Compliance and Regulations
Stay up-to-date of data protection regulations updates and industry compliance standards evolution. Learn about HIPAA, GDPR and data protection laws, compliance requirements specific to your industry, and stay up-to-date on legal developments affecting security practices. Stay inform on notable data breaches and security incidents related.
Mt. Baker Imaging Settes Data Breach Litigation for $3.3M
A $3.3 million class action settlement resolves litigation arising from a ransomware incident that occurred on January 2025 involving Mt. Baker Imaging and Northwest Radiologists, following unauthorized access that exposed the protected health information (PHI) … Read more
Delta Home Health Care Owner Convicted in Medicare Fraud and Illegal Kickback Scheme
Ruby Scott, owner and operator of Delta Home Health Care LLC in Michigan, was convicted by a federal jury on charges related to healthcare fraud and illegal healthcare kickbacks connected to a scheme that caused … Read more
Exposed DICOM Servers Increase Risk of PHI Theft and Ransomware Attacks
Healthcare organizations are exposing patient data through improperly secured DICOM servers that are accessible through the public internet, according to a Trend Micro TrendAI analysis that identified thousands of exposed servers across more than 100 … Read more
OPM Health Data Collection Proposal Raises HIPAA Compliance and Privacy Concerns
The Office of Personnel Management proposal to collect claims-level health insurance data for federal employees and retirees has generated sustained criticism due to privacy risks, potential violations of the HIPAA Privacy Rule, and concerns about … Read more
Concord Orthopaedics Settles Class Action Data Breach Lawsuit
Concord Orthopaedics Professional Association has agreed to a settlement to resolve consolidated class action litigation arising from a November 2024 cybersecurity incident that involved unauthorized access to the personal and protected health information (PHI) of … Read more
CISA Recommends Strict Administrative Controls of Microsoft Intune
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued guidance instructing U.S. organizations to strengthen administrative controls in Microsoft Intune following a cyberattack on Stryker Corporation that involved data exfiltration and substantial data deletion. … Read more
Rebound Orthopedics & Neurosurgery Settles Data Breach Lawsuit For $2.5 Million
Orthopedic and neurosurgery practice, Rebound Orthopedics & Neurosurgery P.C. based in Vancouver, WA, agreed to a $2,500,000 settlement in a class action lawsuit over a February 2024 data breach that exposed the protected health information … Read more
Capital Health Pays $4.5M to Settle Data Breach Lawsuit
Capital Health agreed to pay $4.5 million to resolve the class action lawsuit over a 2023 data breach that exposed patient data and other personal information. Data Breach Incident Capital Health experienced unauthorized access to … Read more
Comstar to Settle Alleged HIPAA Violations for $515,000
The Massachusetts Attorney General is investigating Comstar, an ambulance billing and collections company in Massachusetts and determined to have failed to comply with the Massachusetts Data Security Regulations and the Health Insurance Portability and Accountability … Read more
List of Healthcare Providers Affected by TriZetto Provider Solutions Data Breach
TriZetto Provider Solutions, owned by Cognizant, which provides hospitals, doctors, and health systems with revenue management services, has began informing some healthcare clients regarding a recently discovered cybersecurity breach. On October 2, 2025, TriZetto Provider … Read more
Can Your Cybersecurity Training Qualify You for HIPAA Safe Harbor Protection?
Your HIPAA Safe Harbor protection is only as strong as your ability to prove through documentation and consistent practice that your organization has implemented recognized security practices for at least 12 months, and cybersecurity training … Read more
Richmond Behavioral Health Authority Data Breach Impacts 113,232 Individuals
Richmond Behavioral Health Authority (RBHA) offers substance abuse and prevention and mental health services in Richmond, Virginia. This HIPAA-covered entity recently encountered a data incident that resulted in the compromise of up to 113,232 individuals’ … Read more
Better Protect Patient Data By Understanding the Risk Environment
Part 1 of the 2025 American Hospital Association (AHA) review of healthcare cybersecurity revealed that from January to October 3, 2025, there were 364 hacking incidents that resulted in the compromise of the health records … Read more
Neuromusculoskeletal Center of The Cascades Settles Class Action Lawsuit
HIPAA-covered entity Neuromusculoskeletal Center of The Cascades, PC, and Cascade Surgicenter LLC in Oregon decided to resolve a class action lawsuit resulting from a data breach in October 2023. Employee email accounts were accessed by … Read more
Greater Cincinnati Behavioral Health Services Settles Data Breach Litigation for $850K
HIPAA-covered entity Greater Cincinnati Behavioral Health Services (GCBHS) decided to pay approximately $850,000 to settle all claims associated with a ransomware attack in December 2023 involving unauthorized access to patient and worker data. On December … Read more
Skagit Regional Health Resolves Data Breach Lawsuit Involving Use of Tracking Technologies
Skagit County Public Hospital District No. 1, also called Skagit Regional Health, operates Skagit Regional Hospital, located in Mount Vernon, Washington, agreed to settle class action litigation prompted by its installation of Meta Pixel and … Read more
Verily Faces Lawsuit Over Alleged HIPAA Violations
Verily, owned by Alphabet, is facing a lawsuit filed by an ex-employee who alleges the misuse of the personally identifiable health information of over 25,000 patients, and the failure of the company to submit HIPAA … Read more
163,000 Wayne Memorial Hospital Patients Affected by May 2024 Ransomware Attack
Wayne Memorial Hospital patients received notification recently about a ransomware group that stole their protected health information (PHI) fifteen months ago. The 84-bed rural hospital located in Jessup, Georgia, sent personal notifications to the 163,400 … Read more
Court Approves $40 Million Data Breach Settlement by Cencora & The Lash Group
Cencora & The Lash Group decided to create a $40 million fund to resolve class action litigation over a data breach in February 2024 that affected approximately 1.43 million people. Cencora, Inc., formerly known as … Read more
Syracuse ASC Pays $250K to Resolve Violations of HIPAA Risk Analysis and Breach Notification Law
Director Paula M. Stannard of the Department of Health and Human Services (HHS) Office for Civil Rights (OCR) announced the 18th HIPAA penalty for 2025. Ambulatory surgery center in Liverpool, New York, Syracuse ASC dba … Read more
Northbay Healthcare Pays $3.6 Million to Resolve Data Breach Lawsuit
Northbay Healthcare Corporation agreed to a settlement to resolve a class action lawsuit associated with a 2024 cyberattack and data breach that impacted approximately 570,000 people. Northbay Healthcare discovered suspicious activity inside its computer system … Read more
20 States Sue HHS and DHS for Alleged Illegal Disclosure of Medicaid Data
An alliance of 20 state Attorneys General is filing a lawsuit against the Department of Homeland Security (DHS), DHS Secretary Kristi Noem, the Department of Health and Human Services (HHS), and HHS Secretary Robert F. … Read more
MNGI Digestive Health Resolves Data Breach Lawsuit for $2.8 Million
MNGI Digestive Health consented to resolve a class action lawsuit associated with its negligence for not securing sensitive patient data. The lawsuit is a result of a ransomware attack on the Minnesota gastroenterology practice by … Read more
Class Action Lawsuits Filed Over HealthEC Data Breach
HealthEC LLC faced multiple class action lawsuits because of a data breach that affected about 4.5 million people. Hackers acquired access to the population health management system of HealthEC from July 14 to July 23, … Read more
WellNow Urgent Care Agreed to Settle Data Breach Litigation for $4.4 Million
WellNow Urgent Care (earlier known as Five Star Urgent Care), a community of walk-in urgent care centers in Illinois, New York, Ohio, and Michigan, has decided to pay $4.4 million to resolve a class action … Read more
ELENOR-Corp Ransomware Group Attacks the Healthcare Sector with Mimic Ransomware Variant
According to the cybersecurity company Morphisec, a new ransomware group known as ELENOR-corp is targeting the healthcare sector. Researchers confirmed that ELENOR-corp is utilizing version 7.5 of Mimic ransomware, a ransomware strain first discovered in … Read more
UnitedHealth Implements Aggresive Tactics on Ransomware Attack Loan Recovery
UnitedHealth Group has taken a confrontational approach to retrieve outstanding balances on loans released to HIPAA-covered healthcare companies impacted by the Change Healthcare ransomware attack in February 2024. The attack resulted in an extended outage … Read more
MATCH IT Act of 2025 aims to Address Patient Misidentification
The Health Insurance Portability and Accountability Act of 1996 required the creation of a national patient identifier – a unique ID for all U.S. citizens that would reliably link medical records to the correct persons. … Read more
Is It a HIPAA Violation to Say Someone is Your Patient?
Whether it is a HIPAA violation to say someone is your patient is an event-specific determination that depends on factors such as who is speaking, who they are speaking to, and the context of the … Read more
Fred Hutchinson Cancer Center Pays $11.5M to Settle a Class Action Data Breach Lawsuit
The University of Washington and Fred Hutchinson Cancer Center have decided to settle a proposed class action data breach lawsuit for $11,500,000 and set aside $13,500,000 to enhance cybersecurity. The lawsuit is a result of … Read more
Rhode Island HIE Faces Lawsuit for Alleged HIE Data Impermissible Disclosure
Ex-HIPAA officer Darlene Morris filed a lawsuit against the Rhode Island Quality Institute (RIQI) for allegedly being fired from work for exposing its impermissible disclosures of HIE information. As a state government contractor of Rhode … Read more
Morrison Community Hospital Settles Ransomware Lawsuit for $675K
Critical access hospital Morrison Community Hospital in Illinois has decided to settle a lawsuit for $675,000. The lawsuit was associated with a ransomware attack and data breach in 2023. The BlackCat/ALPHV ransomware group behind the … Read more
Memorial Healthcare System to Pay $60,000 to Settle Alleged HIPAA Right of Access Violation
Florida health system South Broward Hospital District, also known as Memorial Healthcare System, has consented to resolve an alleged HIPAA Right of Access violation determined by the U.S. Department of Health and Human Services’ Office … Read more
Virtual Private Network Solutions Pays $90,000 to Resolve HIPAA Investigation
The HHS’ Office for Civil Rights (OCR) has reported reaching a settlement that ended the investigation of a ransomware attack. Because Virtual Private Network Solutions failed to perform a HIPAA-compliant risk analysis, it will pay … Read more
HIPAA Privacy Rule: New Requirements for Reproductive Healthcare Entities
In April 2024, the HHS Office for Civil Rights (OCR) released the HIPAA Privacy Rule to assist the Reproductive Healthcare Privacy Final Rule. The new rule became effective on June 23, 2024, but the last … Read more
How Often Do You Have To Do HIPAA Training?
How often you have to do HIPAA training depends on factors such as material changes to HIPAA policies and procedures, the frequency of security awareness training, the outcomes of risk analyses and evaluations, and employers’ … Read more
HIPAA Security Awareness Training
HIPAA security awareness training should have the objective of showing members of the workforce why it is important to protect the confidentiality, integrity, and availability of individually identifiable health information as well as explaining cybersecurity … Read more
OMB’s Review of the Proposed Change to the HIPAA Security Rule
In December 2023, the Department of Health and Human Services (HHS) published its cybersecurity strategy for the healthcare sector, detailing a list of actions to be implemented to improve cybersecurity across the healthcare industry, including … Read more
UMC Health’s EHR System is Back After Ransomware Attack
UMC Health System based in Lubbock, Texas reported the progress of its recovery from the ransomware attack in September. The ransomware attack impacted several systems, including the systems used by Texas Tech Physicians and Texas … Read more
Choosing the Right HIPAA Compliance Software
HIPAA compliance software helps a covered entity deal with the issues of HIPAA by streamlining and automating compliance and undertaking comprehensive risk management processes. Smaller organizations that have less than 100 employees assign the responsibility … Read more
Crossing Borders: International Data Transfers
The European Court of Justice’s July 16th 2020 Schrems II judgment had major implications for the use of US cloud services. Since that case, every US cloud service provider has been obliged to verify the … Read more
Minimum Cybersecurity Standards Proposed in Healthcare Bill
A new bill known as the “Health Infrastructure Security and Accountability Act of 2024,” has been introduced to the U.S. Senate to strengthen cybersecurity standards for healthcare information systems. This legislative proposal aims to implement … Read more
New Bill Tackles Chinese Cyber Threats to US Infrastructure
The U.S. House Homeland Security Committee has introduced new legislation aimed at strengthening the nation’s cybersecurity defences against threats from China. This bill establishes an interagency task force to assess the risks by state-sponsored cyber … Read more
Why Cyberattackers Target Third-Party Vendors
Recent big data breaches that affected third-party vendors like Change Healthcare targeted critical security risk management issues for business associates and vendors. These breaches have proven the necessity of security measures and comprehensive monitoring of … Read more
OSHA’s New Online Database of Reported Severe Workplace Injuries
The Department of Labor’s Occupational Safety and Health Administration (OSHA) has introduced a new online dashboard designed to simplify searching its severe injury report database and tracking workplace injury trends in states under federal OSHA … Read more
HIPAA Compliance on Resume
Including HIPAA compliance on a resume is important for candidates in healthcare, IT, administration, and other fields handling sensitive health information. Including this skill emphasizes an understanding of patient privacy and data protection standards, making … Read more
57% More Active Ransomware Groups in H1 2024
Searchlight Cyber1 reported a 57% increase in the number of active ransomware groups. In H1 of 2023, 46 active ransomware groups were identified from posts on dark web data leak sites compared to 72 active … Read more
Atlantic General Hospital Pays $2.25 Million to Resolve Data Breach Lawsuit
Atlantic General Hospital in Berlin, MD, has proposed a $2.24 million settlement to resolve a class action lawsuit associated with a ransomware attack in 2023. The settlement proposal was given preliminary approval by the court. … Read more
Data Security: Business advantage rather than regulatory burden
What comes to mind first when the words ‘Data security’ are mentioned to most workers? Chances are, it is thoughts of things like; frequent password changes, oversensitive spam folders, the inability to make personal calls … Read more
EPA Urged to Develop a Strategy to Address Cybersecurity Risks in Water Sector
The U.S. water and wastewater systems are dealing with an increasingly serious threat from cyberattacks, which could have lasting consequences for public health and environmental safety. A report from the U.S. Government Accountability Office (GAO) … Read more



























































