Security Resource Center

Discover the latest healthcare cybersecurity best practices, HIPAA compliance guidance, ransomware prevention strategies, and security trends affecting today’s healthcare organizations. Our Security Resource Center provides practical insights to help you make informed cybersecurity decisions with confidence.

Your Healthcare Firewall Protects the Perimeter

Who Protects the Microservices Inside? A Look Into Optimal Healthcare Microservices Security 

Healthcare microservices security requires organizations to think beyond the traditional network perimeter as patient portals, billing systems, APIs, analytics platforms, and other applications move into cloud-native environments. A public-facing healthcare application may be protected by a web application firewall, strong authentication, and continuous monitoring while still depending on dozens of interconnected services behind the scenes.

Read More »
Verifiable data destruction in healthcare

Beyond Delete: Why Verifiable Data Destruction in Healthcare Matters

Verifiable data destruction in healthcare addresses a deceptively simple question: when an organization deletes patient information, can it prove that the information is actually unrecoverable? Healthcare organizations across the United States accumulate enormous volumes of information across EHR platforms, billing applications, cloud environments, patient portals, backups, analytics systems, employee devices, and third-party services.

Read More »
CVE-2026-60004

CISA Flags CVE-2026-60004: Why Healthcare Organizations Should Check Their Gitea Exposure Now

CVE-2026-60004 deserves immediate attention from healthcare cybersecurity teams because it has moved beyond a theoretical software vulnerability. On August 25, 2026, CISA added the critical Gitea vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog based on evidence that attackers are exploiting it in the wild. That changes how healthcare organizations should prioritize the vulnerability.

Read More »
adversarial ai

Adversarial AI in Healthcare: How Medical Imaging Attacks Could Undermine Clinical Decision-Making

Adversarial AI in healthcare introduces a new cybersecurity challenge that reaches beyond stolen data and ransomware. As hospitals, physician practices, imaging centers, and health systems adopt artificial intelligence for medical imaging, documentation, billing, scheduling, and clinical decision support, they must also protect the information being fed into those systems. If attackers can manipulate AI inputs without noticeably changing what clinicians see, they may be able to influence the output of systems that support patient care.

Read More »
session cookie security in healthcare

Session Cookie Security in Healthcare: Why MFA Alone Cannot Stop Session Hijacking

Session cookie security in healthcare addresses a critical part of identity protection that begins after a user successfully completes login and multi-factor authentication. Hospitals, physician practices, medical billing companies, specialty clinics, and other healthcare organizations increasingly rely on browser-based patient portals, cloud EHR systems, scheduling platforms, claims tools, and administrative applications.

Read More »
AI Bill of Materials in healthcare

AI Bill of Materials in Healthcare: Why Healthcare Organizations Need Visibility Into the AI Supply Chain

An AI Bill of Materials is an emerging approach to documenting the components, dependencies, and lineage associated with an artificial intelligence system. The concept shares similarities with a Software Bill of Materials (SBOM), which provides visibility into software components and dependencies. An AIBOM expands that concept to address characteristics specific to AI systems.

Read More »
Securing the Network Edge

Securing the Network Edge in Healthcare: Why Routers, VPNs, and Firewalls Are Becoming Prime Cyber Targets

Healthcare organizations rely on network-edge technology to connect clinics, support telehealth, enable remote work, exchange data with partners, and maintain access to cloud applications. These technologies help small and medium-sized healthcare organizations deliver care more efficiently, but they also expand the number of systems attackers can target. Each new connection can become another potential pathway into the environment if it is not properly secured.

Read More »
Vulnerability scan vs penetration testing

Vulnerability Scan vs. Penetration Testing: Which Healthcare Cybersecurity Assessment Does Your Organization Need?

Healthcare organizations continue to face increasing pressure from ransomware groups, financially motivated cybercriminals, insider threats, and sophisticated nation-state actors. At the same time, the healthcare technology landscape continues expanding through Electronic Health Records (EHRs), cloud-based applications, patient portals, telehealth platforms, remote work solutions, and third-party vendor integrations.

Read More »