Carl B. Johnson
Author

Carl B. Johnson

vCISO and compliance expert.

https://carlbjohnson.com

posts

Ransomware Recovery Steps

Ransomware Recovery Steps: A Battle-Tested Playbook

The Attack That Cost a Hospital $67 Million In May 2024, Ascension Healthcare disclosed a ransomware attack that disrupted operations across 140 hospitals. Ambulances were diverted. Clinicians reverted to paper charts. The financial impact reportedly reached $1.8 billion in total losses for the fiscal year, with the cyber incident

Carl B. Johnson Aug 11, 2025 7 min read
Ransomware Examples

Ransomware Examples 2025: Real Attacks Shaping Defenses

Ransomware Isn't Slowing Down — It's Shapeshifting In February 2024, Change Healthcare suffered what became one of the most devastating ransomware attacks in U.S. history. The ALPHV/BlackCat ransomware group crippled the nation's largest health care payment processor, disrupting pharmacies, hospitals, and insurance claims

Carl B. Johnson Jul 19, 2025 7 min read
Ransomware

How Ransomware Spreads: 7 Attack Vectors in 2025

In February 2024, Change Healthcare — the payment processor handling roughly one-third of all U.S. medical claims — was hit by the ALPHV/BlackCat ransomware group. The result: $872 million in direct costs reported by UnitedHealth Group, months of disrupted pharmacy operations, and the personal health data of over 100 million

Carl B. Johnson Jul 15, 2025 7 min read
Ransomware Protection

Ransomware Protection Tips That Actually Work in 2025

The Breach That Changed a Hospital System Overnight In February 2024, Change Healthcare — a subsidiary of UnitedHealth Group — was hit by a ransomware attack that disrupted prescription processing and claims payments for weeks across the U.S. healthcare system. UnitedHealth's CEO later confirmed the company paid a $22

Carl B. Johnson Jul 15, 2025 7 min read
Data Breach Prevention

Data Breach Prevention: 9 Steps That Actually Work

In May 2024, Ticketmaster disclosed a breach that exposed personal data on over 560 million customers. The attack vector? Compromised credentials at a third-party cloud provider. No zero-day exploit. No nation-state wizardry. Just stolen login details and a lack of proper access controls. Data breach prevention doesn't start

Carl B. Johnson Jul 15, 2025 7 min read
Data Breach

What Causes a Data Breach: 7 Root Causes in 2025

In May 2024, Ticketmaster confirmed a breach that exposed the personal data of over 560 million customers. The attack vector? Stolen credentials used to access a third-party cloud database. It wasn't some exotic zero-day exploit. It was a login and password that fell into the wrong hands. If

Carl B. Johnson Jul 15, 2025 7 min read
Data Breach Response Plan

Data Breach Response Plan: What Actually Works in 2025

In May 2023, MOVEit Transfer suffered a mass exploitation that ultimately affected over 2,700 organizations and exposed data on roughly 95 million individuals. Some of those organizations had a tested data breach response plan ready to execute. Most didn't. The difference between the two groups wasn'

Carl B. Johnson Jul 15, 2025 7 min read
Data Breach Reporting

How to Report a Data Breach: A Step-by-Step Guide

In February 2024, Change Healthcare suffered a ransomware attack that exposed the protected health information of approximately 190 million people — making it the largest healthcare data breach in U.S. history. The fallout wasn't just the breach itself. It was the weeks of confusion about who had been

Carl B. Johnson Jul 15, 2025 8 min read
Data Breach Notification Requirements

Data Breach Notification Requirements: A 2025 Guide

In May 2023, T-Mobile agreed to a $350 million settlement after a data breach exposed the personal information of roughly 76 million people. A significant chunk of that cost wasn't the breach itself — it was the fallout from notification failures, regulatory scrutiny, and class-action lawsuits that followed. If

Carl B. Johnson Jun 15, 2025 8 min read