AHA warns of critical software vulnerability

Advertisement

The American Hospital Association is notifying hospitals and health systems about a critical software vulnerability involving Notepad++, a free, open-source coding program used in healthcare.

The vulnerability affected an update component affecting editions of the program before version 8.8.9, allowing cyber criminals to breach and disrupt the update process, according to a Feb. 5 AHA news release.

A nation-state threat actor was likely responsible for hacks that occurred between June and November of 2025, the release stated. The National Institute of Standards and Technology published details on the security flaw Feb. 2.

At the Becker's 11th Annual IT + Revenue Cycle Conference: The Future of AI & Digital Health, taking place September 14–17 in Chicago, healthcare executives and digital leaders from across the country will come together to explore how AI, interoperability, cybersecurity, and revenue cycle innovation are transforming care delivery, strengthening financial performance, and driving the next era of digital health. Apply for complimentary registration now.

Advertisement

Next Up in Cybersecurity

Advertisement