top of page
Search


What an Auditor Actually Looks For: Lessons From the Other Side of the Table
Most healthcare organizations prepare for an audit the way a student crams for an exam. They pull policies together, refresh a risk assessment, assemble a binder, and hope the questions land where they are strong. Then the proposed HIPAA Security Rule is going to make annual compliance audits a permanent fixture, and cramming does not survive an annual cadence. To pass every year, you have to understand what an auditor is actually looking for, and that looks very different fr

Rick Moore
19 hours ago4 min read


The End of "Addressable": Why the 2025 HIPAA Security Rule Turns Compliance Into an Engineering Discipline
For more than two decades, the HIPAA Security Rule gave healthcare organizations a quiet escape hatch. It was called "addressable." If a safeguard was labeled addressable rather than required, an organization could implement it, implement an equivalent alternative, or document why it was not reasonable and appropriate and move on. In practice, that flexibility became a loophole. Encryption was addressable. Multi-factor authentication lived in the gray space. Entire security p

Rick Moore
Aug 246 min read


Medusa Ransomware Has Compromised 500+ Organizations. Healthcare's Regulatory Environment Makes Your Response Window Far Shorter Than You Think.
When #CISA, #HHS, and the #FBI issue a joint advisory naming a specific ransomware group and calling out healthcare as a targeted sector, that is not a signal to schedule a review meeting. It is a directive to validate your controls this week. The #Medusa ransomware group has compromised more than 500 critical infrastructure organizations, and the federal government has been unambiguous: healthcare is in the target set. The question for every health plan, hospital system, and

Rick Moore
Aug 245 min read


When Your Vendor Gets Breached, You Own the Fallout: Lessons from the Aesto Health Incident
The Aesto Health data security incident is not a vendor problem. It is a governance problem, and every healthcare CIO, CISO, and board member who reads past the headline as though it belongs to someone else is making a strategic mistake. Aesto Health, a Birmingham, Alabama-based healthcare technology company, recently disclosed a breach that has compromised the protected health information of patients across multiple provider clients. The details are still emerging, but the p

Rick Moore
Aug 175 min read


When Marketing Broke HIPAA: What Five Pixel Settlements Mean for Healthcare Governance
Five healthcare providers have reached class action settlements in the past eighteen months over one issue: marketing teams deployed tracking pixels on patient-facing web properties without security review, without privacy oversight, and without Business Associate Agreements. That is not an IT failure. That is an organizational governance failure, and it carries price tags that belong in every board risk briefing this quarter. The stakes are no longer theoretical. Boards need

Rick Moore
Aug 105 min read


When the Threat Wears a Badge: Healthcare's Insider Risk Crisis Demands Executive Ownership
A new HIPAA Journal report documents what many of us in healthcare security have been tracking for years: a sustained surge in malicious insider incidents, running alongside a rise in mega data breaches, with 2026 on track to set records across both categories. For health system executives and boards still treating insider threat as an IT checkbox, this data demands a fundamentally different response. The Structural Problem Healthcare Cannot Outspend Healthcare's insider thre

Rick Moore
Aug 45 min read


The 23andMe Settlement Is Not a Consumer Privacy Story. It Is Your Vendor Risk Problem.
The $18 million multistate settlement reached between 23andMe and a coalition of 42 state attorneys general deserves more than a news cycle. For healthcare executives, it is a signal that the regulatory terrain around genomic and sensitive health data has permanently shifted, and most organizations are not positioned to respond. Background: Genomics Has Entered the Care Delivery Stack The 23andMe breach originated in October 2023 through a credential stuffing attack that expo

Rick Moore
Jul 235 min read


Atrium's $1.8 Million Pixel Settlement Is the Floor, Not the Ceiling
Charlotte-Mecklenburg Hospital Authority, operating as Atrium Health, recently agreed to pay up to $1.8 million to resolve a class action lawsuit arising from tracking pixels deployed on its patient-facing web properties. Those pixels transmitted protected health information to Meta, Google, and other advertising platforms without authorization. If your health system still has an unchecked pixel footprint on its website or patient portal, you are carrying a liability your boa

Rick Moore
Jul 215 min read


The Ransomware Attack Ends in a Week. The Lawsuit Takes Two Years.
Marlboro-Chesterfield Pathology has just received preliminary court approval to settle a class action arising from a ransomware breach that hit the organization in January 2025. The attack is 18 months in the rearview mirror. The legal and financial consequences are only now being finalized. For every healthcare executive who still thinks of ransomware as an IT problem that ends when systems are restored, this case is the correction you need. What Actually Happened, and Why t

Rick Moore
Jul 144 min read


When the Ransomware Writes Itself: What Autonomous AI Attacks Mean for Healthcare Governance
Researchers have now documented what many of us in healthcare security have been stress-testing as a near-term scenario: a fully autonomous, LLM-driven ransomware agent that conducted a complete attack campaign without a human operator directing a single step. This is not an academic thought experiment. It is an operational preview of the threat environment your security team will face, possibly before your organization's next board meeting. Healthcare executives need to hear

Rick Moore
Jul 65 min read


Remote Desktop Tools Are Healthcare's Front Door. Treat Them Like One.
The CISA Known Exploited Vulnerabilities catalog added SimpleHelp, a widely deployed remote support platform, this year after researchers confirmed an authentication bypass that allowed unauthenticated acceptance of OIDC tokens. That means an attacker can enter your vendor's remote support session without valid credentials. If you run remote support tools in your environment and you have not audited your vendor access pathways this week, that is where this post starts. Why Re

Rick Moore
Jun 305 min read


When Your AI Vendor Becomes Your Breach Vendor: The Xsolis Incident and What It Demands From Healthcare Leaders
The Xsolis breach is not another footnote in the HHS OCR breach portal. It is a signal that the threat model for healthcare organizations has fundamentally shifted, and most vendor risk programs have not kept up. When a single AI-powered business associate holds clinical and utilization data across multiple covered entities, a successful attack on that vendor is not a vendor problem. It is a system-wide PHI event affecting 1.4 million individuals across an unknown number of h

Rick Moore
Jun 295 min read


Amazon Bought Clinical Scale at One Medical. It Did Not Buy Clinical Security Maturity.
The ShinyHunters data extortion group has reportedly obtained 8.8 terabytes of data from One Medical, the Amazon-owned primary care provider, and is threatening to release it publicly. If even a fraction of that data contains protected health information, we are looking at one of the largest PHI exposure events in recent memory. Every health system executive, health plan board member, and digital health company leader should be paying attention, not because this is unpreceden

Rick Moore
Jun 235 min read


Business Associates Are Now the Weakest Link in Healthcare Security. Boards Need to Treat Them That Way.
The 2024 Verizon Data Breach Investigations Report put a number on something I have been telling healthcare executives for years: healthcare leads every major industry in third-party breach exposure. This is not a streak of bad luck. It is a structural failure in how covered entities manage their vendor ecosystems, and HHS OCR is running out of patience. The Vendor Layer Has Become Healthcare's Largest Attack Surface Healthcare's dependency on Business Associates is unlike an

Rick Moore
Jun 165 min read


MTC Group LLC is now a certified Service Disabled Veteran Owned Small Business (SDVOSB)
It took me several weeks of online information gathering/processing/submitting, but I'm now an officially recognized Veteran's...

Rick Moore
Dec 22, 20211 min read


Rick’s Read on Hiring & Leading Tech Talent
As an executive technology leader, I'm often asked how to build successful "tech teams." As I have moved into roles of greater...

Rick Moore
Sep 30, 20213 min read
bottom of page