Oracle is beginning to turn into one of those cautionary case studies. And that’s not good news for healthcare. From their faltering EHR to the hacking of their software, Oracle’s news hasn’t been cheerful. While still profitable in the quarterly reports, the debt load and its obligations in their chosen wrenching changeover from a software developer/seller to an AI infrastructure landlord have been followed by speculation. The latest speculation from June is selling their EHR business [TTA 2 June]–if they can find a buyer. The EHR is a distant second to Epic in every metric [TTA 27 May] and Oracle... Continue Reading
Search Results for hacking
Chutes & Ladders: Done Global principals sentenced on Adderall fraud, Oracle E-Biz Suite hacked, OpenAI’s 5% offer to US government, Meta considers cloud AI, Pearl’s $110M raise
...Neither will be the last. DOJ and Federal agencies are cracking down hard on waste, fraud, and abuse in healthcare; major targets of DOJ/HHS/DEA scrutiny are telementalhealth and substance use disorder (SUD) management, including prescribing and payments. More to come. Another chute for Oracle, leading to the Hacking trap door. The vulnerability is within Oracle’s E-Business Suite (EBS) and affects the file transmission component of Oracle Payments payments. The flaw has been tracked as CVE-2026-46817 and carries a severity rating of 9.8 out of 10. 900 systems may be exposed, though Oracle flagged it in their May patch updates. The... Continue Reading
Chutes & Ladders: Xsolis data breach affects 1.4M records, Five Eyes warns of AI-supercharged hacking; FDA closes Whoop BP warning, Centene adds HR/finance exec to board; $120M raises for Assort Health, $46M for xCures
...records. Reports were submitted on 5 June to Health and Human Services’ (HHS) Office of Civil Rights (OCR). On 19 June, the California Attorney General’s Office posted a copy of the breach notification letter that Xsolis sent to its clients’ patients. To date, there have been no ransom or extortion demands nor dark web threats. Affected organizations have been reported as Rochester Regional Health with 18,600 patients affected, Mayo Clinic and VHC. DataBreaches.net, Yahoo News–TechRadar The multi-national data security alliance Five Eyes warns of AI supercharging hacking attacks. The three-page statement details how AI accelerates cybersec attacks and the need... Continue Reading
Amazon’s One Medical Seniors hacked by ShinyHunters, issues “final warning” on 8.8 TB of patient data
...notorious for taking credit for other attacks on healthcare organizations, always going big, then going home after gaining their ransom. Their last target was Medtronic, hacking 9 million patient records plus terabytes of corporate information in April [TTA 30 April]. After the leak information was pulled from their website, the conclusion was that Medtronic paid up. ShinyHunters also attacked dental benefits administrator DentaQuest earlier this year. Other big game: Zara, Carnival, 7-Eleven, Pitney Bowes, The Canada Life Assurance Company, and Hallmark. Amazon One Medical is staying mum, but this will be updated as additional information is disclosed. Cybernews, Healthcare IT... Continue Reading
(Updated) Medtronic reports corporate IT systems cyberattacked. 500K UK Biobank records breached in inside job. Are med device and research organizations the new hacker happy hunting ground?
...This fits a pattern of major healthcare hacking. Orthopedic medical device and robotics company Stryker was caught in a massive breach, wiping tens of thousands of systems and servers across the company’s network including applications such as Intune Company Portal, Teams, and VPN clients often used on personal devices. The perpetrator, Handala, is “linked to Iran’s Ministry of Intelligence and Security (MOIS) that targets Israeli organizations with destructive malware designed to wipe Windows and Linux devices.” This makes it political as a primary reason, economic secondary. [TTA 20 Mar] Corporate IT is more vulnerable than production or patient-facing systems, according... Continue Reading
Anne Wojcicki asks 23andMe bankruptcy court to reopen bidding on 12 June with fresh offer (updated with $305M bid)
...board, backed by effective full control over the public company via her special class of shares. Moreover, she has not taken any responsibility for mistakes, including the 2023 coverup of their database hacking that the company blamed upon users reusing passwords. Au contraire. Considering the above, it’s hard to believe that at this point that Anne Wojcicki and her bid, backed by an undisclosed company, would have any credibility with the court. But let’s see what the court says. We won’t have long to wait. Updated 5 June: Wojcicki has presented a $305 million bid to the court. Yahoo Finance... Continue Reading
Two other views on UnitedHealth Group’s annus horribilis, for your consideration
...like Kelsey Seybold that had profitable contracts with competitors like state Blues’ Medicare Advantage or their own plans (Kelsey)–which aren’t so profitable anymore. OptumInsight was decimated by hasty acquisitions–Equian, Change Healthcare, and naviHealth. It went from a 28% margin business to 16.5%. (Change Healthcare alone was responsible for a $2.9 billion loss.) Then Change’s ransomwaring and hacking proved that UHG was negligent in running that type of business. As stated before in writing about Change, UHG did not do its due diligence on the only partly digested meal-via-acquisition that Change really was, nor spent the two years before the cyberattack... Continue Reading
News roundup 22 May: an inflight ‘save’ and AliveCor’s KardiaMobile, rolling out the VA/Oracle EHR in ‘waves’, Fuze Health formed from LetsGetChecked/Truepill, hacking and ransomware 92% of PHI data breaches
...566 incidents in 2024, 457 were “IT incidents” and 61 were tagged as ransomware, totaling 92%. Despite the massive Change Healthcare breach, ransomware breaches fell to 11%. Considering patient records, there were 170 million breached in 2024 and hacking/IT incidents accounted for 91% of the total. Of 732 million records affected from 2010 to 2024, hacking or IT incidents and ransomware (considered as a subset) accounted for 88% (643 million) and 39% (285 million) of incidents. Since 2020, ransomware has affected more than half of all patients annually, reaching 69% in 2024–again, the effect of Change Healthcare. Also Healthcare Dive... Continue Reading
Breaking: 23andMe files for Chapter 11 bankruptcy–whither customer data and security? An impact similar to Theranos?
...fraud. Here, the founder and key shareholder is a mature wealthy woman who kept a fairly low profile, the technology worked, the consumer business broke fresh consumer ground and, for its time, getting your genetic information and ancestry was a popular concept. GSK’s five year deal was completed–not renewed, but no lawsuits ensued. What was way off was its $6 billion valuation in 2021 after its SPAC and IPO. Its faltering wasn’t news like Theranos or (for that matter) Walgreens either. The concatenation of failures along the way, save for the 2023-24 data breach/hacking which was news and drove away... Continue Reading
News roundup: DOJ investigating UHG on Medicare Advantage billing upcoding; Teladoc’s BetterHelp therapists using AI?–a short seller alleges; Hims whacked by FDA ending compounded GLP-1s (updated); some fired FDA staffers in CDRH reinstated
...on antitrust grounds. Optum’s Change Healthcare (contested by DOJ but approved) is still recovering from an unprecedented hacking and ransomwaring, with the huge expense of restoring systems plus notification and providing a reported 100 million with free credit monitoring services. The proposed $3.3 billion deal with Amedisys for home care continues to be delayed by the DOJ antitrust suit. Their UnitedHealthcare president was assassinated in New York, and his (alleged) killer is starting his trial here, a spectacle which will go into the summer. But the issue that supposedly tipped off the murder–claim denials and denials of care due to... Continue Reading



Most Recent Comments