HHS-OIG Urges CMS & MA Organziations Increase Efforts to Prevent Durable Medical Equipment Fraud
Each year, millions of taxpayers’ dollars are lost to Medicare and Medicaid fraud, with fraud related to durable medical equipment, prosthetics, orthotics, and supplies (DMEPOS) a major problem. In one case alone, the largest ever healthcare fraud loss charged by the Department of Justice, an 11-person, Russia-based transnational network attempted to defraud Medicare out of $10.6 billion through fraudulent DMEPOS billings. DMEPOS-related healthcare fraud is a longstanding problem for the Original Medicare program; however, HHS-OIG has identified fraud schemes targeting Medicare Advantage and warns that DMEPOS fraud could put the program at risk. Currently, more than half of all Medicare recipients, around 34 million individuals, are enrolled in the Medicare Advantage (MA) program. The MA program involves the government paying private health insurance companies – MA organizations – to provide coverage to Medicare enrollees. MA organizations may create networks of providers and DMEPOS suppliers, and contract with those organizations. Other suppliers can provide DMEPOS that do not...
Democratic Senators Reintroduce the Health Infrastructure Security and Accountability Act
On September 17, 2026, two Democratic Senators reintroduced the Health Infrastructure Security and Accountability Act, which seeks to improve cybersecurity standards for the U.S. healthcare system and make funds available to help rural and underserved hospitals invest in essential cybersecurity measures. The bill was reintroduced by Sens. Mark R. Warner (D-VA) and Ron Wyden (D-OR), following its initial introduction in the 118th Congress 2D Session on September 25, 2024. When the bill was first introduced, 394 large hacking-related healthcare data breaches had been reported to the Department of Health and Human Services Office for Civil Rights (OCR), involving the protected health information of 43 million Americans. At the time, the senators explained that cyberattacks are delaying and disrupting patient care, harming patient health and national security, and putting Americans at risk of identity theft and fraud. “These hacks are entirely preventable and are the direct result of lax cybersecurity practices by health care providers and their business partners,” explained the...
Settlement Resolves Class Action Data Breach Complaint Against Community Dental Care
Community Dental Care, a nonprofit Medicaid dental provider in the state of Minnesota, has agreed to settle class action litigation over a 2024 cyberattack and data breach that exposed patients’ personal and protected health information. The cyberattack and data breach that sparked the litigation occurred on or around December 20, 2024. A cybercriminal actor accessed its network and potentially exfiltrated the personal and protected health information of more than 130,000 individuals, including their names, health insurance information, dates of birth, medical information, and Social Security numbers. Approximately 7,100 of the affected individuals had their Social Security numbers exposed in the incident. Notification letters started to be mailed to the affected individuals on March 28, 2025. A few days after mailing notifications, a class action lawsuit was filed in the District Court for Ramsey County in the state of Minnesota. A further four class action complaints were filed in response to the data breach, which were consolidated into a single complaint. The consolidated...
Ambry Genetics Pays $700,000 Penalty to Settle HIPAA Violations
The U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) and the Aliso Viejo, California-based genetic testing and clinical genomics company Ambry Genetics Corporation have agreed to a settlement to resolve alleged violations of the Health Insurance Portability and Accountability Act (HIPAA). Ambry Genetics has agreed to pay a $700,000 financial penalty and adopt a corrective action plan to address the areas of noncompliance identified by OCR during its investigation of a breach of the electronic protected health information (ePHI) of 225,370 individuals. The data breach was reported to OCR on March 22, 2020, initially as involving the protected health information of 232,772 individuals, although the total was later updated to 225,370 individuals. Ambry Genetics identified suspicious activity within its email environment on January 22, 2020, and its forensic investigation determined that an unauthorized third party gained access to an employee’s email account as a result of a response to a phishing email. The account was accessed by a criminal actor...
McKesson Cyberattack: Stolen Data Includes 6.4 Million Unique Email Addresses
McKesson, a major U.S. wholesale medical supplies & equipment, pharmaceutical distribution, and healthcare technology solutions company, continues to investigate a cybersecurity incident involving unauthorized access and the exfiltration of sensitive data. The number of individuals affected has yet to be determined; however, on September 8, 2026, McKesson issued an update on the initial findings of its investigation. While the investigation and data review are ongoing, McKesson has confirmed that the information potentially exfiltrated likely included personal and protected health information such as names, addresses, phone numbers, email addresses, patient IDs, and dates of birth, along with one or more of the following data elements: Health insurance information (including Medicaid/Medicare ID numbers) Health and medical information (including dates of service, medical record numbers, providers, diagnoses, medications, test results, medical images, and care/treatment information) Billing, claims and payment information (including claim numbers, account numbers, billing codes,...



