Cybersecurity

Cyber Threat Intelligence, Alerts and Reports

As part of the AHA’s commitment to helping hospitals and health systems prepare for and prevent cyber threats, we have gathered the latest government cyber threat intelligence and alerts and Health Information Sharing and Analysis Center (H-ISAC) reports.

You may be asked to enter your AHA member credentials to view certain reports and intelligence alerts.

Cybersecurity & Risk Advisory

Learn how AHA can help hospitals and health systems prepare for and mitigate cyber threats through the expertise of John Riggi, AHA’s National Advisor for Cybersecurity and Risk.

Learn More

From March to November 2024, Health-ISAC held ten workshops as part of the Discussion Based Exercise Series, involving over 100 member organizations, potential members, and strategic partners.
On March 5, 2025, Microsoft released a report identifying the Silk Typhoon’s evolving tactics.
H-ISAC TLP Green Daily Cyber Headlines for March 6, 2025.
A daily ransomware tracker at TLP:GREEN for the purpose of increasing ransomware threat awareness.
In recent days, the AHA and the FBI have received multiple reports of hospitals and health systems receiving data extortion letters delivered through the U.S. Postal Service and originating domestically. The AHA has engaged with recipient organizations and the FBI on this issue.
H-ISAC TLP Green Daily Cyber Headlines for March 5, 2025.
A daily ransomware tracker at TLP:GREEN for the purpose of increasing ransomware threat awareness.
H-ISAC TLP Green Daily Cyber Headlines for March 4, 2025.
This week, Health-ISAC®'s Hacking Healthcare® examines a new policy shift that will affect how the public is able to interact with new rulemaking efforts coming out of the United States' Department of Health and Human Services. Join us as we breakdown what the new policy statement says and how it…
On March 4, 2025, Broadcom released an advisory (VMSA-2025-0004) prompted by the Microsoft Threat Intelligence Center’s disclosure of multiple, actively exploited, zero-day vulnerabilities affecting VMware ESXi, Workstation, Fusion, Cloud Foundation, and Telco Cloud Platform solutions.