Data Breaches Announced by Five Small Healthcare Organizations
Five small healthcare organizations have recently announced that they have experienced security incidents exposing patient data: Family Medical Associates of…
Get The FREE
HIPAA Checklist
Discover everything you need to become HIPAA compliant
Get Free ChecklistFive small healthcare organizations have recently announced that they have experienced security incidents exposing patient data: Family Medical Associates of…
CISA, the FBI, and international partners have issued a joint cybersecurity advisory about the Gunra ransomware-as-a-service (RaaS) operation, which is…
A vishing attack on Sunshine Health, a Florida-based Medicaid and health insurance agency, involved the theft of the PHI of…
A data breach has recently been announced by Child Care Resource Center that shows how even well-intentioned employee practices can…
Data security incidents have recently been announced by Loma Linda University Health and UCLA Health. Loma Linda University Health Loma…
Over the past 18 months, many healthcare providers have settled class action lawsuits over their use of website tracking and…
The Health Information Privacy Reform Act, introduced last year to improve privacy protections for health data not currently protected by…
Free Webinar: HIPAA Compliant Email – What you Actually Need (Without an IT Team)
The healthcare industry has the highest rate of third-party data breaches out of any sector, according to the Verizon Data…
A final rule updating the HIPAA Security Rule was due for release as early as May 2026; however, the time…
Artificial intelligence is rapidly reshaping healthcare, offering new ways to analyze data, support clinical decisions, streamline operations, and improve patient…
Hackers focus on medical records because the combination of demographic data, insurance details, clinical information, and financial identifiers creates a…
Five small healthcare organizations have recently announced that they have experienced security incidents exposing patient data: Family Medical Associates of…
A vishing attack on Sunshine Health, a Florida-based Medicaid and health insurance agency, involved the theft of the PHI of…
Data security incidents have recently been announced by Loma Linda University Health and UCLA Health. Loma Linda University Health Loma…
On July 23, 2026, the HIPAA Journal reported on a data breach at Unlimited Technology Systems, a Cincinnati, Ohio-based provider…
The United States Consumer Product Safety Commission (CPSC) is requesting digital patient data from hospitals as part of its efforts…
OSF Healthcare System and its Affiliated Covered Entities (OSF Healthcare) have agreed to pay a penalty of $552,250 to resolve…
Based on the current data on the HHS’ Office for Civil Rights (OCR) breach portal, 61 healthcare data breaches affecting…
Choosing HIPAA training for employees should be about compliance outcomes, not simply checking the box for mandatory training...
Why AI Tools are Problem for HIPAA Compliance and how training can help.
Organizations must take care how social media is used to avoid HIPAA violations.
Why healthcare students need additional targeted HIPAA training.
First identify which standards your organization needs to comply with HIPAA compliant, then implement these.
HIPAA security training is required for all members of the workforce regardless of whether they have access to PHI or not.
Changes to HIPAA in 2025, including expected upcoming updates.
The Health Information Privacy Reform Act, introduced last year to improve privacy protections for health data not currently protected by…
A $182,000 settlement has been agreed between the HHS’ Office for Civil Rights and five Delaware healthcare providers to resolve…
A New York business associate has chosen to settle an alleged violation of the Health Insurance Portability and Accountability Act…
The Department of Health and Human Services Office of Inspector General (HHS-OIG) has announced new additions to its List of…
Two hospitals have entered into settlement agreements with the Department of Health and Human Services (HHS) Office of Inspector General…
Over the past 18 months, many healthcare providers have settled class action lawsuits over their use of website tracking and…
The Belarusian cybercriminal behind the Ransom Cartel ransomware group has been sentenced to 16 years in prison for his role…
Settlements have been agreed to resolve class action data breach lawsuits against McKenzie Health System in Michigan and Aspire Health…
Settlements have been agreed to resolve class action data breach lawsuits against Omni Healthcare Financial Holdings and its subsidiaries, and…
Him & Hers, a San Francisco, CA-based telehealth company, is being sued by the Federal Trade Commission (FTC) and the…
Two healthcare providers have agreed to settle lawsuits over their use of pixels and other website tracking technologies. The tools…
Healthcare Services Group has agreed to pay $3,000,000 to settle litigation arising from a September 2024 cybersecurity incident that involved…
ApolloMD Business Services, a business associate that provides integrated, multispecialty physician, APC, and practice management services, has agreed to settle…
CISA, the FBI, and international partners have issued a joint cybersecurity advisory about the Gunra ransomware-as-a-service (RaaS) operation, which is…
A data breach has recently been announced by Child Care Resource Center that shows how even well-intentioned employee practices can…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA), Federal Bureau of Investigation (FBI), National Security Agency (NSA), and 15 international…
Health sector organizations have been warned about an increase in successful attacks by the ShinyHunters threat group. In contrast to…
The Department of Health and Human Services (HHS) has provided an update on how it plans to accelerate the adoption of artificial intelligence (AI) in clinical care settings. AI has…
A lawsuit has been filed in the U.S. District Court for the Northern District of California against two healthcare organizations over their use of an AI-based tool that records conversations…
The Department of Health and Human Services (HHS) Centers for Medicare and Medicaid Services (CMS) has launched the first wave of Health Tech Ecosystem tools as part of its initiative…
Free Webinar: HIPAA Compliant Email - What you Actually Need (Without an IT Team)
See what an investigation actually looks like and learn where organizations fail so you can avoid government fines and drawn…
According to the Paubox 2026 Healthcare Email Security Report, in 2025, 170 email-related data breaches were reported to the HHS’…
A bill that seeks to prohibit the Department of Labor’s Occupational Safety and Health Administration (OSHA) from issuing a standard on heat illness and heat injury prevention has been advanced…
On April 10, 2026, two days after the Occupational Safety and Health Administration’s (OSHA) Heat National Emphasis Program (NEP) expired, OSHA announced an update to the NEP. The updated NEP…
The Department of Labor Office of Inspector General will be conducting a federal audit to determine how well the Occupational Safety and Health Administration (OSHA) is addressing the growing problem…
The Health Information Privacy Reform Act, introduced last year to improve privacy protections for health data not currently protected by…
The Department of Health and Human Services Office of Inspector General (HHS-OIG) has announced that two settlements have been agreed…
Him & Hers, a San Francisco, CA-based telehealth company, is being sued by the Federal Trade Commission (FTC) and the…
HIPAA compliance training for business associates should include Security Rule security awareness training, applicable Privacy Rule training, Breach Notification Rule…
Mandatory HIPAA training explained.
Medical spas that qualify as HIPAA-Covered Entities should provide all members of their workforce with HIPAA training that covers foundational…
5-part guide to choosing HIPAA training