Breach Autopsy: Abbott Shows Legacy Healthcare Systems Carry Their Own Blast Radius Abbott's two-incident investigation shows why healthcare breach scope depends on legacy systems, portals, and inherited data boundaries.
The Docket: OCR Turned Ransomware Into Security Rule Evidence OCR's four ransomware settlements show how post-attack facts can reveal whether Security Rule discipline existed before the incident.
Breach Autopsy: Change Healthcare and the $22M Ransom That Broke US Pharmacies When a single ransomware attack on a healthcare clearinghouse disrupts prescriptions nationwide, the third-party risk math changes.
Breach Autopsy: Balance Autism and the Hidden Cost of Vendor Email Compromises When a vendor's compromised email becomes your class action lawsuit - Balance Autism's settlement shows why vendor access control is a legal liability, not just a security one.
The Docket: Eight-Month Notification Delays Are Not Anomalies Anymore Three healthcare breaches announced the same week with similar delays. The notification timeline is the second vulnerability.
Breach Autopsy: When Your Ransomware Settlement Costs More Than Your Security Budget Long Island Plastic Surgical Group settled a BlackCat ransomware class action for $2.6M. That's a lot of money to pay for security you should have had upfront.
Breach Autopsy: Stryker and the Wiper Problem Here is the part nobody wants to admit: the breach was not the surprise. The timeline was.