Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
AWS has released the "HIPAA Security Rule on AWS: Technical Safeguards Implementation and Readiness Guidance" to assist covered entities and business associates in configuring, implementing, and demonstrating compliance with HIPAA Security Rule Technical Safeguard requirements (45 CFR §164.312) for healthcare workloads on AWS. The guidance addresses five standards and nine implementation specifications, including access control, audit controls, integrity, authentication, and transmission security. It also incorporates proposed changes from the 2025 Notice of Proposed Rulemaking (NPRM), such as mandatory encryption at rest and in transit, multi-factor authentication (MFA) for accessing electronic Personal Health Information (ePHI), and new requirements for network segmentation, patch management, and incident response.
Today, we’re releasing the <a class="Link" href="https://d1.awsstatic.com/onedam/marketing-channels/website/aws/en_US/whitepapers/compliance/HIPAA-Security-Rule-Technical-Controls-On-AWS-Compliance-Guidance.
This article announces AWS's release of a new guidance document for implementing HIPAA Security Rule Technical Safeguards on AWS. It details the five standards and nine implementation specifications, as well as proposed 2025 NPRM changes like mandatory encryption and MFA. The guidance provides a shared responsibility matrix, ePHI boundary architecture, and a foundation checklist for cloud architects and security engineers.
OpenAI says it has reduced the price of two GPT-5.6 models, cutting Luna's API price by 80% and Terra's by 20% as it works to make its models more efficient.
BleepingComputer reports OpenAI states its new GPT 5.6 models are becoming more cost-efficient while maintaining performance. Reduced inference costs make advanced AI capabilities more accessible.
A suspected Chinese-speaking threat actor has launched a series of cyberattacks targeting government organizations in Central Asia, including Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, Kazakhstan, and the Syrian Arab Republic, since January 2025. The attacks span sectors such as healthcare, research, foreign affairs, law enforcement, and education, as reported by Kaspersky.