Wilbarger General Hospital & Ochsner LSU Health System Announce Data Breaches
Data breaches have been announced by Wilbarger General Hospital, a rural and community hospital in Vernon, Texas, and Ochsner LSU Health System – Regional Urology in northern Louisiana. Wilbarger General Hospital Wilbarger General Hospital, a rural and community hospital in Vernon, Texas, has recently announced a security incident involving unauthorized access to an employee’s email account. Suspicious activity was identified within the account on October 20, 2025, and an investigation was launched to determine the cause of the activity. Assisted by third-party cybersecurity experts, Wilbarger General Hospital determined that an unauthorized third party had access to the email account for a short period, during which time information in the account may have been accessed or copied. The affected account was reviewed to determine the extent to which patient data had been exposed, and on November 25, 2025, Wilbarger General Hospital confirmed that patients’ protected health information was present in the account. The substitute breach notice states that the review of the account is...
Senator Pushes EHR Vendors to Give Patients Greater Control Over Health Record Sharing
Senator Ron Wyden (D-OR) is pushing electronic health record (EHR) vendors to add features to their products to give patients greater control over how and with whom their health information is shared. Digital health records have revolutionized how health information is stored and shared. While there have been data sharing challenges, a concerted effort toward interoperability has allowed different health systems to communicate and exchange health information seamlessly to support the provision of timely, coordinated, and high-quality health care. Congress recognized the importance of electronic health records with the passing of the Health Information Technology for Economic and Clinical Health Act (HITECH Act) in 2009. One of the main aims of the HITECH Act was to encourage the adoption of EHRs. Then, in 2016, Congress passed the 21st Century Cures Act to improve the exchange of health information between providers. The 21st Century Cures Act required health information in EHRs to be accessible and exchangeable across different health systems, also giving patients the right to...
Governor Hochul Vetoes New York Health Information Privacy Act
The New York Health Information Privacy Act (NYHIPA) was passed by the New York Assembly and Senate earlier this year and headed to New York Governor Kathy Hochul’s desk on December 8, 2025, to await her signature; however, on December 19, 2025, Governor Hochul vetoed the healthcare privacy law. The federal Health Insurance Portability and Accountability Act (HIPAA) covers protected health information that is created, collected, stored, or transmitted by healthcare providers, health plans, healthcare clearinghouses, and business associates of those entities; however, a vast amount of personally identifiable health data is created, collected, stored, and transmitted by entities not bound by the HIPAA Rules. Many state residents mistakenly believe that all health information is covered by HIPAA and must be protected, when that is not the case. NYHIPA “creates a legal framework for residents to reclaim and retain control of their healthcare information,” introducing HIPAA-like protections for personally identifiable health data not covered by the HIPAA Rules (A full...
HIPAA Compliance for Call Centers
HIPAA compliance for call centers is achieved by implementing policies, procedures, and safeguards that protect Protected Health Information (PHI) during inbound and outbound communications, while ensuring the workforce understands how to apply those safeguards in real conversations. Call centers often handle high volumes of sensitive information in fast-paced environments where mistakes can happen quickly, such as disclosing information to the wrong person, failing to verify identity, or documenting too much information in call notes. Compliance depends on the HIPAA Privacy Rule, the HIPAA Security Rule, and the HIPAA Breach Notification Rule working together, supported by practical training that reduces avoidable errors. Call Centers and HIPAA Coverage Call centers may operate as part of a covered entity, such as a hospital scheduling center, a health plan member services line, or a pharmacy support line. Call centers can also operate as HIPAA Business Associates when they provide services on behalf of covered entities and create, receive, maintain, or transmit PHI in the...
The Top HIPAA Threats Are Likely Not What You Think
The top HIPAA threats are threats from insiders who, either due to a lack of HIPAA training or a lack of security awareness, violate HIPAA standards or make mistakes that allow cybercriminals to access healthcare networks. While more training could help mitigate these top HIPAA threats, a fairly enforced sanctions policy will likely be more effective. Many articles listing the top HIPAA threats pretty much follow a similar theme. Protect devices against theft, protect data against cybercriminals, and protect yourself against unauthorized third party disclosures by signing a Business Associate Agreement. Unfortunately these articles are way off the mark. The top HIPAA threats facing healthcare organizations today often originate inside the organization rather than from external attackers. In many organizations, the most common issues involve workforce behaviors, inappropriate access, mishandled credentials, and avoidable mistakes that expose systems to threat actors. Technical safeguards matter, but insider activity remains one of the top HIPAA threats that compliance teams must...



