Valley Oaks Health Data Breach Settlement Gets First Nod from Court
Valley Oaks Health faced class action litigation over a June 2023 data security incident that affected 50,352 individuals. The consolidated…
Get The FREE
HIPAA Checklist
Discover everything you need to become HIPAA compliant
Get Free ChecklistValley Oaks Health faced class action litigation over a June 2023 data security incident that affected 50,352 individuals. The consolidated…
Data breaches have been announced by Bacon County Health Services in Georgia, Comprehensive Orthopaedics & Musculoskeletal Care in Connecticut, Imagine…
iRhythm, a health technology company that specializes in wearable cardiac monitoring devices such as the Zio wearable ECG monitor, has…
A missing or inadequate HIPAA Security Risk Assessment can leave a major gap in your HIPAA compliance program. Yet many practices remain uncertain about what an SRA should cover, how often it should be updated.
Data breaches have been announced by Casper Orthopedic Associates in Wyoming and Atlantic Digestive Specialists in New Hampshire. Casper Orthopedic…
Laboratory Services Cooperative, a Seattle, Washington-based nonprofit clinical laboratory that provides diagnostic and analytical testing services for Planned Parenthood affiliates…
The scale of a 2025 data breach involving electronic protected health information stored on Oracle Health’s legacy Cerner servers is…
Jefferson-Blount-St. Clair Mental Health Authority has agreed to settle a consolidated class action lawsuit stemming from a 2025 security incident…
I spent two days at the beginning of September at the National Institute of Standards and Technology campus in Gaithersburg,…
A two-stage review of 4,019 medical and dental practices found an estimated 21,117 public replies that met a conservative patient-information…
The healthcare industry has the highest rate of third-party data breaches out of any sector, according to the Verizon Data…
A final rule updating the HIPAA Security Rule was due for release as early as May 2026; however, the time…
Data breaches have been announced by Bacon County Health Services in Georgia, Comprehensive Orthopaedics & Musculoskeletal Care in Connecticut, Imagine…
iRhythm, a health technology company that specializes in wearable cardiac monitoring devices such as the Zio wearable ECG monitor, has…
Data breaches have been announced by Casper Orthopedic Associates in Wyoming and Atlantic Digestive Specialists in New Hampshire. Casper Orthopedic…
The scale of a 2025 data breach involving electronic protected health information stored on Oracle Health’s legacy Cerner servers is…
There has been a 5.9% decline in healthcare breaches compared to H1 2025. Between January 1 and June 30, 2026,…
A coalition of 44 state attorneys general has agreed to settle a multistate investigation of Laboratory Corporation of America (Labcorp)…
On September 17, 2026, two Democratic Senators reintroduced the Health Infrastructure Security and Accountability Act, which seeks to improve cybersecurity…
Choosing HIPAA training for employees should be about compliance outcomes, not simply checking the box for mandatory training...
Why AI Tools are Problem for HIPAA Compliance and how training can help.
Organizations must take care how social media is used to avoid HIPAA violations.
Why healthcare students need additional targeted HIPAA training.
First identify which standards your organization needs to comply with HIPAA compliant, then implement these.
HIPAA security training is required for all members of the workforce regardless of whether they have access to PHI or not.
Changes to HIPAA in 2025, including expected upcoming updates.
The Health Information Privacy Reform Act, introduced last year to improve privacy protections for health data not currently protected by…
A $182,000 settlement has been agreed between the HHS’ Office for Civil Rights and five Delaware healthcare providers to resolve…
A New York business associate has chosen to settle an alleged violation of the Health Insurance Portability and Accountability Act…
Each year, millions of taxpayers’ dollars are lost to Medicare and Medicaid fraud, with fraud related to durable medical equipment,…
The HHS OIG fraud, waste, and abuse guidelines are intended to support healthcare organizations in their efforts to self-monitor compliance…
The Emergency Medical Treatment and Labor Act (EMTALA) is a federal law that requires qualifying healthcare providers in the Medicare…
Valley Oaks Health faced class action litigation over a June 2023 data security incident that affected 50,352 individuals. The consolidated…
Laboratory Services Cooperative, a Seattle, Washington-based nonprofit clinical laboratory that provides diagnostic and analytical testing services for Planned Parenthood affiliates…
Jefferson-Blount-St. Clair Mental Health Authority has agreed to settle a consolidated class action lawsuit stemming from a 2025 security incident…
Fairchild Medical Center and Boone Health have agreed to settlements to resolve complaints alleging they impermissibly disclosed patient data to…
CPAP Medical Supplies and Services, a Jacksonville, Florida-based provider of durable medical equipment for treating sleep apnea, has agreed to…
The Mental Health Association, a Chicopee, Massachusetts-based human services agency that provides substance use recovery and support services for developmental…
A settlement has been agreed to resolve class action litigation over a November 2024 targeted cyberattack on the information systems…
Settlements have been agreed to resolve class action complaints against Wayne Memorial Hospital in Georgia and Regional Urology in Louisiana…
An analysis of medical devices indicates that healthcare organizations face a significant risk of future quantum-enabled attacks, as only a…
Citrix has released another patch for a zero day vulnerability under active exploitation, just a few days after patches were…
Two critical zero-day vulnerabilities in Citrix NetScaler ADC (formerly Citrix ADC) and Citrix NetScaler Gateway (formerly Citrix Gateway) are under…
An artificial intelligence (AI) agent developed by OpenAI gained unauthorized access to an Australian Medicare statistics reporting service portal and…
The Department of Health and Human Services (HHS) has provided an update on how it plans to accelerate the adoption of artificial intelligence (AI) in clinical care settings. AI has…
A lawsuit has been filed in the U.S. District Court for the Northern District of California against two healthcare organizations over their use of an AI-based tool that records conversations…
The Department of Health and Human Services (HHS) Centers for Medicare and Medicaid Services (CMS) has launched the first wave of Health Tech Ecosystem tools as part of its initiative…
A missing or inadequate HIPAA Security Risk Assessment can leave a major gap in your HIPAA compliance program. Yet many…
Learn where AI is hiding in your practice, the HIPAA risks it creates, and a simple framework for using AI…
See what an investigation actually looks like and learn where organizations fail so you can avoid government fines and drawn…
A bill that seeks to prohibit the Department of Labor’s Occupational Safety and Health Administration (OSHA) from issuing a standard on heat illness and heat injury prevention has been advanced…
On April 10, 2026, two days after the Occupational Safety and Health Administration’s (OSHA) Heat National Emphasis Program (NEP) expired, OSHA announced an update to the NEP. The updated NEP…
The Department of Labor Office of Inspector General will be conducting a federal audit to determine how well the Occupational Safety and Health Administration (OSHA) is addressing the growing problem…
A bipartisan bill that seeks to improve healthcare cybersecurity and resilience has been unanimously passed by the U.S. Senate. The…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has penned a final rule under the Cyber Incident Reporting for Critical…
The U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) has issued guidance for state Medicaid…
HIPAA compliance training for business associates should include Security Rule security awareness training, applicable Privacy Rule training, Breach Notification Rule…
Mandatory HIPAA training explained.
Medical spas that qualify as HIPAA-Covered Entities should provide all members of their workforce with HIPAA training that covers foundational…
5-part guide to choosing HIPAA training