Healthcare’s Reliance on Outdated IT Putting Patient Safety and Cybersecurity at Risk
Outdated systems are causing healthcare professionals to lose hours each week, impacting patient care, organizational performance, efficiency, and security, according to a new report from the technology services and solution provider Presidio. The report is based on a survey of more than 1,000 frontline healthcare professionals in the United States, the United Kingdom, and Ireland. Almost all respondents (98%) said inefficient technologies are causing patient care and safety issues, including delays or errors in patient care, and 89% said those issues are a regular occurrence, with 24% reporting that these incidents occur at least once per shift. On average, the respondents experienced 11 such incidents a month. Healthcare employees are using legacy software and outdated devices that do not support efficient working practices. Some of the main problems associated with outdated systems were latency issues with EHR systems, disconnected and fragmented platforms, and a lack of mobile access. Due to inefficiencies, almost one-quarter of respondents (23%) said they often resort to...
Vendor Breaches Announced by Illinois and Virginia Healthcare Providers
Personic Management Company (Personic Health) and Innovative Physical Therapy have recently confirmed that patient information was compromised in vendor security incidents. Anchorage Neighborhood Health Center has recently disclosed an August cyberattack that exposed patient data. Personic Management Company (Personic Health) Vienna, VA-based Personic Management Company LLC, doing business as Personic Health, a wound care specialist, has recently disclosed a data breach involving a third-party software platform used to process patient data. Personic Health was informed on September 1, 2025, that there had been unauthorized access to the platform. Assisted by third-party digital forensics experts, Personic Health launched a comprehensive investigation to determine how the breach occurred and the types of information potentially compromised in the incident. The investigation confirmed that an unauthorized actor accessed the platform on August 29, 2025, and acquired certain data. The data review was completed on October 13, 2025, and confirmed that the protected health information had...
Watson Clinic Agrees to $10 Million Data Breach Settlement
Florida’s Watson Clinic has agreed to pay $10,000,000 to settle class action litigation over a January 2024 data breach that affected 280,278 individuals. The hackers stole sensitive data, including digital images, and posted them on the dark web. The Lakeland-based medical group serves approximately one million patients annually and employs around 1,600 team members and 350 physicians. Watson Clinic identified unauthorized access to its computer network on February 6, 2024, and the forensic investigation confirmed that hackers first gained access to its network on January 26. The review of the exposed files confirmed that they contained the protected health information of current and former patients, including names, addresses, dates of birth, Social Security numbers, government identifiers, driver’s license numbers, financial account information, and medical information, including diagnoses, treatments, medical record numbers, and pre- and/or post-operative medically necessary images. Watson Clinic received the results of the third-party file review in July 2024, announced...
How Long Does HIPAA Training Take?
HIPAA training for employees typically takes about 90 minutes to 3 hours depending on the specific needs and roles of the individuals being trained and where they work. New employees typically need training that takes at least 3 hours to cover everything in a HIPAA compliance training program. For healthcare staff who have already received comprehensive training, then HIPAA refresher training typically takes about 90 minutes to complete. Recommended core HIPAA training should introduce HIPAA, explain why the training is being provided, and highlight the importance of asking questions so that workforce members understand, absorb, and apply what they learn. It should cover the main HIPAA Regulatory Rules—the Privacy, Security, and Breach Notification Rules—and how they apply to day-to-day roles, along with practical guidance on complying with workplace policies. Core content should also explain HIPAA compliance from staff members’ perspective, including how to recognize and report HIPAA security incidents, and emphasize the consequences of HIPAA violations and breaches for...
$6.5 Million Settlement Resolves Omni Family Health Class Action Data Breach Lawsuit
Omni Family Health, a network of 39 community health centers in Kern, Kings, Tulare, and Fresno counties in California, experienced a cyberattack in 2024. A $6.5 million settlement has recently been agreed to resolve the resultant class action litigation. Omni Family Health experienced a cyberattack in February 2024 that caused a 5-day outage of its IT systems. The cyberattack was investigated at the time; however, no evidence was found to indicate that any patient data had been compromised in the incident. On August 7, 2024, Omni Family Health was made aware that a threat actor (Hunters International) had claimed to have compromised its network and had posted data allegedly stolen in the attack on the dark web. Omni Family Health investigated and concluded that the data was real and issued notifications to the 468,344 affected individuals, who included current and former patients and employees. Data potentially stolen in the attack included names, addresses, Social Security numbers, dates of birth, health insurance information, and medical information. The affected individuals...



