Samwise Healthcare IT Newsletter
Monday, July 13, 2026
AI Tools Are Putting Healthcare Vendors in Hackers’ Crosshairs
The U.S. Department of Health and Human Services had logged 351 major health data breaches in 2026 as of this week, affecting nearly 20.7 million people — with third-party business associates linked to 41 percent of incidents and about 9.94 million of those affected. Security experts warn that rapidly advancing AI tools capable of generating exploit code, automating reconnaissance and identifying vulnerabilities will intensify those attacks. AI-aided attackers can impact an organization within 27 minutes of initial access. The concentration of risk around third-party service providers is expected to grow further as vendors handle progressively larger volumes of protected health information.
Sources: GovInfoSecurity Share ↗ ✉︎ Email 💬 Text
Federal Regulators Delay HIPAA Security Rule Overhaul Until Mid-2027
The Department of Health and Human Services' Office for Civil Rights has pushed back a sweeping overhaul of the HIPAA Security Rule until at least July 2027, abandoning a May 2026 target after receiving nearly 5,000 public comments. Healthcare industry groups argued the proposed changes — which would convert previously optional safeguards including multifactor authentication, data encryption and network segmentation into mandatory requirements — were too costly and difficult to implement on the proposed timelines. HHS moved the rulemaking to “long-term actions” on Reginfo.gov, signaling a final rule is more than a year away. OCR still plans to finalize updates to the HIPAA Privacy Rule in August.
Sources: Becker's Hospital Review Share ↗ ✉︎ Email 💬 Text
Medtronic Begins Notifying 3.8 Million Patients of April Data Breach Claimed by ShinyHunters
Medtronic began notifying approximately 3.8 million patients that their personal information was compromised in an April data theft attack claimed by ransomware gang ShinyHunters. An unauthorized party accessed certain Medtronic corporate IT systems from April 13 to April 19, with the company noting that products, manufacturing operations and hospital customer networks were not affected. ShinyHunters claimed to have stolen more than 9 million records. State attorney general filings confirmed tens of thousands of affected residents in Massachusetts, Vermont and Texas. The company is offering 24 months of complimentary credit monitoring, dark web monitoring and identity theft restoration services to affected individuals.
Sources: GovInfoSecurity Share ↗ ✉︎ Email 💬 Text
Epic Expands Four Executives’ Roles as President Sumit Rana Steps Down in August
Epic CEO Judy Faulkner tapped four senior leaders to take on expanded responsibilities following President Sumit Rana’s decision to leave the company. Rana announced in an email to Epic’s 14,000 employees on July 3 that he would step down on August 14 after more than two decades with the company, citing family responsibilities following his father’s death. The four executives stepping up are Seth Howard, executive vice president of research and development, and senior vice presidents Mark Lipsky, Erv Walter and Garrett Adams. Epic did not name a replacement president. Rana had been widely viewed as a potential successor to Faulkner, who is 82.
Sources: Fierce Healthcare Share ↗ ✉︎ Email 💬 Text
AI Hallucinations Are Forcing Healthcare CIOs to Rethink Governance and Trust
As generative AI embeds itself across clinical workflows, healthcare chief information officers report that the central challenge has shifted from deploying new tools to ensuring those systems remain accurate, transparent and accountable in practice. Hallucinations — plausible AI outputs that contain false or unsupported information — are surfacing in clinical documentation and other healthcare applications, forcing CIOs to rethink governance, validation and trust frameworks. Many organizations cannot confidently answer a fundamental question: where exactly is AI influencing patient care? Success, CIOs say, will be measured not by speed of deployment but by whether systems remain transparent, auditable and clinically trustworthy throughout their operational life.
Sources: Healthcare IT News Share ↗ ✉︎ Email 💬 Text
AdaptHealth Discloses Patient Data Stolen Through Social Engineering Attack on Third-Party Contractor
AdaptHealth, a supplier of home medical equipment, disclosed that a threat actor gained unauthorized access to cloud-based company systems through a social engineering attack on a third-party contractor’s account, exfiltrating patient health information and stored passwords associated with insurance billing. The company determined on June 27 that the incident was material and filed an 8-K disclosure with the Securities and Exchange Commission on July 2. Accessed systems included internal patient management platforms and document storage. AdaptHealth said it does not collect Social Security numbers in the affected systems. The company promptly disabled the compromised account and implemented additional access controls.
Sources: Healthcare Dive Share ↗ ✉︎ Email 💬 Text
Linux Foundation Launches Open Health Stack Software Foundation With Google and WHO
The Linux Foundation announced Thursday plans to launch the Open Health Stack Software Foundation, a vendor-neutral, community-governed initiative designed to address the fragmented state of digital health infrastructure that impedes interoperability and limits health system adoption of emerging technology. Google, the World Health Organization and other contributors are backing the effort, which centers on three technical pillars including AI Commons — a model-agnostic space for safe, effective and verifiable AI in global health developed jointly with WHO. Google provided a $3 million grant to support long-term development. The foundation aims to provide developers and health organizations with shared, standards-based, open-source tools.
Sources: Healthcare IT News Share ↗ ✉︎ Email 💬 Text
Health Systems Shift to Long-Term IT Workforce Investments to Meet AI and Cybersecurity Demand
Health systems across the United States are making longer-term investments in their technology workforces in 2026, shifting away from reactive hiring toward building sustainable talent pipelines, leadership structures and internal expertise as digital transformation accelerates. The push is driven by growing pressure to implement AI tools, strengthen cybersecurity defenses and compete for specialized talent in an increasingly tight labor market. Smaller and rural health systems may struggle to match the resources larger organizations can devote to workforce development and AI leadership expansion. In February, Care New England announced a partnership with Rhode Island College to train healthcare IT professionals in cybersecurity, artificial intelligence and Epic EHR systems.
Sources: Becker's Hospital Review Share ↗ ✉︎ Email 💬 Text
Curated by JD · samwise.agency

Leave a Reply
You must be logged in to post a comment.