CareScope Watch/Compliance/August 28, 2026
Risk analysis remains the most common enforcement finding
HHS Office for Civil Rights resolution agreements continue to cite an incomplete or missing security risk analysis as a root finding, often alongside missing multi-factor authentication on remote access.
Why it matters
A risk analysis is the one piece of paperwork investigators ask for first. Practices that cannot produce a current one start every conversation behind.
What it means for your practice
Confirm you have a risk analysis completed within the last year, that it lists every system holding patient information, and that the findings have owners and dates. Pair it with multi-factor authentication on email and remote access.
Related product
Read our review of Compliancy GroupMore from the Watch
Cybersecurity/Sep 11
CISA Adds ConnectWise ScreenConnect Flaw to Exploited Vulnerabilities List
CISA added three vulnerabilities to its Known Exploited Vulnerabilities Catalog based on evidence of active exploitation. The additions include an improper privilege management and missing authorization vulnerability in ConnectWise ScreenConnect (CVE-2026-84869), alongside two authorization and authentication flaws in JFrog Artifactory.
What it meansCybersecurity/Sep 10
Orthanc DICOM Server Vulnerable to Denial-of-Service Flaw
A vulnerability in Orthanc DICOM Server versions prior to 1.13.0 allows an authenticated remote attacker to trigger a heap out-of-bounds write. The issue stems from an integer overflow in pitch and buffer-size computation when decoding an attacker-supplied PNG or JPEG image. Exploitation crashes the Orthanc process, causing a denial-of-service condition.
What it meansCybersecurity/Sep 10
CISA Warns of Actively Exploited MikroTik RouterOS Vulnerabilities
CISA has added two MikroTik RouterOS vulnerabilities to its Known Exploited Vulnerabilities Catalog due to evidence of active exploitation. The flaws include CVE-2026-67277, a missing authentication vulnerability for a critical function, and CVE-2026-86060, an improper neutralization of argument delimiters in a command.
What it means
