
Hosted by Paubox · EN
Fully Automated is your weekly rundown of the biggest healthcare cybersecurity stories, delivered in a conversational format by Alex and Jen, two AI hosts who break down breaches, vulnerabilities, and compliance news with clarity, a little dark humor, and always a practical takeaway. Perfect for healthcare IT leaders, administrators, and compliance officers who want to stay informed without wading through the noise.

In this episode, Alex and Jen discuss a major breach affecting 542,000 individuals at Centers Laboratory, a $500,000+ ransomware settlement involving a Pennsylvania treatment facility, and the HHS delay of the final HIPAA Security Rule update to 2027. They also cover practical tools like the new Paubox Email API template gallery and emphasize how consistent security fundamentals can prevent costly incidents.

This episode examines three emerging cybersecurity threats affecting healthcare organizations: Microsoft 365 Groups being exploited for calendar-based phishing attacks, newly discovered vulnerabilities in the widely used DICOM Toolkit that could impact medical imaging systems, and a data breach that originated through social engineering targeting third-party applications. The hosts provide actionable guidance on tightening platform configurations, vetting vendors, and strengthening staff training to address these preventable security gaps.

In this episode, Jen and Alex discuss Paubox's new MFA options, the ShinyHunters breach involving legacy Iora Health data, World Cup-related phishing scams, and a Senate bill addressing cybersecurity risks in Chinese-made medical devices. The hosts emphasize the importance of addressing legacy systems, conducting thorough asset inventories, and implementing foundational security controls to protect patient data.

In this episode, we cover emerging threats targeting healthcare and enterprise organizations, including AI platform impersonation scams, the ShinyHunters attacks on Oracle PeopleSoft systems, and research showing AI email agents are vulnerable to phishing. We also discuss Paubox joining LegitScript's Compliance Collective and the Novo Nordisk clinical trial data breach investigation. Key takeaways include verifying AI tool sources, reviewing legacy system configurations, and applying least-privilege principles to AI agents.

In this episode, we discuss Paubox Forms' new conditional logic feature, the Conduent breach affecting 62 million people, and critical findings from controlled tests revealing Amazon SES may transmit PHI in plaintext despite documentation claims. We also cover recent ransomware incidents at Mt. Baker, Northwest Radiologists, and Singing River Health System, along with key takeaways from the June Zoom social mixer on AI tooling and vendor management strategies for small IT teams.

This episode examines recent healthcare data breaches and settlements, including the $4 million IBJI case involving extended attacker dwell time, Mission Community Hospital's $1.5 million RansomHouse extortion settlement, and third-party vendor risks exposed by the La Perouse billing breach. We also discuss Rutgers University research showing hospitals using third-party tracking pixels are 46 percent more likely to experience breaches, emphasizing the critical need for system patching, vendor oversight, and web property audits.

In this episode, Alex and Jen discuss new Paubox product updates including a Forms template library and API dashboard improvements, then analyze recent healthcare data breaches affecting Esse Health, Gandara Mental Health Center, and NYC Health + Hospitals. The conversation highlights common security gaps, the growing risk of third-party vendor breaches, and practical steps organizations can take to strengthen their compliance and security posture.

This episode covers the new Paubox CLI support for Forms, the LockBit 5.0 ransomware attack on Mt. Spokane Pediatrics affecting over 32,000 patients, a CISA-flagged vulnerability in medical imaging software, and the FBI warning about the Kali365 phishing-as-a-service platform targeting Microsoft 365 credentials. The hosts discuss the security gaps facing small clinics and emphasize actionable steps including patching systems, network segmentation, and staff training to address these evolving threats.

In this episode, Jen and Alex break down the surge in QR code phishing attacks, the cautionary tale of a ransomware negotiator who defrauded healthcare clients, and practical strategies for reducing security friction. They also cover new tools for HIPAA-compliant email automation and self-service archive exports that streamline compliance workflows.

In this episode, we break down the SAG-AFTRA Health Plan's $950,000 phishing settlement, Medtronic's nine-million-record breach, and the Inc Ransom attack on Sandhills Medical Foundation. We also highlight Henderson Behavioral Health's patient-centered approach and discuss practical takeaways for strengthening your organization's security posture through staff training, system patching, and incident response planning.