Ambry Genetics Pays $700,000 Penalty to Settle HIPAA Violations
The U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) and the Aliso Viejo, California-based genetic…
Get The FREE
HIPAA Checklist
Discover everything you need to become HIPAA compliant
Get Free ChecklistThe U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) and the Aliso Viejo, California-based genetic…
McKesson, a major U.S. wholesale medical supplies & equipment, pharmaceutical distribution, and healthcare technology solutions company, continues to investigate a…
Modernizing Medicine, a Boca Raton, Florida-based company that provides cloud-based, AI-powered software and electronic health record systems for healthcare providers,…
The Florida dermatology practice, Brevard Skin and Cancer Center, has agreed to a settlement to resolve class action litigation stemming…
A hacking group has claimed responsibility for an August 2026 cyberattack on Cedar County Memorial Hospital in Missouri. Hacking-related data…
Learn where AI is hiding in your practice, the HIPAA risks it creates, and a simple framework for using AI while remaining HIPAA compliant.
A data breach at zHealth, a practice management and EHR software provider, has affected 118,000 individuals. Data breaches have also…
Data breaches have been reported by the Louisiana-based home health service provider LHC Group, Provident Behavioral Health in Missouri, Elixir…
A two-stage review of 4,019 medical and dental practices found an estimated 21,117 public replies that met a conservative patient-information…
The healthcare industry has the highest rate of third-party data breaches out of any sector, according to the Verizon Data…
A final rule updating the HIPAA Security Rule was due for release as early as May 2026; however, the time…
Artificial intelligence is rapidly reshaping healthcare, offering new ways to analyze data, support clinical decisions, streamline operations, and improve patient…
McKesson, a major U.S. wholesale medical supplies & equipment, pharmaceutical distribution, and healthcare technology solutions company, continues to investigate a…
A hacking group has claimed responsibility for an August 2026 cyberattack on Cedar County Memorial Hospital in Missouri. Hacking-related data…
A data breach at zHealth, a practice management and EHR software provider, has affected 118,000 individuals. Data breaches have also…
Data breaches have been reported by the Louisiana-based home health service provider LHC Group, Provident Behavioral Health in Missouri, Elixir…
The U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) and the Aliso Viejo, California-based genetic…
The HHS has released an updated version of the Security Risk Assessment (SRA) Tool (v3.7). The tool is ideally suited…
In June 2026, 66 large healthcare data breaches – data breaches involving the protected health information of 500 or more…
Choosing HIPAA training for employees should be about compliance outcomes, not simply checking the box for mandatory training...
Why AI Tools are Problem for HIPAA Compliance and how training can help.
Organizations must take care how social media is used to avoid HIPAA violations.
Why healthcare students need additional targeted HIPAA training.
First identify which standards your organization needs to comply with HIPAA compliant, then implement these.
HIPAA security training is required for all members of the workforce regardless of whether they have access to PHI or not.
Changes to HIPAA in 2025, including expected upcoming updates.
The Health Information Privacy Reform Act, introduced last year to improve privacy protections for health data not currently protected by…
A $182,000 settlement has been agreed between the HHS’ Office for Civil Rights and five Delaware healthcare providers to resolve…
A New York business associate has chosen to settle an alleged violation of the Health Insurance Portability and Accountability Act…
The HHS OIG fraud, waste, and abuse guidelines are intended to support healthcare organizations in their efforts to self-monitor compliance…
The Emergency Medical Treatment and Labor Act (EMTALA) is a federal law that requires qualifying healthcare providers in the Medicare…
The Department of Health and Human Services Office of Inspector General (HHS-OIG) has announced new additions to its List of…
Modernizing Medicine, a Boca Raton, Florida-based company that provides cloud-based, AI-powered software and electronic health record systems for healthcare providers,…
The Florida dermatology practice, Brevard Skin and Cancer Center, has agreed to a settlement to resolve class action litigation stemming…
Central Maine Medical Center & Susan B. Allen Memorial Hospital have agreed to settle class action lawsuits stemming from data…
Settlements have been reached to resolve class action data breach lawsuits against Palomar Health Medical Group in California and Summit…
Settlements have been agreed to resolve class action lawsuits against Wellstar Health System and Moses H. Cone Memorial Hospital Operating…
The Wisconsin mailing and printing vendor OneTouchPoint Corp. has agreed to settle class action litigation over a 2022 ransomware attack…
Managed Care of North America, Inc. (MCNA) has agreed to settle class action litigation stemming from a 2023 cybersecurity incident…
Highlands Oncology Group, an Arkansas-based physician-owned community cancer care and research practice serving Northwest Arkansas, Southwest Missouri, and Southeast Oklahoma,…
A Ukrainian national who deployed Conti ransomware on the networks of at least 12 organizations in the United States and…
A high-severity vulnerability has been identified in Orthanc DICOM Server that could be exploited by an authenticated remote attacker to…
Three high-severity vulnerabilities have been identified in NextGen Healthcare Mirth Connect (Mirth Connect), a cross-platform healthcare integration engine for connecting,…
The Federal Bureau of Investigation (FBI) has issued a warning about ongoing phishing activity involving a sophisticated technique known as…
The Department of Health and Human Services (HHS) has provided an update on how it plans to accelerate the adoption of artificial intelligence (AI) in clinical care settings. AI has…
A lawsuit has been filed in the U.S. District Court for the Northern District of California against two healthcare organizations over their use of an AI-based tool that records conversations…
The Department of Health and Human Services (HHS) Centers for Medicare and Medicaid Services (CMS) has launched the first wave of Health Tech Ecosystem tools as part of its initiative…
Learn where AI is hiding in your practice, the HIPAA risks it creates, and a simple framework for using AI…
See what an investigation actually looks like and learn where organizations fail so you can avoid government fines and drawn…
Free Webinar: HIPAA Compliant Email - What you Actually Need (Without an IT Team)
A bill that seeks to prohibit the Department of Labor’s Occupational Safety and Health Administration (OSHA) from issuing a standard on heat illness and heat injury prevention has been advanced…
On April 10, 2026, two days after the Occupational Safety and Health Administration’s (OSHA) Heat National Emphasis Program (NEP) expired, OSHA announced an update to the NEP. The updated NEP…
The Department of Labor Office of Inspector General will be conducting a federal audit to determine how well the Occupational Safety and Health Administration (OSHA) is addressing the growing problem…
On September 15, 2026, the United States House Energy and Commerce Committee Subcommittee on Health held a legislative hearing on…
In September 2021, the U.S. Federal Trade Commission (FTC) issued a policy statement extending the FTC Health Breach Notification Rule…
The U.S. Food and Drug Administration (FDA) has issued a discussion paper on considerations for the regulation of Generative AI…
HIPAA compliance training for business associates should include Security Rule security awareness training, applicable Privacy Rule training, Breach Notification Rule…
Mandatory HIPAA training explained.
Medical spas that qualify as HIPAA-Covered Entities should provide all members of their workforce with HIPAA training that covers foundational…
5-part guide to choosing HIPAA training