< ciso
brief />
Tag Banner

All news with #hipaa tag

27 articles

Practical IAM Compliance: Requirements and Best Practices

🔐 This guide defines IAM compliance as proving that identity and access controls are not only documented but enforced across users, applications, infrastructure, and non-human identities. It explains key obligations from frameworks like SOX, PCI DSS, HIPAA, ISO/IEC 27001, NIST SP 800-53, and GDPR, and highlights evidence gaps between policy intent and runtime execution. The article outlines core controls—least privilege, segregation of duties, MFA, lifecycle management—and urges continuous, application-layer verification rather than periodic reviews.
read more →

AWS PCS expands security and compliance coverage

🔒 AWS Parallel Computing Service (PCS) has broadened its compliance posture to support regulated workloads. PCS is now in scope for FedRAMP Class C in US East (Ohio), US East (N. Virginia), and US West (Oregon), and FedRAMP Class D in AWS GovCloud (US). PCS is included in SOC 1/2/3 reports, ISO certifications, CSA STAR (CCM 4.0), PCI attestations, and is HIPAA eligible, enabling sensitive HPC workloads on AWS.
read more →

HIPAA Security Rule Technical Safeguards on AWS

🔒 This new guidance helps covered entities and business associates implement and evidence compliance with the HIPAA Security Rule Technical Safeguards (45 CFR §164.312) when building healthcare workloads on AWS. It explains the five standards and nine implementation specifications for access control, audit controls, integrity, authentication, and transmission security. The document also addresses proposed 2025 NPRM changes—such as mandatory encryption, MFA, and new network and configuration controls—and recommends treating all specifications as required for new workloads.
read more →

MCBS network breach exposes over 1.26M records

🔒 Medical billing firm Medical Computer Business Services (MCBS) disclosed a 2025 network breach that exposed data for 1,261,464 individuals. The intrusion, occurring between September 22–26, 2025, potentially exposed sensitive information including Social Security numbers, dates of birth, medical histories, and insurance identifiers. MCBS identified seven covered entities whose patient records it processed and urges affected individuals to consider fraud alerts or credit freezes. The PEAR ransomware group claims responsibility and says 3.3 TB of data was exfiltrated and leaked.
read more →

AWS HealthOmics private workflows expand to regions

🧬 AWS HealthOmics private workflows are now available in the Asia Pacific (Tokyo) and US East (Ohio) Regions, extending access to fully managed bioinformatics pipelines for research, drug discovery, and agricultural science with regional compliance. The HIPAA-eligible service supports domain-specific languages like Nextflow, WDL, and CWL, and includes Git integrations and Amazon ECR container support to simplify migration and maintain data provenance.
read more →

AWS guidance for HITRUST i1 compliance on cloud

🛡️ This post announces a new AWS compliance implementation guide: HITRUST i1 Compliance on AWS: Customer Implementation Guidance with an Illustrative Healthcare Platform. The guidance helps healthcare organizations bridge requirements and practical implementation on AWS, covering 11 HITRUST i1 technical domains. It uses a realistic example platform deployed on AWS Landing Zone Accelerator to make control mapping concrete while noting scoping remains organization-specific.
read more →

Xsolis data breach compromises 1.4M patient records

🔒 Xsolis, a U.S. healthcare technology provider, detected a targeted phishing attack that led to unauthorized access to parts of its network in January 2026. The company says files containing sensitive customer information—such as names, addresses, dates of birth, insurance details, Social Security numbers, and medical treatment data—were accessed, affecting 1,396,519 individuals. Xsolis contained the breach, engaged external cybersecurity experts, reset user passwords, enhanced monitoring, accelerated employee security training, and is notifying impacted individuals with offered identity monitoring services.
read more →

HealthOmics adds ephemeral scratch storage for workflows

🧬 AWS HealthOmics now provides ephemeral local scratch volumes for individual workflow tasks, mounted at /tmp, to improve performance for bioinformatics workloads such as sequence alignment, BAM sorting, and variant calling. Each task gets 16 GiB by default at no extra charge, with configurable sizes up to 3,072 GiB via WDL, Nextflow, or CWL directives and enabled at runtime using the StartRun API. Volumes are encrypted and deleted on task termination, and the feature is available in all Regions where HealthOmics operates. HealthOmics is HIPAA-eligible and designed to accelerate managed bioinformatics workflows for healthcare and life sciences customers.
read more →

AWS HealthOmics adds real-time engine log streaming

📡 AWS HealthOmics now streams workflow engine logs to Amazon CloudWatch in real time, enabling customers to monitor workflow execution progress as it happens. This HIPAA-eligible service helps healthcare and life sciences teams accelerate bioinformatics workflows with immediate access to orchestration events, task scheduling details, import/export activity, and full stack traces on errors. Streamed logs support CloudWatch alarms, dashboards, and integration with observability tooling for faster debugging and iterative development.
read more →

AWS HealthLake Adds CMS-0057-F FHIR API Support

🩺 AWS HealthLake now natively supports payer compliance with the CMS Interoperability and Prior Authorization Final Rule (CMS-0057-F), requiring four standardized FHIR-based APIs by January 1, 2027. The release implements Patient Access, Provider Access, Payer-to-Payer, and Prior Authorization APIs using CARIN, DaVinci, and SMART standards, and adds metrics and consent integrations. It is HIPAA-eligible and available in multiple AWS Regions.
read more →

Cloud Infrastructure as the Foundation for Digital Health

🏥 The post argues that modern cloud infrastructure is the superior foundation for regulated Software as a Medical Device (SaMD), enabling faster innovation while meeting regulatory obligations. It outlines regulatory shifts in early 2026, including the FDA's QMSR alignment with ISO 13485 and the EU AI Act's applicability for high-risk systems. The author advocates Compliance as Code and describes three architectural planes—data, control, and evidence—on Google Cloud to deliver continuous audit readiness. It also highlights AI-driven monitoring and a shared fate model between cloud providers and manufacturers.
read more →

7 Biggest Healthcare Security Threats and Emerging Risks

🔒 Cyberattacks on healthcare have surged since COVID-19, driven by telehealth adoption, cloud migration, and interconnected medical devices. Experts identify seven primary threats — ransomware, cloud misconfigurations, web application exploits, bad bots, phishing, insecure smart devices, and generative AI misuse — that target EHRs, PHI, and clinical availability. Under-resourced teams and extensive third-party dependencies amplify the operational and patient-safety impacts.
read more →

AWS Launches VPC Encryption Controls in GovCloud US

🔒 AWS VPC Encryption Controls is now available in AWS GovCloud (US-East) and GovCloud (US-West). The feature lets security teams enable monitoring and enforcement of encryption in transit across existing VPCs, automatically identifying flows that permit plaintext. It transparently activates hardware-based AES-256 encryption across VPC resources (including Fargate, NLB, and ALB) and produces audit logs to help demonstrate compliance with standards such as HIPAA, PCI DSS, FedRAMP, and FIPS 140-2.
read more →

AWS HealthOmics Adds VPC-Connected Bioinformatics Workflows

🧬 AWS HealthOmics now supports VPC-connected workflows, allowing bioinformatics pipelines to access AWS resources across regions and public internet resources through a customer VPC. New Configuration APIs let teams specify VPCs and manage public internet dependencies at a per-run level without changing workflow code. This capability is HIPAA-eligible and available in all HealthOmics regions.
read more →

AWS HealthOmics Launches Batch Run for Genomics Workflows

🧬 AWS announced that HealthOmics now supports batch run submission, enabling customers to submit up to 100,000 runs of a workflow in a single request. All runs in a batch share a common configuration with optional per-run overrides for specific sample inputs or parameter values. The batch APIs provide full lifecycle management—including a batch ID for tracking, bulk cancel/delete, and progress monitoring—to simplify orchestration and troubleshooting. The feature is available across all HealthOmics regions and the service is HIPAA-eligible.
read more →

TriZetto Provider Solutions Breach Exposes 3.4M Patients

🔒 TriZetto Provider Solutions (TPS) has reported a breach that impacted more than 3.4 million individuals after suspicious activity was detected in a customer-facing web portal on 2 October 2025. TPS confirmed that no payment card or bank account data were taken, but said names, addresses, dates of birth, Social Security numbers and health insurance identifiers may have been accessed. The company, owned by Cognizant, says it is working with law enforcement, has implemented additional security measures and is offering credit monitoring to those affected.
read more →

AWS Backup adds PrivateLink support for SAP HANA on EC2

🔒 AWS Backup now supports AWS PrivateLink for SAP HANA systems running on Amazon EC2. This lets customers route backup traffic over private VPC endpoints instead of the public internet, helping meet security and compliance requirements for regulated workloads. Organizations subject to HIPAA, PCI DSS and privacy frameworks can maintain end-to-end private connectivity for both application and backup data. The feature is available in all AWS Regions that support SAP HANA on EC2; to enable it, update the Backint agent and add the backup-storage VPCE to your VPC.
read more →

CISOs: Move Beyond Compliance to Anticipate Risk in 2026

🔒 CISOs entering 2026 should treat compliance as a baseline, not a destination. While frameworks like HIPAA, SOC 2 and ISO 27001 provide essential controls, relying solely on checklists breeds complacency and misses evolving threats such as AI-enabled attacks, third-party failures and future quantum risks. Adopt longer time horizons, scenario-based risk assessments and financial impact modelling to align security with business priorities and secure board support.
read more →

AI Agents Are Rewriting Compliance Controls—CISOs Must Act

🛡️ AI agents are being embedded into regulated workflows and are forcing a rethink of controls designed for human actors, including SOX, GDPR, PCI DSS, and HIPAA. Because agents act, adapt, and drift, controls that once relied on predictable human behavior can silently fail, collapsing segregation of duties and exposing sensitive data. CISOs should treat agents as non-human identities with least‑privilege access, strong credential management, continuous monitoring, and robust logging and change governance to keep regulated workflows auditable and defensible.
read more →

Anthropic Brings Claude to Healthcare With HIPAA Tools

🔒 Anthropic is expanding Claude into healthcare with HIPAA-ready enterprise tools and new healthcare-specific connectors. It can access the CMS Coverage Database to check Medicare coverage rules, support prior authorization, and look up ICD-10 codes. Anthropic says deployments can help revenue cycle, credentialing, and reduce claim errors.
read more →