Please review the Cybersecurity Advisory and share it with teams at your hospital, including IT.
Cybersecurity

Cyber Threat Intelligence, Alerts and Reports
As part of the AHA’s commitment to helping hospitals and health systems prepare for and prevent cyber threats, we have gathered the latest government cyber threat intelligence and alerts and Health Information Sharing and Analysis Center (H-ISAC) reports.
You may be asked to enter your AHA member credentials to view certain reports and intelligence alerts.
Cybersecurity & Risk Advisory
Learn how AHA can help hospitals and health systems prepare for and mitigate cyber threats through the expertise of John Riggi, AHA’s National Advisor for Cybersecurity and Risk.
PaperCut Software has issued an urgent security advisory confirming that its security response teams are actively investigating in-the-wild exploitation of a vulnerability affecting PaperCut NG and PaperCut MF Application Servers.
The FBI and the Department of Justice Aug. 26 announced the disruption of a China-linked hacking group known as QTFY. The group, which also identifies as QT and QTCYBER, has targeted hospitals and health systems, as well as government services and facilities, communications, energy, information…
The Federal Bureau of Investigation, National Security Agency, and Cyber National Mission Force are releasing this joint cybersecurity advisory to alert organizations concerning China-linked cyber threat actors, who use the acronyms QTFY, QT, and QTCYBER for themselves and their tools and have…
Boston Scientific, a large supplier of medical devices, said in an Aug. 26 statement posted on its website that on Aug. 25 it “identified a cybersecurity incident affecting certain information technology systems that resulted in a network outage and disruption to the company’s operations.”
TLP green FBI FLASH regarding Chaos Ransomware Threat Actors impersonating IT support and using artificial intelligence tools.
A daily ransomware tracker at TLP Green to increase awareness of the ransomware threat.
Epic’s MyChart has shared examples from potential phishing schemes observed as recently this month that include email messages linking to a fake MyChart website displaying erroneous medical records and others notifying of a free “2026 Medicare Health Kit.”
Voice Security: Protecting Patients, Care Teams & Critical Communications While Building Physician Engagement Healthcare's Most Overlooked Cybersecurity RiskTuesday, October 20, 2026 1 - 2 p.m. Eastern; noon - 1 p.m. Central; 10 - 11 a.m. Pacific
On August 22, 2026, threat actors linked to the extortion group ShinyHunters executed a targeted social engineering campaign against ReliaQuest using voice phishing and lookalike single sign-on (SSO) infrastructure.