Intel Hub

Healthcare Security Intelligence Hub

Resources for healthcare IT and security teams — from small practices to regional health systems. Ransomware defense, BEC response, HIPAA security monitoring, and what modern healthcare cybersecurity actually looks like.

Why Healthcare Security Is Different

Healthcare cybersecurity isn't just IT security with HIPAA checkboxes added. The threat model is different: ransomware in a hospital isn't a business continuity problem, it's a patient safety problem. Business email compromise targeting healthcare billing workflows has led to multi-million dollar fraud cases. Unauthorized EHR access can run undetected for months.

The security tools and practices that protect a retail business don't map cleanly onto a medical practice or health system. EHR systems, clinical devices, and the 24/7 operational requirements of patient care require a different approach to monitoring and response.

This hub covers the tactics, techniques, and procedures (TTPs) used against healthcare organizations — plus the detection and response approaches that actually work. We publish here because the threat landscape doesn't stop evolving, and annual security reviews don't keep pace.

If you manage security for a healthcare organization and want to discuss what coverage looks like for your environment, book an assessment.

Latest Healthcare Security Articles

Rhysida Ransomware Leaks 6TB of Berlin State Data After 30 BTC Ransom Refusal — Detection and Hardening Guide

Rhysida ransomware dumped nearly 6TB of Berlin state administration and defense data after the city refused a 30 BTC ransom. Here's how to detect and stop this playbook.

Sep 7, 2026

Debian DSA-6486-1: libde265 H.265 Codec Flaws Enable DoS and Arbitrary Code Execution — Patching and Detection Guide

Two flaws in Debian's libde265 H.265 codec library allow denial of service and potential code execution via malformed media. Patch trixie systems now.

Sep 6, 2026

Why Dependency Modernization in Security Tools Matters: Lessons from Malwarebytes' Engineering Overhaul

Malwarebytes' dependency modernization effort is a reminder that outdated components in security products are attack surface — here's what defenders should demand from vendors.

Sep 6, 2026

Infostealers Target Claude AI Sessions, Fire Ant Hits Hypervisors, ValleyRAT Poses as Adware: Defender's Guide to Round 113 Malware Campaigns

Infostealers are now hijacking Claude AI login sessions, Fire Ant is burrowing into hypervisors and trusted infrastructure, and ValleyRAT hides inside fake adware. Here's how to detect and stop them.

Sep 6, 2026

THEGENTLEMEN Ransomware Gang: 5 Victims in 5 Days — Transportation, Healthcare & Technology Under Active Fire

THEGENTLEMEN posted 5 victims across 4 countries in 5 days, hitting Transportation, Healthcare, Retail, and Tech. Enterprises with exposed VPNs, RDP, or unpatched KEV flaws should hunt now.

Sep 5, 2026

Token Research Exposes 39 Passkey Attack Methods: A Defender's Guide to Hardening FIDO2 Deployments

Researchers at Token have documented 39 techniques that compromise passkey authentication without breaking FIDO2 cryptography — targeting enrollment, sync, recovery, and user prompts. Here's how to detect and defend.

Sep 4, 2026

Resource Center of Dallas Breach: 12,500 Patients Notified — Healthcare Detection and Hardening Playbook

Resource Center of Dallas has notified 12,500 patients of a cyber incident exposing PHI. Here's what healthcare SOC teams must hunt for and harden right now.

Sep 4, 2026

IDScan Breach: 153 Million Driver's Licenses Allegedly Stolen — Third-Party PII Exposure Response Guide

Identity verification vendor IDScan faces lawsuits after attackers allegedly exfiltrated 153M+ driver's license records. Here's how to assess exposure and hunt for bulk PII theft.

Sep 4, 2026

Frequently Asked Questions

Protect Your Healthcare Organization

Book a security assessment to review your current posture and identify the gaps that matter most for your environment.