惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

F
Fox-IT International blog
Recent Announcements
Recent Announcements
D
Docker
IT之家
IT之家
B
Blog
Jina AI
Jina AI
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
博客园 - 【当耐特】
Google DeepMind News
Google DeepMind News
F
Fortinet All Blogs
量子位
C
Check Point Blog
Microsoft Azure Blog
Microsoft Azure Blog
罗磊的独立博客
博客园 - 司徒正美
李成银的技术随笔
美团技术团队
Blog — PlanetScale
Blog — PlanetScale
雷峰网
雷峰网
The GitHub Blog
The GitHub Blog
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
J
Java Code Geeks
T
The Blog of Author Tim Ferriss
酷 壳 – CoolShell
酷 壳 – CoolShell
MongoDB | Blog
MongoDB | Blog
P
Proofpoint News Feed
L
LangChain Blog
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
Y
Y Combinator Blog
大猫的无限游戏
大猫的无限游戏
有赞技术团队
有赞技术团队
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
V
Visual Studio Blog
T
Tailwind CSS Blog
H
Help Net Security
Engineering at Meta
Engineering at Meta
小众软件
小众软件
B
Blog RSS Feed
Stack Overflow Blog
Stack Overflow Blog
月光博客
月光博客
M
Microsoft Research Blog - Microsoft Research
宝玉的分享
宝玉的分享
人人都是产品经理
人人都是产品经理
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
GbyAI
GbyAI
H
Hackread – Cybersecurity News, Data Breaches, AI and More
Last Week in AI
Last Week in AI
Martin Fowler
Martin Fowler
Stack Overflow Blog
Stack Overflow Blog

BankInfoSecurity.com RSS Syndication

How AI Is Improving SAST Accuracy and Reducing Developer Friction Freight Hacker Wields Code-Signing Service to Evade Defenses The Future of Modern Observability Why Data Trust Is Key to AI Success Your Fraud Detection Model Is Already Too Late to the Party Why Data Protection Vendor Commvault Is Eyeing Going Private Webinar | Agentic AI vs. Identity’s Last Mile Problem Live Webinar | Do You Really Know Your Risk? Rethinking Cyber Risk in the Age of AI What CISOs Need to Know About AI Risk US FCC Grants Netgear Temporary Exemption from Router Ban Artemis Gets $70M to Build AI Agents for Detection, Response Federal Staffers Are Still Using Claude Despite Trump Orders Why Cloud Intrusions Still Evade Detection FDIC: Supervisory Approach to Payment Processing Relationships with Merchant Customers FFIEC: Statement on End of Microsoft Support for Windows XP OnDemand | Why SecOps and GRC Still Struggle to Align in Financial Services FDIC Issues Guidance to Areas in Illinois Impacted by Severe Storms Pentagon Memo Blasted Anthropic for PR Campaign Studies: Banks Penalize Bad Cybersecurity With Higher Rates Project Glasswing Just Made Your Security Playbook Obsolete CrowdStrike Tests Claude Mythos for Vulnerability Detection FDIC: Institutions Encouraged to Work with Borrowers Impacted by Shutdown Turning Military Experience Into Cyber Advantage Simplify Your Approach to Securing OT Networks Why 'Emerging Threats' Are Harder to Prioritize in the AI Era The End of Static Security: Why AI Demands Real-Time Microsegmentation Bug Management in the Mythos Era: 'Assume You're Unpatched' Regulation Didn’t Change, Your Identity Landscape Did OnDemand | Why SecOps and GRC Still Struggle to Align in Financial Services Live Webinar | Cloud-Conscious Intrusions: How to Detect and Contain Attacks in Seconds with CrowdStrike and Google Cloud Why Data Security Standards in Cancer Innovation Matter How Main Line Health Secures Devices With Microsegmentation Why Claude Mythos Shifts Focus From Finding to Fixing Bugs Live Webinar | Safeguarding the Hybrid Attack Surface from AI-Enabled Adversaries Breach Roundup: Mr. Raccoon Wants Your Password CISA Warns of 'Detrimental Capacity Impacts' Amid Shutdown OpenAI Courts Banks in Trusted Access for Cyber Partner Push Rethinking Cybersecurity for AI Speed in the Mythos Era Beyond Mythos: A Defining Moment for Cybersecurity Europe Spurs Digital Sovereignty With $213M Cloud Contract Moving Toward Identity Intelligence in Fraud Detection ISMG Editors: Adapting to the Looming Mythos AI Onslaught Maximizing Mythos Returns Requires AI Cybersecurity Pipeline Scattered Spider Hacker Pleads Guilty in US Federal Court Finance Chiefs Warn New AI Models May Rattle Global Banking Healthcare Cyber Research Programs Escape Budget Knife Pentagon Cyber Leaders Back $1.5T Budget Request Cyber threats are rising. Your headcount isn’t. Airbus Acquires Quarkslab to Counter AI Reverse Engineering US OPM Health Insurance Data Collection Plan Draws Concern How to Secure AI Agents and Machine Identities at Enterprise Scale What the AI Mirror Reveals About How We Think Report: Discord Group Uses Claude's Supposedly Secret Mythos UK: Russian Hacking Reaches New Levels of Hostility Why AI-Driven Arms Race Needs Better Threat Intelligence Pharma Giant Merck and Google Cloud Sign $1B Agentic AI Deal Why Cisco Is Eyeing Buy of Non-Human Identity Startup Astrix Unwary Chinese Hackers Hardcoded Credentials into Backdoors UK Cyber Spooks: 'Is Your Computer Monitor Spying On You?' Webinar | SASE Outlook 2026 and Beyond: Top 5 Predictions and Trends Cryptohack Roundup: US-Sanctioned Grinex Hacked Trump's Top Cyber Nominee Withdraws After Turbulent Process Hacked Devices Are Gateways for Chinese Nation-State Hackers Germany Tries, Tries Again With ISP Data Retention Mandate Doctor Lobby Urges Congress to Set AI Chatbot Safeguards Breach Roundup: Myanmar Scam Compound Managers Charged Cloudsmith Raises $72M for Software Supply-Chain Security White House Warns of AI Model 'Extraction' Campaigns Flurry of Supply-Chain Software Library Attacks Setbacks Cost Healthcare Firms $1.7M in HIPAA Fines The Rise of 'Shadow AI Agents' Inside Enterprises TekStream Targets Proactive Security With ImagineX Cyber Buy Poor Risk Analysis Cost 4 Firms $1.7 Million in HIPAA Fines CISA Hunts for Cisco Backdoor Spotted on Federal Network ISMG Editors: The Push for AI Innovation - and the Fallout Is Your IAM Ready for AI? Home Security Firm ADT Breach: 5.5M Customers' Data Exposed AI Red Teaming Is Not Equal to Prompt Injection Crypto-Targeting North Koreans Wield Fake Zoom Meetings Medical Device Maker Medtronic Says It's Been Hacked Pentagon's Anthropic Fight Draws Rebuke From Ex-DOD Leaders Breaking the Endpoint Tax: Aligning Security With Risk The Evolution of Scattered Spider: How Organizations Are Strengthening Defenses Researchers Find 38 Flaws in OpenEMR. They've Been Fixed AI Agent Wipes Startup's Data in 9-Second API Call Webinar | The Next Wave of Identity Risk: Securing Non Human Identities in an AI Driven World OT Cybersecurity Frozen Out by Frontier Labs Germany Caught Up in Likely Russian Signal Phishing AI Governance Moves From Theory to Practice Google Bets Up to $40B on Anthropic as AI Compute Race Grows Webinar | Governing AI at Scale: Building Trust, Control, and Confidence in Banking Europe Gliding Toward Mandatory Online Age Verification Webinar | Exposing the Security Gaps Behind AI Agents and Shadow Identities US FDA Piloting Use of AI for 'Real-Time' Clinical Trials UK Biobank Health Data Listed for Sale on Alibaba OpenAI Trades Azure Exclusivity for Enterprise Reach Live Webinar | Protecting OT Systems after Windows 10 End of Support Live Webinar | Safeguarding the Hybrid Attack Surface from AI-Enabled Adversaries Silverfort Purchases Fabrix to Bring AI to Access Decisions FBI-Backed Takedown Hits Crypto Scam Centers
HSCC Guide Targets Third-Party AI Risk in Healthcare
2026-04-16 · via BankInfoSecurity.com RSS Syndication

3rd Party Risk Management , Artificial Intelligence & Machine Learning , Governance & Risk Management

Playbook Aims to Help Healthcare, Public Sector Manage AI Vendor Security Gaps (HealthInfoSec) • April 15, 2026    
HSCC Guide Targets Third-Party AI Risk in Healthcare
The Health Sector Coordinating Council has issued new guidance to help healthcare and public health sector organizations manage an explosion of AI vendor cyber risk. (Image: HSCC)

A deluge of artificial intelligence embedded into software and devices means a new horizon of cyber risks for the healthcare sector. The Health Sector Coordinating Council on Wednesday released guidance to help the sector better manage AI third-party risk concerns.

See Also: Know Thy Enemy: Threats to Cyber Resilience

From AI-enabled remote patient monitoring to electronic health record systems containing natural language processing engines, the healthcare sector now finds itself relying on critical functions powered by AI tools. But third-party security, data governance practices and model integrity are difficult to verify, the organization said.

Risk is compounded by complex layered healthcare supply-chains that include subcontractors, offshore developers and open-source technology.

The 109-page guide provides advise to manage AI-supply chain related risks, said Samantha Jacques, vice president of clinical engineering at McLaren Health and vice chair of the HSCC cybersecurity working group that produced the document.

"This guide is useful for all size organizations and they can use the pieces and parts that work for their organizational processes, or adopt the entire process as a whole," said Jacques, a co-lead in the development of the guidance. "Each organization is at a different place for AI adoption and this guide is meant to enhance them, wherever they are in their journey."

The vast majority of healthcare organizations have partnered with a third party to design and implement AI solutions, said Rob Suarez, vice president and CISO at insurer CareFirst BlueCross BlueShield. "While we move at light-speed, these are in fact still early days of AI," said Suarez, a contributor to the new guide.

"Healthcare organizations require clear answers to what third party suppliers of AI are and are not doing; and how we can collectively protect patients, their health and financial wellbeing," he said. "We can't protect what we don't know," he said. The healthcare industry must understand and clarify with AI vendors if patient health information is used and how the risks managed, he said.

The guide draws from established frameworks, including the National Institute of Standards and Technology's AI Risk Management Framework and the voluntary Health Industry Cybersecurity Practices established by HSCC and the U.S. Department of Health and Human Services, Jacques said.

The playbook offers tactical guidance for governance, risk and compliance practices that CISOs and security teams can implement, addressing related issues involving AI tech - such as patching and legacy product concerns, she said.

Compliance teams also can use the guidance for recommended business associate agreement AI tips; legal and supply chain teams can tap the guide's AI contract terms AI governance leadership teams within organizations can use the training curriculum to help train users, she said. The guide is aimed to be useful for the entire AI-supply chain process, from procurement through implementation and de-installation at end of life, she said.

In addition to the AI supply chain guidance, HSCC also published a companion glossary of AI cyber terminology and definitions for healthcare clinical, operational, compliance, and technical stakeholders.

"Healthcare organizations benefit from clarity on the terminology we use in the world of AI and what that means in the context of these other healthcare oriented AI resources," Suarez said.