|
|
The Privacy Risks of Embedded, Shadow AI in Healthcare
Attorney Elizabeth Hodge of Akerman LLP on Taking Action
Artificial intelligence stealthily embedded into newer editions of software and other technology tools is a risk on par with shadow AI, said regulatory attorney Elizabeth Hodge with the law firm Akerman LLP.
"There are applications, software, tools or services that vendors are providing that historically did not incorporate AI, but now they have," Hodge said. Sometimes the vendors will inform the customers, but sometimes they don't, she said.
So it's important to ask and scrutinize where vendors might be incorporating AI into their products, she said.
"Consider doing a risk analysis of which of those applications, products, services, etc. potentially use the most data, or would pose the greatest risk to the organization if data was used improperly," she said. "Focus on those vendors - reach out to them, have your information security team or contracts team review periodically your vendors," she said.
"Have them answer questions about their use of AI, so you have a better understanding of the risk."
To read this article in its entirety, please click:
The Privacy Risks of Embedded, Shadow AI in Healthcare
| | |
Is a publication provided by | |
Eminere Group is a leading assurance and advisory firm specializing in IT Governance, Risk Management, Cybersecurity, Privacy, Business Risk, Internal Audit Services, and Training.
We distinguish ourselves through our team of highly experienced professionals, all holding relevant certifications and extensive expertise.
Contact Us Here
| | |
|
Instructure Breach Exposes Schools' Vendor Dependence
ShinyHunters' attack on Instructure, which owns the widely used Canvas learning management system (LMS), carries big questions about the trust educational institutions put into their vendors.
The breach of a leading educational technology provider has raised fears and concerns regarding possible downstream implications for schools, their staff, and their students.
Instructure, which provides learning management system (LMS) software Canvas for K-12 and higher education clients, disclosed a data breach on May 1 in which a threat actor stole "certain identifying information of users at affected institutions," the company said on its status page. This identifying information includes names, emails, student ID numbers, and messages shared among users. There is no evidence passwords, dates of birth, government identifiers, or financial information were stolen, according to the disclosure.
To read this article in its entirety, please click:
Instructure Breach Exposes Schools' Vendor Dependence
| | |
|
AHA and Joint Commission Release Hospital Cyber Resilience Assessment Program
The Cyber Resilience Readiness (CRR) program includes a self-assessment and for $2000 you can add a self-assessment “expert” review.
Developed collaboratively by Joint Commission, the American Hospital Association (AHA), and in partnership with several healthcare organizations, CRR complements traditional cybersecurity approaches by emphasizing real-world operational readiness and patient safety impacts, rather than IT recovery alone. The goal is to help hospitals and health systems move from awareness to readiness, and from readiness to resilience, ultimately enabling organizations to move beyond assessment to practical, operational improvement.
For additional information, please see the following two resources:
Hospital Cyber Resilience Assessment Program
Joint Commission’s Cyber Resilience Readiness Program
| | |
|
Proof of Concept: Anatomy of a Breach - the Aftermath
Blackbaud's Attorneys Jon Olson and Ron Raether on Legal Risk, Trust and Recovery
After the immediate crisis passes, the legal and regulatory fallout of a breach begins. Lawsuits, regulatory scrutiny and reputational damage can unfold over years, often shaped by decisions made in the first hours after the incident.
Such was the case for philanthropy software leader Blackbaud, which suffered a high-profile ransomware attack in 2020. In this Proof of Concept on "Anatomy of a Breach," Blackbaud Chief Legal Officer Jon W. Olson and outside counsel Ron Raether explained why sustaining control in the aftermath of a breach requires disciplined communication, legal strategy and coordination across the business, cybersecurity and leadership teams.
"One of the things I found is that so much of what unfolds over the long endured period - the multiple years - are determined in the first few days. Even though the consequences unfold over time, the early framing decisions become anchors," Olson said.
Those early choices influence regulatory posture, litigation strategy and how trust is preserved or rebuilt with customers, partners and authorities.
To read this article in its entirety, please click:
Proof of Concept: Anatomy of a Breach - the Aftermath
| | |
|
Building Strategic Data Systems at Data Summit 2026
Strategic small-data systems can outperform large architectures when designed around the real problem, the real people, and the real business model.
At Data Summit 2026, Joseph Hilger, COO, Enterprise Knowledge, LLC, presented his session “Simplicity as Strategy: Building Data Systems People Actually Trust.”
The annual Data Summit conference returned to Boston, May 6-7, 2026, with pre-conference workshops on May 5.
“As I’ve talked to people it’s just more stuff, more stuff, and it’s not simple,” Hilger said. “Let’s learn how to make things simpler.”
The challenge is that many organizations’ data systems are overly large and complex, he explained.
“We have more data and more data sources,” Hilger said. “We have content that’s not organized.”
Complexity causes administrative burden and undue costs. Data managers and the information technology between data and decision makers cause time lags and errors. “Black box” systems lead to confusion and mistrust. Redundant data prevents both humans and AI from understanding and delivering answers, Hilger said.
To read this article in its entirety, please click:
Building Strategic Data Systems at Data Summit 2026
| | | | |