Skip to main content

CareScope Watch

What changed, and what it means for you

Every note here points back to a primary document — a rule, an advisory, a filing — so you can check the source yourself and decide how much of your week it deserves.

Cybersecurity/Sep 11

CISA Adds ConnectWise ScreenConnect Flaw to Exploited Vulnerabilities List

CISA added three vulnerabilities to its Known Exploited Vulnerabilities Catalog based on evidence of active exploitation. The additions include an improper privilege management and missing authorization vulnerability in ConnectWise ScreenConnect (CVE-2026-84869), alongside two authorization and authentication flaws in JFrog Artifactory.

What it means

Cybersecurity/Sep 10

Orthanc DICOM Server Vulnerable to Denial-of-Service Flaw

A vulnerability in Orthanc DICOM Server versions prior to 1.13.0 allows an authenticated remote attacker to trigger a heap out-of-bounds write. The issue stems from an integer overflow in pitch and buffer-size computation when decoding an attacker-supplied PNG or JPEG image. Exploitation crashes the Orthanc process, causing a denial-of-service condition.

What it means

Cybersecurity/Sep 10

CISA Warns of Actively Exploited MikroTik RouterOS Vulnerabilities

CISA has added two MikroTik RouterOS vulnerabilities to its Known Exploited Vulnerabilities Catalog due to evidence of active exploitation. The flaws include CVE-2026-67277, a missing authentication vulnerability for a critical function, and CVE-2026-86060, an improper neutralization of argument delimiters in a command.

What it means

Compliance/Sep 4

Information blocking expectations keep tightening

The federal information blocking rules require that patients and their designated recipients get electronic access to their records without unnecessary delay, and enforcement attention has continued to grow rather than fade.

What it means

Compliance/Aug 28

Risk analysis remains the most common enforcement finding

HHS Office for Civil Rights resolution agreements continue to cite an incomplete or missing security risk analysis as a root finding, often alongside missing multi-factor authentication on remote access.

What it means

Compliance/Aug 20

Website tracking on patient-facing pages is still a live risk

Federal guidance on online tracking technologies used by covered entities has been litigated and revised, but the underlying exposure has not changed: analytics and advertising tags on patient-facing pages can transmit identifiable information to third parties.

What it means

AI & AI Scribes/Aug 13

The list of authorized AI-enabled medical devices keeps growing

The FDA maintains a public list of AI-enabled medical devices that have been authorized for marketing, and it continues to expand across imaging, cardiology, and ophthalmology.

What it means

Cybersecurity/Aug 6

Attackers keep using vulnerabilities that already have patches

CISA's Known Exploited Vulnerabilities catalog lists flaws confirmed to be under active exploitation. A recurring share of them are in remote access and file transfer products used by small organizations, and patches existed before the attacks.

What it means

Compliance/Jul 30

NIST's updated security rule guidance is the practical checklist

NIST Special Publication 800-66r2 maps the HIPAA Security Rule to concrete cybersecurity practices, including risk assessment steps and safeguard selection for organizations without security staff.

What it means