Healthcare IT News 2026/07/26

Samwise Healthcare IT Newsletter

Sunday, July 26, 2026

Healthcare IT  ·  Cybersecurity  ·  Policy  ·  AI Analytics  ·  Interoperability
All your morning news, carefully curated and summarized daily
CYBERSECURITY

Patient Files Federal Class Action Lawsuit Against Abbott Labs, Exact Sciences After ShinyHunters Data Theft

A patient filed a federal class action lawsuit against Abbott Laboratories and its Exact Sciences cancer diagnostics unit after the ShinyHunters gang claimed responsibility for a data theft. The suit, filed by Brian Troesch in Illinois federal court on July 22, alleges Abbott and Exact Sciences failed to implement adequate data security safeguards. Abbott acknowledged July 16 it is investigating unauthorized access to legacy Exact Sciences systems, which were kept separate from Abbott’s main infrastructure after Abbott completed its acquisition of the Wisconsin cancer testing company in March 2026. The lawsuit seeks lifetime credit monitoring and identity theft insurance for all affected patients.

Sources: GovInfoSecurity

AI/ANALYTICS

Johns Hopkins Medicine Benchmarks AI Agents Before Deployment, Prioritizing Governance Over Quick ROI

Johns Hopkins Medicine is taking a deliberately measured approach to agentic artificial intelligence, prioritizing reliability benchmarking and governance over financial returns. Working with the actAVA platform, the health system is evaluating AI agents designed to automate policy-dense administrative workflows, including revenue cycle management, patient access and care coordination. Hopkins leaders say the first challenge is proving frontier agents can complete end-to-end tasks — not just isolated demos that look impressive but fall short in practice. The effort reflects growing urgency among large health systems to establish governance frameworks before AI agent deployments scale across administrative operations.

Sources: Healthcare IT News

CYBERSECURITY

Healthcare Providers Addressed Only 6% of Cyber Risks in First Half of 2026 as Supply-Chain Vulnerabilities Jumped Sixfold

Healthcare organizations addressed only 6 percent of identified cybersecurity risks in the first half of 2026, down sharply from 23 percent in the same period of 2025, according to Fortified Health Security. Supply-chain risks identified by providers rose sixfold year over year, with nearly two-thirds rated critical or high severity. Separately, 92 percent of healthcare network domains had at least one administrator account with a password unchanged for more than three years. The report flags a new and growing threat: non-human identities created by AI agents operating in administrative and clinical settings, which security programs have not yet adapted to govern.

Sources: Healthcare Dive

CYBERSECURITY

Healthcare Data Breaches Rose to 281 in First Half of 2026 as Insider Attacks Surged Sevenfold

Healthcare data breaches rose to 281 in the first half of 2026, up from 270 in the same period of 2025, according to the Identity Theft Resource Center. The sector ranked second among all industries, behind financial services at 387. Insider wrongdoing incidents surged to 21 cases through June, compared with three in all of 2025 — a rise the ITRC links to tech-sector layoffs and North Korean operatives posing as remote IT workers. Only 24 percent of breach notices disclosed how incidents occurred, down from 100 percent in 2020, limiting organizations’ ability to defend against similar attacks.

Sources: Becker’s Hospital Review

TELEHEALTH

Teladoc Launches AI-Powered “Teladoc One” Platform, Ties 100% of Fees to Patient Outcomes

Teladoc Health launched its redesigned virtual care platform, Teladoc One, on July 23, restructuring its business model to place 100 percent of fees at risk by linking payment directly to medical cost savings and clinical outcomes. The platform draws on a unified virtual care data ecosystem, using artificial intelligence-driven touchpoints that integrate health, claims and pharmacy data to deliver real-time guidance to caregivers. Teladoc designed Teladoc One to address fragmented care by serving the full spectrum of a patient’s potential health needs through a single connected system. The company says the move marks a shift to a new era of connected virtual care.

Sources: Healthcare IT News

CYBERSECURITYINFRASTRUCTURE

Craneware Discloses Cybersecurity Breach Affecting Employee, Customer and Partner Data at 2,000-Hospital Software Provider

Craneware, an Edinburgh, Scotland-based healthcare software company serving more than 2,000 U.S. hospitals and nearly 10,000 clinics and retail pharmacies, disclosed a cybersecurity incident on July 20 in a London Stock Exchange filing. Investigators found that a significant volume of file names were viewed and exfiltrated from a subset of the company’s data environment, including employee data and some customer and partner records. Craneware said the incident has been contained, customer services are unaffected, and external specialists confirmed no residual indicators of compromise remain. The company characterized a large portion of the exfiltrated data as non-sensitive or already public regulatory information.

Sources: Becker’s Hospital Review

AI/ANALYTICS

Digital Medicine Society Launches Initiative to Build Operational AI Governance Tools for Health Systems

The Digital Medicine Society launched Operationalizing AI Governance in Healthcare on July 21, a new initiative under its Connected Health Collaborative Community designed to build practical tools that health systems can use to evaluate, govern, monitor and integrate artificial intelligence. The effort responds to growing recognition among chief information officers that deploying AI is no longer the primary challenge — ensuring it remains accurate, transparent and accountable in clinical practice is. DiMe will channel insights from member organizations into a series of tools released in succession, addressing a gap in deployable governance infrastructure that health systems have struggled to close independently.

Sources: Healthcare IT News

POLICY

HHS Appeals Court Ruling That Struck Down Eight ACA Exchange Provisions Including Shorter Sign-Up Windows

The Department of Health and Human Services filed an appeal with the Fourth Circuit Court of Appeals on July 24, seeking to restore eight provisions of its 2025 Affordable Care Act exchange rule that a Maryland district court judge invalidated last month. The contested provisions include shorter enrollment sign-up windows and heightened eligibility verification that regulators say are needed to crack down on widespread fraud in the federal health insurance exchanges. HHS has argued the provisions are necessary to prevent improper enrollment and protect the integrity of ACA premium tax credits against fraudulent claims by ineligible applicants.

Sources: Healthcare Dive

Leave a Reply