> ## Content Index
> Fetch the complete content index at: https://www.cyberverso.net/llms.txt
> Use this file to discover other available public pages before exploring further.

# eHealth Cyber Brief — EU — 13 Sep 2026
- URL: https://www.cyberverso.net/ehealth/ehealth-cyber-brief-eu-13-sep-2026/
- Published: 2026-09-13T14:16:05.000Z
- Updated: 2026-09-13T14:16:04.000Z
- Description: Europe's hospitals absorbed another blow to patient privacy: France's data-protection regulator fined the Hôpital Privé de la Loire in Saint-Étienne €500,000 after a cyberattack exposed the health records of more than 727,000 people — one entry in a wave that has left European hospital IT…
- Author: Paolo De Rosa
- Tags: #bulletin, #ehealth

Europe's hospitals absorbed another blow to patient privacy: France's data-protection regulator fined the Hôpital Privé de la Loire in Saint-Étienne €500,000 after a cyberattack exposed the health records of more than 727,000 people — one entry in a wave that has left European hospital IT leaders warning that the rush to build the European Health Data Space is outpacing the cyber defences meant to protect it, with the EU's own security agency now ranking health in its cyber "risk zone." The extortion crews are circling the sector directly: Health-ISAC issued an urgent alert that ShinyHunters — the gang behind the McKesson mega-breach — is running voice-phishing campaigns and medical-themed impersonation domains against healthcare worldwide, talking staff past multi-factor authentication to loot cloud systems, and the wider spree pulled in the home-medical provider AdaptHealth (4.1 million people) and the health-tech firm Veradigm (a reported 3.5 million). And Europe moved to write the rules for medical AI: a UK national commission set out how AI-enabled medical devices should be regulated across their lifecycle — with continuous performance monitoring after deployment and accountability shared rather than pinned on a single clinician — a governance blueprint landing as regulators on both sides of the Atlantic race to catch a technology already in the clinic.

## Top Stories

- [National Commission into the Regulation of AI recommendations for shared responsibility, post-market surveillance, AI readiness](https://htn.co.uk/2026/09/10/national-commission-into-the-regulation-of-ai-recommendations-for-shared-responsibility-post-market-surveillance-ai-readiness/) — *HTN Health Tech News* · Health Policy & Regulation
- [France fines Hopital Prive de la Loire EUR 500,000 after breach exposes 727,000 patients](https://www.bleepingcomputer.com/news/security/cyberattack-at-french-hospital-exposes-health-data-of-750-000-patients/) — *BleepingComputer / CNIL* · Health Data & Breaches
- [Urgent Threat Alert: ShinyHunters Vishing Campaigns and Domain Impersonation](https://health-isac.org/urgent-threat-alert-shinyhunters-vishing-campaigns-and-domain-impersonation/) — *Health-ISAC – Health Information Sharing and Analysis Center* · Threat Intelligence (Health)
- [\[Comment\] Regulating artificial intelligence in health care: a tech-enabled, people-centred future](https://www.thelancet.com/journals/landig/article/PIIS2589-7500%2826%2900136-6/fulltext?rss=yes) — *The Lancet Digital Health* · Clinical AI & Safety
- [Orthanc DICOM Server Vulnerability Can Lead to Denial of Service](https://www.hipaajournal.com/orthanc-dicom-server-vulnerability-denial-of-service/) — *The HIPAA Journal* · Medical Devices & IoMT

---

## Health Policy & Regulation

[National Commission into the Regulation of AI recommendations for shared responsibility, post-market surveillance, AI readiness](https://htn.co.uk/2026/09/10/national-commission-into-the-regulation-of-ai-recommendations-for-shared-responsibility-post-market-surveillance-ai-readiness/) — *HTN Health Tech News*  
Why it matters: The UK setting out how AI-enabled medical devices should actually be regulated — proportionate, lifecycle-based, with continuous post-market monitoring and liability shared rather than pinned on a single clinician — is Europe's most concrete answer yet to the question the whole health-AI boom has begged: who is accountable when the algorithm gets it wrong.  
The UK's National Commission into the Regulation of AI in Healthcare (launched by the MHRA in September 2025, chaired by Professor Alastair Denniston) published recommendations for a future regulatory framework: a proportionate, risk-based, lifecycle-focused approach to regulating software and AI-enabled medical devices. On post-market surveillance, it recommends the MHRA evaluate a manufacturer's monitoring plan as part of the approval application itself (a credible plan becoming part of the case for approval), with routine performance reporting after deployment and defined thresholds that trigger escalation when a model's performance deteriorates. Crucially, it argues accountability should not rest with a single person or institution, favouring a model that distributes liability across the AI lifecycle, and it calls for strengthened clinical-evidence requirements. As one of the most detailed national blueprints for governing medical AI, it maps closely onto the EU's own frameworks — MDR/IVDR for devices, the AI Act's high-risk-medical-AI regime, and its post-market-monitoring obligations — and it lands as regulators across Europe and the US race to write rules for a technology already in clinical use, offering a concrete answer to the accountability, evidence and monitoring questions that clinical AI has raced ahead of.

[ENISA ranks health in cyber 'risk zone' as it backs EU hospital defences ahead of 11th eHealth conference](https://www.enisa.europa.eu/events/11th-ehealth-security-conference) — *ENISA*  
Why it matters: Europe's own cybersecurity agency ranking the health sector in its cyber 'risk zone' - a gap between the sector's maturity and its criticality - is the institutional acknowledgement behind the fortnight's hospital breaches, and a marker of the EU machinery now mobilising to close it.  
ENISA, the EU cybersecurity agency, classifies the health sector in the 'risk zone' in its NIS360 assessment - flagging a significant gap between the sector's cybersecurity maturity and its critical importance - and has signed a Contribution Agreement with the European Commission to support the health sector in building robust defences (including revised procurement guidelines for hospitals and medical-device cybersecurity). These themes, alongside NIS2 implementation for health and the European Health Data Space (EHDS), head the agenda of ENISA's 11th eHealth Security Conference (Nicosia, Cyprus, 7 October 2026). The mobilisation matters because it is the EU's structural response to exactly the pressure European hospital IT leaders have warned about - that the drive toward EHDS-enabled health-data exchange is outpacing the cyber defences meant to protect it - and it frames the policy backdrop (NIS2 as essential-entity obligations, EHDS, MDR/IVDR, procurement security) against which the sector's breaches, from the French hospital fine to the ShinyHunters campaign, are unfolding. For European health systems it signals both recognition of the risk and the arrival of concrete EU support (guidelines, agreements, NIS2 enforcement) to raise the sector's cyber maturity toward its criticality.

[FDA Seeks Feedback on Potential Regulation of GenAI Medical Devices](https://www.hipaajournal.com/fda-feedback-potential-regulation-genai-medical-devices/) — *The HIPAA Journal*  
Why it matters: The FDA opening consultation on how to regulate generative-AI medical devices is the US regulator acknowledging it has no settled rules for the LLMs and generative systems already reaching the clinic — a gap Europe's AI Act nominally closes on paper but that both jurisdictions are still learning to operationalise.  
The US Food and Drug Administration is seeking feedback on the potential regulation of generative-AI medical devices, opening consultation on how to handle the distinctive challenges of LLMs and generative systems in medicine — models whose outputs are non-deterministic, hard to validate against a fixed reference, and prone to change as they are updated. The move matters because generative AI is already being built into clinical tools while the regulatory framework for it remains unsettled, and the FDA's questions (how to evaluate, authorise, monitor and control generative medical AI) are the same ones every health regulator faces. For Europe, the AI Act nominally classifies medical AI as high-risk and layers on MDR/IVDR conformity assessment and post-market monitoring, but operationalising those rules for generative systems is an unresolved challenge shared across the Atlantic. The FDA's consultation is a marker that the rules for the most consequential and fastest-moving class of medical AI are still being written — a governance lag that, given the pace of clinical adoption, both the US and the EU are racing to close before generative tools are entrenched in care.

---

## Health Data & Breaches

**\[P2\]** [France fines Hopital Prive de la Loire EUR 500,000 after breach exposes 727,000 patients](https://www.bleepingcomputer.com/news/security/cyberattack-at-french-hospital-exposes-health-data-of-750-000-patients/) — *BleepingComputer / CNIL*  
Why it matters: France's CNIL fining a hospital EUR 500,000 after a cyberattack exposed the health records of more than 727,000 people is the fortnight's starkest European reminder that patients pay the price of the sector's security gap - a landmark GDPR penalty against a health provider as the continent's hospital defences struggle to keep pace with its digitisation drive.  
France's data-protection authority (CNIL) fined the Hopital Prive de la Loire in Saint-Etienne EUR 500,000 (penalty announced 3 September 2026) following a cyberattack that exposed the personal and health data of more than 727,000 people (some reports put it at \~750,000). The penalty reflects findings of inadequate security measures that contributed to the exposure of sensitive health data; the underlying attack disrupted the hospital and exposed medical and personal records. It is among the larger European hospital-data breaches of the period and a rare sizeable GDPR penalty against a health provider, and it lands amid warnings that European hospital cyber defences are lagging the sector's rapid digitisation (the EHDS push).  
severity high · exploited in the wild · EU: GDPR, NIS2, EHDS

**\[P2\]** [AdaptHealth Data Breach Affects 4.1 Million Individuals](https://www.hipaajournal.com/adapthealth-data-breach/) — *The HIPAA Journal*  
Why it matters: The home-medical-equipment provider AdaptHealth confirmed a breach exposing the personal and health data of 4.1 million people — health and insurance details taken after attackers socially engineered their way into a contractor's privileged account, part of the same extortion wave sweeping healthcare.  
AdaptHealth, a large US home-medical-equipment and healthcare-services company, confirmed a cyberattack exposed the data of 4.1 million people, in an incident attributed to the ShinyHunters threat group. The compromise occurred on 5 June 2026; AdaptHealth disclosed it in an SEC filing on 2 July, and a ransom was demanded on 15 June. The breach was achieved through social engineering that compromised the privileged account of a third-party contractor, giving access to cloud-based business applications including internal patient-management systems, document-storage platforms and electronic-health-record portals. Exposed data includes personal, health and insurance information but excludes Social Security numbers and financial data; AdaptHealth is offering 12 months of credit monitoring and identity protection. The 4.1-million figure confirms the scale of a breach that sits within the broader ShinyHunters healthcare spree.  
severity medium · exploited in the wild · EU: GDPR, NIS2, HIPAA · actor ShinyHunters (60%)

**\[P3\]** [Veradigm Discloses Third Party Data Breach as Hackers Threaten to Publish Data](https://www.hipaajournal.com/veradigm-data-breach-2026/) — *The HIPAA Journal*  
Why it matters: Veradigm — the health-tech firm formerly known as Allscripts — disclosed that a breach at one of its vendors let attackers copy the personal data of a reported 3.5 million patients through a customer-services API, with a ransomware crew now threatening to publish it.  
Veradigm (formerly Allscripts Healthcare Solutions) disclosed in an SEC 8-K filing on 8 September 2026 a cybersecurity incident at a third-party vendor that impacted a small number of Veradigm's customers. A threat actor obtained credentials from the vendor's environment for a Veradigm customer-services API and used that access to copy patient data; the actor only had access to the API, with no other Veradigm systems (servers, databases) compromised, and there was no operational disruption. The ransomware group 'The Gentlemen' added Veradigm to its dark-web leak site on 5 September and threatened to publish the data if unpaid; it alleges 3.5 million patient records including names, addresses, phone numbers, email addresses and other PII, and Social Security numbers — but reportedly no clinical or medical information. Veradigm's investigation and notification are ongoing.  
severity medium · exploited in the wild · EU: GDPR, NIS2, HIPAA · actor The Gentlemen (claimed) (50%)

---

## Clinical AI & Safety

[\[Comment\] Regulating artificial intelligence in health care: a tech-enabled, people-centred future](https://www.thelancet.com/journals/landig/article/PIIS2589-7500%2826%2900136-6/fulltext?rss=yes) — *The Lancet Digital Health*  
Why it matters: A call to regulate health-care AI toward a 'tech-enabled, people-centred future' is the field insisting that governance keep the patient — not the technology or the vendor — at the centre, a corrective to a debate too often framed around innovation speed and market access.  
A Lancet Digital Health comment argues for regulating artificial intelligence in health care in a way that is tech-enabled but people-centred — keeping patients, clinicians and equity at the centre of the governance framework rather than optimising for innovation speed or commercial interests alone. The framing matters because the medical-AI regulatory debate is frequently dominated by questions of market access, approval speed and manufacturer burden, and this comment insists that the purpose of regulation is to serve patients and the health system — through transparency, evidence, equity of access and meaningful oversight. It aligns with the values underpinning Europe's approach (the AI Act's rights-and-safety orientation, GDPR's patient-data protections, the emphasis on human oversight of high-risk medical AI) and with the UK commission's people-centred recommendations. For the shape of health-AI governance, it is a reminder that how the technology is regulated encodes whose interests it ultimately serves, and that a people-centred framework — not merely a permissive or a restrictive one — is the goal that should anchor the rules Europe and others are now writing.

[STAT+: FDA pilot offers generative AI medical devices a path to patients before they are authorized](https://www.statnews.com/2026/09/03/tempo-fda-pilor-generative-ai-medical-device-regulation/?utm%5Fcampaign=rss) — *STAT health tech: Stories on AI, new medical devices and more*  
Why it matters: An FDA pilot that lets generative-AI medical devices reach patients before they are formally authorised is a striking bet on speed over the usual pre-market gate — a fast-track that eases access to promising tools but tests how much safety assurance can be deferred to after deployment.  
A STAT report describes an FDA pilot offering generative-AI medical devices a path to patients before full authorisation — a mechanism to get promising generative tools into clinical use faster than the traditional pre-market review would allow. The pilot matters because it embodies the central tension in medical-AI regulation: the pressure to make beneficial AI available quickly versus the imperative to assure its safety and efficacy before patients rely on it. Fast-tracking access before authorisation shifts more of the safety burden to post-market monitoring and real-world surveillance — workable only if that monitoring is robust (the very thing the UK commission's recommendations emphasise). It contrasts sharply with the EU's more precautionary posture under the AI Act and MDR/IVDR, which front-load conformity assessment before market entry, and it raises the question of whether deferring assurance to after deployment is prudent acceleration or premature exposure. For the transatlantic debate over how to regulate clinical AI, the FDA pilot is a notable experiment in prioritising access — one whose wisdom depends entirely on the strength of the post-deployment safety net it assumes.

[Your AI Didn't Lie to You: It Was Just Being Manipulated](https://www.healthcareinfosecurity.com/blogs/your-ai-didnt-lie-to-you-was-just-being-manipulated-p-4183) — *HealthcareInfoSecurity.com RSS Syndication*  
Why it matters: The reframing that a misbehaving AI 'wasn't lying — it was being manipulated' points at the security dimension of clinical AI that safety debates often miss: models can be steered to harmful outputs by adversarial inputs, so a health AI's trustworthiness depends on its resistance to attack as much as its accuracy.  
A HealthcareInfoSecurity analysis argues that when an AI produces a harmful or false output, the cause is often manipulation — adversarial or poisoned inputs steering the model — rather than the model simply 'lying,' reframing AI trustworthiness as a security problem as much as a safety one. The point matters for health AI specifically: a clinical model can be manipulated through prompt injection, data poisoning or adversarial inputs into producing dangerous recommendations, so its reliability depends not only on validated accuracy but on resistance to attack — a dimension that clinical-safety evaluation and much of the medical-AI governance conversation underweight. It connects clinical AI to the broader AI-security threats surfacing across the sector (manipulation, poisoning, the weaponisation of models) and to the recognition that securing medical AI requires adversarial robustness testing, input validation and monitoring, not just performance benchmarking. For European deployers under the AI Act (which requires robustness and cybersecurity for high-risk systems) and MDR, it is a reminder that a clinical AI's security posture is inseparable from its safety, and that a manipulable model is an unsafe one however accurate it tests in benign conditions.

---

## Medical Devices & IoMT

**\[P2\]** [Orthanc DICOM Server Vulnerability Can Lead to Denial of Service](https://www.hipaajournal.com/orthanc-dicom-server-vulnerability-denial-of-service/) — *The HIPAA Journal*  
Why it matters: A flaw in Orthanc — one of the most widely used open-source servers for storing and viewing medical images — lets a crafted scan crash the system, a denial-of-service risk in the imaging infrastructure hospitals depend on to read X-rays, CTs and MRIs.  
CVE-2026-87020 is an integer-overflow flaw in the Orthanc DICOM Server (a widely used, European-origin open-source server for storing, managing and viewing medical images) that, in a pitch and buffer-size computation, results in a heap out-of-bounds write when Orthanc decodes a specially crafted PNG or JPEG image — causing a crash and a denial-of-service condition. It carries a CVSS v3.1 base score of 8.1 (v4.0 7.2); exploitation requires an authenticated remote attacker who can supply the malicious image. Affected versions are Orthanc <1.13.0, fixed in 1.13.0; CISA published advisory ICSMA-26-253-02 on 10 September 2026, and related reporting notes multiple Orthanc heap-overflow issues (some raising remote-code-execution risk beyond DoS). No known public exploitation targeting the flaw has been reported.  
severity high (CVSS 8.1) · `CVE-2026-87020` · EU: MDR, NIS2, EHDS

**\[P2\]** [High Severity Vulnerabilities Identified in NextGen Healthcare Mirth Connect](https://www.hipaajournal.com/high-severity-vulnerabilities-nextgen-healthcare-mirth-connect/) — *The HIPAA Journal*  
Why it matters: High-severity flaws in NextGen's Mirth Connect — the integration engine that shuttles clinical data between hospital systems — could let an attacker steal the stored logins for every system it connects to, turning the plumbing of health-data exchange into a master key.  
CISA cataloged three high-severity vulnerabilities in NextGen Healthcare Mirth Connect (a widely used open-source healthcare integration engine that routes HL7 and other clinical data between systems), all CVSS 7-8: CVE-2026-82583, an authenticated SQL injection via the Database Connector API that can disclose stored credentials for connected systems, write arbitrary files and cause denial of service; and CVE-2026-78224 and CVE-2026-82578, XML-External-Entity (XXE) flaws (the latter when XML batch processing with the XPath option is enabled) enabling data exfiltration and DoS. All affect versions up to 4.7.1 and are fixed in v4.7.2 (issued 5 August 2026); one report describes a critical Mirth Connect flaw under active exploitation. Because Mirth Connect sits between health systems and holds credentials for the systems it integrates, its compromise can expose downstream logins and the data flowing through it.  
severity high · exploited in the wild · `CVE-2026-82583` · EU: MDR, NIS2, EHDS, GDPR

**\[P3\]** [Boston Scientific fully restores operations after cyberattack](https://www.medtechdive.com/news/boston-scientific-fully-restores-operations-after-cyberattack/830182/) — *MedTech Dive - Latest News*  
Why it matters: The medical-device giant Boston Scientific said it has fully restored operations after a cyberattack that dented its results — a reminder that when a maker of pacemakers, stents and other implantable devices is disrupted, the ripples reach the hospitals and patients who depend on its products.  
Boston Scientific, one of the world's largest medical-device manufacturers (implantables such as pacemakers, defibrillators, stents and more), said it has fully restored operations following a cyberattack that had disrupted its business and was expected to weigh on its financial results. The company had earlier flagged a financial hit from the incident; the update is that operations are now recovered. While the immediate impact reported is operational-and-financial rather than a direct patient-safety event, a cyberattack on a major device manufacturer carries downstream stakes: disruption to manufacturing, supply, order fulfilment or device-support services can affect the availability of critical devices and the hospitals and patients that rely on them. Details of the attack's nature and any data impact are limited in the recovery announcement.  
severity medium · EU: MDR, NIS2, CRA

---

## Telehealth & Digital Health

[North West Ambulance Service plans £19 million unified CAD and EPR platform](https://htn.co.uk/2026/09/08/north-west-ambulance-service-plans-19-million-unified-cad-and-epr-platform/) — *HTN Health Tech News*  
Why it matters: An English ambulance service investing £19 million in a single platform to unite its dispatch and patient records is the digitisation of emergency care in one procurement — a modernisation that promises faster, better-coordinated response but concentrates a life-critical service's dependence on one system that must never go dark.  
North West Ambulance Service (NHS) plans a £19 million unified computer-aided dispatch (CAD) and electronic patient record (EPR) platform, consolidating the systems that coordinate emergency response and capture patient care onto a single modern platform. The investment matters as a marker of the digitisation of emergency and pre-hospital care in the NHS: unifying dispatch and clinical records promises faster, better-informed and more coordinated response, and reflects the broader push to modernise the digital backbone of European health systems. But it also concentrates a life-critical service's dependence on a single platform, raising the resilience-and-cybersecurity stakes: dispatch-and-EPR systems are exactly the kind of essential healthcare infrastructure NIS2 designates for protection, because their disruption directly threatens emergency response and patient safety. It connects to the digital-health-modernisation thread across the NHS and Europe, and it is a reminder that as emergency care goes digital, the security and resilience of the unified systems that run it become a patient-safety imperative — modernisation and cyber resilience must advance together, since a life-critical platform is only an asset if it stays available under attack.

[Barking, Havering and Redbridge University Hospitals highlights pressing requirement for maternity EPR](https://htn.co.uk/2026/09/11/barking-havering-and-redbridge-university-hospitals-highlights-pressing-requirement-for-maternity-epr/) — *HTN Health Tech News*  
Why it matters: An English NHS trust flagging an urgent need for a maternity electronic patient record is a small but telling marker of where health digitisation still has gaps — the most safety-sensitive corners of care, like maternity, running on records that have not yet caught up.  
Barking, Havering and Redbridge University Hospitals (an NHS trust) highlighted a pressing requirement for a maternity electronic patient record (EPR), pointing to a gap in the digitisation of one of the most safety-sensitive areas of care. The need matters because maternity care carries acute patient-safety stakes (well-documented failings in some NHS maternity services have been linked partly to poor record-keeping and information flow), and a dedicated, integrated maternity EPR can improve the continuity, accuracy and safety of care for mothers and babies. It reflects the uneven progress of health digitisation — even in systems investing heavily in EPRs, specific high-stakes domains can lag — and the recognition that the right digital records infrastructure is a patient-safety tool, not just an administrative one. It connects to the broader NHS and European digital-health modernisation effort, and it is a reminder that as health systems digitise, prioritising the most safety-critical areas (maternity, emergency, medication management) matters, and that the security and reliability of these records — holding highly sensitive data on mothers and newborns — must be built in as the systems that were missing are finally procured.

---

## Threat Intelligence (Health)

**\[P2\]** [Urgent Threat Alert: ShinyHunters Vishing Campaigns and Domain Impersonation](https://health-isac.org/urgent-threat-alert-shinyhunters-vishing-campaigns-and-domain-impersonation/) — *Health-ISAC – Health Information Sharing and Analysis Center*  
Why it matters: Health-ISAC issued an urgent alert that ShinyHunters — the gang behind the McKesson mega-breach — is running voice-phishing campaigns and medical-themed impersonation domains against healthcare worldwide, calling employees on their personal phones and talking them past multi-factor authentication to loot the sector's cloud systems.  
Health-ISAC issued an urgent threat alert warning that the ShinyHunters cybercrime group poses a clear and present danger to the global health sector through persistent, highly targeted voice-phishing (vishing) campaigns. Group members call employees on personal mobile devices and email them from multiple random accounts, following up with voicemails instructing users to bypass corporate security controls via malicious links; they register new domains combining a target company's name with variable endings (e.g. '.claim') for medical-themed impersonation lures. Health-ISAC notes ShinyHunters is behaving less like a traditional ransomware group and more like an identity- and SaaS-access extortion operation — bypassing multi-factor authentication to pivot rapidly from single-sign-on (SSO) platforms to connected SaaS applications for large-scale data exfiltration and extortion. The alert cites the McKesson breach (ShinyHunters claiming 284 million records after vishing employees) as the exemplar, and urges strong authentication, least privilege and continuous monitoring.  
severity high · exploited in the wild · EU: GDPR, NIS2, HIPAA · actor ShinyHunters (75%), escalation