Pomona Valley Hospital Medical Center Pays $600K to Settle Meta Pixel Lawsuit
Pomona Valley Hospital Medical Center in California has agreed to pay $600,000 to resolve all claims in class action litigation over its use of Meta Pixel and similar tracking technologies on its public website. According to the lawsuit, the tracking tools resulted in an impermissible disclosure of personally identifiable information to third parties such as Meta (Facebook). The lawsuit – Warren v. Pomona Valley Hospital Medical Center – was filed in the Superior Court of the State of California, County of Los Angeles, and alleged the use of these tools violated wiretapping and other statutes. Pomona Valley Hospital Medical Center denies all material allegations in the lawsuit and maintains there was no wrongdoing or liability; however, the decision was made to settle the litigation to avoid the costs and risks associated with a trial and related appeals. Following extensive arm’s-length negotiations, a settlement in principle was reached, and the full terms of the settlement have now been finalized and approved by the court. Under the terms of the settlement, Pomona Valley...
What is the Texas Medical Records Privacy Act?
The Texas Medical Records Privacy Act is a law passed by the Texas legislature in 2001 that created Chapter 181 of the Texas Health and Safety Code. Subsequent amendments to the Act have strengthened its privacy protections and increased the penalties for non-compliance. Importantly, the Act can apply to organizations located outside the state of Texas. The Texas Medical Records Privacy Act came about due to the opinion of the state that the provisions of the first proposed HIPAA Privacy Rule in 1999 did not go far enough to protect the privacy of individually identifiable health information. The legislature subsequently developed standards that apply to medical records belonging to Texas residents. The adopted standards use the HIPAA Privacy Rule as a base and use many of the same definitions – the major difference being that Chapter 181 of the Texas Health and Safety Code applies to any person or organization (covered entity) that assembles, collects, analyzes, uses, evaluates, stores, or transmits Protected Health Information (PHI). Therefore, unlike HIPAA – which only applies...
Neuromusculoskeletal Center of The Cascades Settlement Provides Cash Benefits for Breach Victims
Neuromusculoskeletal Center of The Cascades, PC, and Cascade Surgicenter LLC in Oregon have agreed to settle class action litigation stemming from an October 2023 data incident. An unauthorized third party gained access to employee email accounts between October 2, 2023, and October 3, 2023. While the unauthorized access was detected and remediated promptly, the hackers had access to sensitive data such as names, addresses, phone numbers, email addresses, dates of birth, Social Security numbers, driver’s license numbers/state ID numbers, financial information, medical information, health insurance information, and digital signatures. Notification letters were mailed to the affected individuals on December 1, 2023. The Oregon Attorney General was informed that the breach affected 22,796 individuals, and the HHS’ Office for Civil Rights was notified that the protected health information of 19,373 individuals was potentially compromised in the attack. A class action lawsuit was filed by plaintiff Krysta Hakkila individually and on behalf of similarly situated individuals, which was...
New Jersey Medical Center Suffers Ransomware Attack
Central Jersey Medical Center in New Jersey has experienced a ransomware attack. David A. Nover, M.D, is notifying patients about a hacking incident, and Goglia Nutrition (FuturHealth) has announced an October 2024 data breach. Central Jersey Medical Center, New Jersey Central Jersey Medical Center, Inc., a Federally Qualified Health Center with locations in Perth Amboy, Newark, and Carteret, New Jersey, has started notifying dental patients about a recent security incident. On August 25, 2025, a cybercriminal actor gained access to its dental server’s network and used ransomware to encrypt files. An investigation was launched to determine the nature and scope of the activity, and a review was conducted to identify the patients affected and the types of information that were exposed. The electronic medical record system was unaffected; however, files containing patient information were potentially accessed or obtained. At the time of issuing notification letters, Central Jersey Medical Center had not found any evidence to indicate any misuse of the exposed data. The Sinobi...
Oglethorpe Hacking Incident Affects more than 92,000 Patients
A Tampa, FL-based network of mental health and addiction recovery treatment facilities has recently disclosed a security incident that involved unauthorized access to patient data. Oglethorpe offers management solutions for health centers, wellness clinics, and hospitals that specialize in psychiatric services, substance abuse treatment programs, and behavioral health counseling, and has facilities in Florida, Louisiana, and Ohio. In June 2025, Oglethorpe experienced a hacking incident that rendered its systems inoperable for a limited time. Third-party cybersecurity experts were engaged to help contain, investigate, and remediate the incident. The investigation revealed that the hackers first gained access to its network on May 15, 2025, and maintained access until June 6, 2025. The investigation concluded on September 16, 2025, when it was confirmed that files containing patient information had been exfiltrated from its network. Those files were reviewed, and that process was completed on October 23, 2025, when Oglethorpe learned that first and last names, birth dates, Social...



