Compliance and Regulations

Stay up-to-date of data protection regulations updates and industry compliance standards evolution. Learn about HIPAA, GDPR and data protection laws, compliance requirements specific to your industry, and stay up-to-date on legal developments affecting security practices. Stay inform on notable data breaches and security incidents related.

Mt. Baker Imaging Settes Data Breach Litigation for $3.3M

Mt. Baker Imaging Settes Data Breach Litigation for $3.3M

A $3.3 million class action settlement resolves litigation arising from a ransomware incident that occurred on January 2025 involving Mt. Baker Imaging and Northwest Radiologists, following unauthorized access that exposed the protected health information (PHI) … Read more

Delta Home Health Care Owner Convicted in Medicare Fraud and Illegal Kickback Scheme

Delta Home Health Care Owner Convicted in Medicare Fraud and Illegal Kickback Scheme

Ruby Scott, owner and operator of Delta Home Health Care LLC in Michigan, was convicted by a federal jury on charges related to healthcare fraud and illegal healthcare kickbacks connected to a scheme that caused … Read more

Exposed DICOM Servers Increase Risk of PHI Theft and Ransomware Attacks

Exposed DICOM Servers Increase Risk of PHI Theft and Ransomware Attacks

Healthcare organizations are exposing patient data through improperly secured DICOM servers that are accessible through the public internet, according to a Trend Micro TrendAI analysis that identified thousands of exposed servers across more than 100 … Read more

OPM Health Data Collection Proposal Raises HIPAA Compliance and Privacy Concerns

OPM Health Data Collection Proposal Raises HIPAA Compliance and Privacy Concerns

The Office of Personnel Management proposal to collect claims-level health insurance data for federal employees and retirees has generated sustained criticism due to privacy risks, potential violations of the HIPAA Privacy Rule, and concerns about … Read more

Concord Orthopaedics Settles Class Action Data Breach Lawsuit

Concord Orthopaedics Settles Class Action Data Breach Lawsuit

Concord Orthopaedics Professional Association has agreed to a settlement to resolve consolidated class action litigation arising from a November 2024 cybersecurity incident that involved unauthorized access to the personal and protected health information (PHI) of … Read more

CISA Recommends Strict Administrative Controls of Microsoft Intune

CISA Recommends Strict Administrative Controls of Microsoft Intune

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued guidance instructing U.S. organizations to strengthen administrative controls in Microsoft Intune following a cyberattack on Stryker Corporation that involved data exfiltration and substantial data deletion. … Read more

Rebound Orthopedics & Neurosurgery Settles Data Breach Lawsuit For $2.5 Million

Rebound Orthopedics & Neurosurgery Settles Data Breach Lawsuit For $2.5 Million

Orthopedic and neurosurgery practice, Rebound Orthopedics & Neurosurgery P.C. based in Vancouver, WA, agreed to a $2,500,000 settlement in a class action lawsuit over a February 2024 data breach that exposed the protected health information … Read more

Capital Health Pays $4.5M to Settle Data Breach Lawsuit

Capital Health Pays $4.5M to Settle Data Breach Lawsuit

Capital Health agreed to pay $4.5 million to resolve the class action lawsuit over a 2023 data breach that exposed patient data and other personal information. Data Breach Incident Capital Health experienced unauthorized access to … Read more

Comstar to Settle Alleged HIPAA Violations for $515,000

Comstar to Settle Alleged HIPAA Violations for $515,000

The Massachusetts Attorney General is investigating Comstar, an ambulance billing and collections company in Massachusetts and determined to have failed to comply with the Massachusetts Data Security Regulations and the Health Insurance Portability and Accountability … Read more

List of Healthcare Providers Affected by TriZetto Provider Solutions Data Breach

List of Healthcare Providers Affected by TriZetto Provider Solutions Data Breach

TriZetto Provider Solutions, owned by Cognizant, which provides hospitals, doctors, and health systems with revenue management services, has began informing some healthcare clients regarding a recently discovered cybersecurity breach. On October 2, 2025, TriZetto Provider … Read more

Can Your Cybersecurity Training Qualify You for HIPAA Safe Harbor Protection?

Your HIPAA Safe Harbor protection is only as strong as your ability to prove through documentation and consistent practice that your organization has implemented recognized security practices for at least 12 months, and cybersecurity training … Read more

Richmond Behavioral Health Authority Data Breach Impacts 113,232 Individuals

Richmond Behavioral Health Authority Data Breach Impacts 113,232 Individuals

Richmond Behavioral Health Authority (RBHA) offers substance abuse and prevention and mental health services in Richmond, Virginia. This HIPAA-covered entity recently encountered a data incident that resulted in the compromise of up to 113,232 individuals’ … Read more

Better Protect Patient Data By Understanding the Risk Environment

Better Protect Patient Data By Understanding the Risk Environment

Part 1 of the 2025 American Hospital Association (AHA) review of healthcare cybersecurity revealed that from January to October 3, 2025, there were 364 hacking incidents that resulted in the compromise of the health records … Read more

Neuromusculoskeletal Center of The Cascades Settles Class Action Lawsuit

Neuromusculoskeletal Center of The Cascades Settles Class Action Lawsuit

HIPAA-covered entity Neuromusculoskeletal Center of The Cascades, PC, and Cascade Surgicenter LLC in Oregon decided to resolve a class action lawsuit resulting from a data breach in October 2023. Employee email accounts were accessed by … Read more

Greater Cincinnati Behavioral Health Services Settles Data Breach Litigation for $850K

Greater Cincinnati Behavioral Health Services Settles Data Breach Litigation for $850K

HIPAA-covered entity Greater Cincinnati Behavioral Health Services (GCBHS) decided to pay approximately $850,000 to settle all claims associated with a ransomware attack in December 2023 involving unauthorized access to patient and worker data. On December … Read more

Skagit Regional Health Resolves Data Breach Lawsuit Involving Use of Tracking Technologies

Skagit Regional Health Resolves Data Breach Lawsuit Involving Use of Tracking Technologies

Skagit County Public Hospital District No. 1, also called Skagit Regional Health, operates Skagit Regional Hospital, located in Mount Vernon, Washington, agreed to settle class action litigation prompted by its installation of Meta Pixel and … Read more

Verily Faces Lawsuit Over Alleged HIPAA Violations

Verily Faces Lawsuit Over Alleged HIPAA Violations

Verily, owned by Alphabet, is facing a lawsuit filed by an ex-employee who alleges the misuse of the personally identifiable health information of over 25,000 patients, and the failure of the company to submit HIPAA … Read more

163,000 Wayne Memorial Hospital Patients Affected by May 2024 Ransomware Attack

163,000 Wayne Memorial Hospital Patients Affected by May 2024 Ransomware Attack

Wayne Memorial Hospital patients received notification recently about a ransomware group that stole their protected health information (PHI) fifteen months ago. The 84-bed rural hospital located in Jessup, Georgia, sent personal notifications to the 163,400 … Read more

Court Approves $40 Million Data Breach Settlement by Cencora & The Lash Group

Court Approves $40 Million Data Breach Settlement by Cencora & The Lash Group

Cencora & The Lash Group decided to create a $40 million fund to resolve class action litigation over a data breach in February 2024 that affected approximately 1.43 million people. Cencora, Inc., formerly known as … Read more

Syracuse ASC Pays $250K to Resolve Violations of HIPAA Risk Analysis and Breach Notification Law

Syracuse ASC Pays $250K to Resolve Violations of HIPAA Risk Analysis and Breach Notification Law

Director Paula M. Stannard of the Department of Health and Human Services (HHS) Office for Civil Rights (OCR) announced the 18th HIPAA penalty for 2025. Ambulatory surgery center in Liverpool, New York, Syracuse ASC dba … Read more

Northbay Healthcare Pays $3.6 Million to Resolve Data Breach Lawsuit

Northbay Healthcare Pays $3.6 Million to Resolve Data Breach Lawsuit

Northbay Healthcare Corporation agreed to a settlement to resolve a class action lawsuit associated with a 2024 cyberattack and data breach that impacted approximately 570,000 people. Northbay Healthcare discovered suspicious activity inside its computer system … Read more

20 States Sue HHS and DHS for Alleged Illegal Disclosure of Medicaid Data

20 States Sue HHS and DHS for Alleged Illegal Disclosure of Medicaid Data

An alliance of 20 state Attorneys General is filing a lawsuit against the Department of Homeland Security (DHS), DHS Secretary Kristi Noem, the Department of Health and Human Services (HHS), and HHS Secretary Robert F. … Read more

MNGI Digestive Health Resolves Data Breach Lawsuit for $2.8 Million

MNGI Digestive Health Resolves Data Breach Lawsuit for $2.8 Million

MNGI Digestive Health consented to resolve a class action lawsuit associated with its negligence for not securing sensitive patient data. The lawsuit is a result of a ransomware attack on the Minnesota gastroenterology practice by … Read more

Class Action Lawsuits Filed Over HealthEC Data Breach

Class Action Lawsuits Filed Over HealthEC Data Breach

HealthEC LLC faced multiple class action lawsuits because of a data breach that affected about 4.5 million people. Hackers acquired access to the population health management system of HealthEC from July 14 to July 23, … Read more

WellNow Urgent Care Agreed to Settle Data Breach Litigation for $4.4 Million

WellNow Urgent Care (earlier known as Five Star Urgent Care), a community of walk-in urgent care centers in Illinois, New York, Ohio, and Michigan, has decided to pay $4.4 million to resolve a class action … Read more

ELENOR-Corp Ransomware Group Attacks the Healthcare Sector with Mimic Ransomware Variant

ELENOR-Corp Ransomware Group Attacks the Healthcare Sector with Mimic Ransomware Variant

According to the cybersecurity company Morphisec, a new ransomware group known as ELENOR-corp is targeting the healthcare sector. Researchers confirmed that ELENOR-corp is utilizing version 7.5 of Mimic ransomware, a ransomware strain first discovered in … Read more

UnitedHealth Implements Aggresive Tactics on Ransomware Attack Loan Recovery

UnitedHealth Implements Aggresive Tactics on Ransomware Attack Loan Recovery

UnitedHealth Group has taken a confrontational approach to retrieve outstanding balances on loans released to HIPAA-covered healthcare companies impacted by the Change Healthcare ransomware attack in February 2024. The attack resulted in an extended outage … Read more

MATCH IT Act of 2025 aims to Address Patient Misidentification

MATCH IT Act of 2025 aims to Address Patient Misidentification

The Health Insurance Portability and Accountability Act of 1996 required the creation of a national patient identifier – a unique ID for all U.S. citizens that would reliably link medical records to the correct persons. … Read more

Is It a HIPAA Violation to Say Someone is Your Patient?

Is It a HIPAA Violation to Say Someone is Your Patient?

Whether it is a HIPAA violation to say someone is your patient is an event-specific determination that depends on factors such as who is speaking, who they are speaking to, and the context of the … Read more

Fred Hutchinson Cancer Center Pays $11.5M to Settle a Class Action Data Breach Lawsuit

Fred Hutchinson Cancer Center Pays $11.5M to Settle a Class Action Data Breach Lawsuit

The University of Washington and Fred Hutchinson Cancer Center have decided to settle a proposed class action data breach lawsuit for $11,500,000 and set aside $13,500,000 to enhance cybersecurity. The lawsuit is a result of … Read more

Rhode Island HIE Faces Lawsuit for Alleged HIE Data Impermissible Disclosure

Rhode Island HIE Faces Lawsuit for Alleged HIE Data Impermissible Disclosure

Ex-HIPAA officer Darlene Morris filed a lawsuit against the Rhode Island Quality Institute (RIQI) for allegedly being fired from work for exposing its impermissible disclosures of HIE information. As a state government contractor of Rhode … Read more

Morrison Community Hospital Settles Ransomware Lawsuit for $675K

Critical access hospital Morrison Community Hospital in Illinois has decided to settle a lawsuit for $675,000. The lawsuit was associated with a ransomware attack and data breach in 2023. The BlackCat/ALPHV ransomware group behind the … Read more

Memorial Healthcare System to Pay $60,000 to Settle Alleged HIPAA Right of Access Violation

Memorial Healthcare System to Pay $60,000 to Settle Alleged HIPAA Right of Access Violation

Florida health system South Broward Hospital District, also known as Memorial Healthcare System, has consented to resolve an alleged HIPAA Right of Access violation determined by the U.S. Department of Health and Human Services’ Office … Read more

Virtual Private Network Solutions Pays $90,000 to Resolve HIPAA Investigation

Virtual Private Network Solutions Pays $90,000 to Resolve HIPAA Investigation

The HHS’ Office for Civil Rights (OCR) has reported reaching a settlement that ended the investigation of a ransomware attack. Because Virtual Private Network Solutions failed to perform a HIPAA-compliant risk analysis, it will pay … Read more

HIPAA Privacy Rule: New Requirements for Reproductive Healthcare Entities

HIPAA Privacy Rule: New Requirements for Reproductive Healthcare Entities

In April 2024, the HHS Office for Civil Rights (OCR) released the HIPAA Privacy Rule to assist the Reproductive Healthcare Privacy Final Rule. The new rule became effective on June 23, 2024, but the last … Read more

How Often Do You Have To Do HIPAA Training?

How Often Do You Have To Do HIPAA Training?

How often you have to do HIPAA training depends on factors such as material changes to HIPAA policies and procedures, the frequency of security awareness training, the outcomes of risk analyses and evaluations, and employers’ … Read more

HIPAA Security Awareness Training

HIPAA security awareness training should have the objective of showing members of the workforce why it is important to protect the confidentiality, integrity, and availability of individually identifiable health information as well as explaining cybersecurity … Read more

OMB’s Change of the HIPAA Security Rule

OMB’s Review of the Proposed Change to the HIPAA Security Rule

In December 2023, the Department of Health and Human Services (HHS) published its cybersecurity strategy for the healthcare sector, detailing a list of actions to be implemented to improve cybersecurity across the healthcare industry, including … Read more

UMC Health’s EHR System is Back After Ransomware Attack

UMC Health System based in Lubbock, Texas reported the progress of its recovery from the ransomware attack in September. The ransomware attack impacted several systems, including the systems used by Texas Tech Physicians and Texas … Read more

Choosing the Right HIPAA Compliance Software

HIPAA compliance software helps a covered entity deal with the issues of HIPAA by streamlining and automating compliance and undertaking comprehensive risk management processes. Smaller organizations that have less than 100 employees assign the responsibility … Read more

International Data Transfers

Crossing Borders: International Data Transfers

The European Court of Justice’s July 16th 2020 Schrems II judgment had major implications for the use of US cloud services. Since that case, every US cloud service provider has been obliged to verify the … Read more

Minimum Cybersecurity Standards Proposed in Healthcare Bill

A new bill known as the “Health Infrastructure Security and Accountability Act of 2024,” has been introduced to the U.S. Senate to strengthen cybersecurity standards for healthcare information systems. This legislative proposal aims to implement … Read more

Chinese Cyber Threats to US Infrastructure

New Bill Tackles Chinese Cyber Threats to US Infrastructure

The U.S. House Homeland Security Committee has introduced new legislation aimed at strengthening the nation’s cybersecurity defences against threats from China. This bill establishes an interagency task force to assess the risks by state-sponsored cyber … Read more

Why Cyberattackers Target Third-Party Vendors

Recent big data breaches that affected third-party vendors like Change Healthcare targeted critical security risk management issues for business associates and vendors. These breaches have proven the necessity of security measures and comprehensive monitoring of … Read more

OSHA’s New Online Database of Reported Severe Workplace Injuries

The Department of Labor’s Occupational Safety and Health Administration (OSHA) has introduced a new online dashboard designed to simplify searching its severe injury report database and tracking workplace injury trends in states under federal OSHA … Read more

HIPAA Compliance on Resume

Including HIPAA compliance on a resume is important for candidates in healthcare, IT, administration, and other fields handling sensitive health information. Including this skill emphasizes an understanding of patient privacy and data protection standards, making … Read more

57% More Active Ransomware Groups in H1 2024

Searchlight Cyber1 reported a 57% increase in the number of active ransomware groups. In H1 of 2023, 46 active ransomware groups were identified from posts on dark web data leak sites compared to 72 active … Read more

Atlantic General Hospital Pays $2.25 Million to Resolve Data Breach Lawsuit

Atlantic General Hospital in Berlin, MD, has proposed a $2.24 million settlement to resolve a class action lawsuit associated with a ransomware attack in 2023. The settlement proposal was given preliminary approval by the court. … Read more

Data Security: Business advantage rather than regulatory burden

What comes to mind first when the words ‘Data security’ are mentioned to most workers? Chances are, it is thoughts of things like; frequent password changes, oversensitive spam folders, the inability to make personal calls … Read more

EPA Urged to Develop a Strategy to Address Cybersecurity Risks in Water Sector

The U.S. water and wastewater systems are dealing with an increasingly serious threat from cyberattacks, which could have lasting consequences for public health and environmental safety. A report from the U.S. Government Accountability Office (GAO) … Read more

1236 Next