by embedding third-party tracking pixels on their websites without consent. A year-long Office of the Australian Information Commissioner investigation concluded both organizations collected sensitive health data, failed to notify individuals, and used it for direct marketing without authorization. Both companies were ordered to stop using tracking pixels until proper consent mechanisms are in place and to destroy previously collected data. A separate OAIC survey of 50 health provider websites found 96% used tracking technologies, 52% deployed third-party pixels, and 77% of those failed to disclose the practice in their privacy policies.

Sources: Healthcare IT News   ✉︎ Email 💬 Text

CYBERSECURITY

Scattered Spider Suspect Extradited From Finland to US

Peter Stokes, 19, a suspected member of the Scattered Spider cybercrime group, has been extradited from Finland to face criminal charges in the United States. Scattered Spider — which uses social engineering and SIM-swapping tactics to compromise IT help desks — has documented healthcare targets, with prior members having pleaded guilty to conspiring to hack SSM Health Care and Sutter Health. The Finland extradition reflects intensifying international law enforcement cooperation against the group. Healthcare security teams should treat the prosecution trend as a signal to audit help desk social engineering controls and tighten SIM-swap defenses, particularly for accounts with access to clinical and administrative systems.

Sources: GovInfoSecurity   ✉︎ Email 💬 Text

INTEROP

Fewer Health Information Exchanges Say They Experience Info Blocking

The share of health information exchange organizations reporting potential information blocking has fallen from over 90% in 2019 to 71% in 2025, according to new Office of the National Coordinator for Health Information Technology data. Certified health IT developers remain the most commonly cited blockers: more than 60% of HIEs reported that developers sometimes or routinely hindered data flow in 2025. Despite the overall decline, roughly one in three HIEs still reports routine blocking by IT vendors — a rate unchanged over six years. The Trump administration has vowed to crack down, and ONC has indicated IT developers could lose certification for sustained blocking. The report may inform upcoming enforcement.

Sources: Healthcare Dive   ✉︎ Email 💬 Text