Doctor Alliance Investigating 353 GB Data Theft Claim
Dallas, TX-based Doctor Alliance, a HIPAA business associate that provides document management and billing services to HIPAA-covered entities, is investigating a claim that a hacker exfiltrated 353 GB of data in a November cyberattack. On or around November 7, 2025, a hacker using the moniker Kazu, added a post to an underground hacking forum claiming to have stolen 1.24 million files from Doctor Alliance. The hacker has demanded a $200,000 ransom, payment of which is required to ensure that the stolen data is deleted. The hacker has threatened to sell the data if the ransom is not paid. A 200 MB sample was added to the listing that was analyzed and found to contain what appears to be patient names, addresses, phone numbers, email addresses, medical record numbers, Medicare numbers, diagnoses, treatment information, medications, and provider information. According to the leak site, Doctor Alliance has until November 21, 2025, to pay the ransom. While the sample appears to include patient data, it has yet to be confirmed whether the data came from Doctor Alliance. It is possible...
What is the Best EMR for Small Practices in 2026?
Whether you are starting a new practice or looking to grow your existing business, choosing the right electronic medical record system (EMR) is key to improving revenues and profits. An EMR is more than a system for managing large data records. An EMR is an invaluable tool at the heart of your practice that facilitates many aspects of your practice’s operations, such as scheduling, payments, insurance billing, record requests, patient engagement, telehealth, patient follow-ups, and HIPAA compliance. In addition to ensuring accurate patient records, an EMR is an invaluable tool for aiding decision-making, improving efficiency by streamlining documentation, and eliminating manual administrative tasks that inevitably impact revenue-generating activities and patient care. An EMR can significantly improve the patient experience by streamlining scheduling, providing patients with easy access to their health data to improve engagement, and facilitating communication, helping to improve satisfaction and attract new patients. With an EMR that is the right fit for your practice, you can...
HIPAA Compliance Training Programs
HIPAA compliance training programs are foundational training courses that ensure every member of the workforce understands basic HIPAA provisions to better protect patient information, follow internal policies and procedures, recognize privacy and security risks, and respond appropriately to incidents. The purpose of HIPAA compliance training programs is to fill gaps in workforce knowledge that are attributable to organizations applying the HIPAA training requirements to the letter of the law. For example, the HIPAA Privacy Rule training standard (45 CFR 164.530(b)(1)) states: “A covered entity must train all members of its workforce on policies and procedures […] as necessary and appropriate for the members of the workforce to carry out their functions within the covered entity”. When this requirement is complied with literally, staff may understand the organization’s policies and procedures, but not the underlying principles. This can lead to confusion in new or ambiguous situations, and unintentional violations of HIPAA when the connection between policy and behavior is absent....
Warning Issued About Akira Ransomware as Attacks on Critical Infrastructure Accelerate
A joint cybersecurity advisory has been issued by the Federal Bureau of Investigation (FBI), Cybersecurity and Infrastructure Security Agency (CISA), Department of Defense Cyber Crime Center (DC3), Department of Health and Human Services (HHS), and international law enforcement partners about the Akira ransomware group, which has accelerated its attacks on critical infrastructure in recent months. According to the FBI, Akira has been paid more than $244 million in ransoms since the group was first identified in March 2023. While Akira primarily targets small- to medium-sized organizations, the group has also attacked larger organizations, favoring sectors such as manufacturing, education, information technology, healthcare, financial services, and food and agriculture. The group’s tactics are constantly evolving. While the group initially targeted Windows systems, a Linux version of its encryptor has been developed that is used to target VMware Elastic Sky X Integrated (ESXi) virtual machines (VMs), and recently the group has been observed encrypting Nutanix AHV VM disk files....
HIPAA Compliance for Pediatricians
HIPAA compliance for pediatricians means following established privacy and security policies to protect children’s protected health information at every touchpoint, including verifying a parent or guardian’s authority before disclosures, applying the minimum necessary standard in communications with schools and caregivers, safeguarding records across EHRs, portals, and mobile devices, and promptly reporting potential incidents so privacy or security risks are contained quickly. HIPAA compliance for pediatricians is complicated by the provisions of the Privacy Rule relating to personal representatives of unemancipated minors and the data sharing requirements of the 21st Century Cures Act Interoperability Final Rule. Most pediatricians, or the organizations they work for, are Covered Entities under HIPAA if they transmit health information electronically in connection with a transaction for which the Department of Health and Human Services (HHS) has developed standards. These transactions include (but are not limited to): Payment and remittance advice Claims status Eligibility...



