12,000-Record Data Breach Announced by New York Plastic Surgery Practice
Data breaches have recently been reported by Pearlman Aesthetic Surgery and Associated Radiologists of the Finger Lakes in New York and Fast Pace Urgent Care in Tennessee. Pearlman Aesthetic Surgery Steven J. Pearlman, MD, PC, a well-known plastic surgeon and the owner of Pearlman Aesthetic Surgery, a popular plastic surgery practice in Manhattan, New York, has recently reported a breach of the protected health information of 11,764 individuals to the HHS’ Office for Civil Rights (OCR). The specifics of the data breach have yet to be publicly disclosed, other than it being a hacking/IT incident. The incident was reported to OCR on November 9, 2025, and there is currently no substitute data breach notice on the Pearlman Aesthetic Surgery website. This post will be updated when further information becomes available. Associated Radiologists of the Finger Lakes Associated Radiologists of the Finger Lakes, a network of interventional and diagnostic radiology centers in Elmira, NY, and the surrounding areas, has identified unauthorized access to its computer network. Anomalous activity...
October 2025 Healthcare Data Breach Report
A delayed October 2025 healthcare data breach report due to the government shutdown for the whole of the month, which caused a significant delay at the HHS’ Office for Civil Rights, which failed to upload any data breach reports in October. The shutdown ended on November 12, 2025, and the HHS had a considerable backlog of data breaches to add to the data breach portal. When a data breach report is received, OCR verifies the data, a process that may take up to around two weeks, before it is added to the OCR breach portal. Data breaches continued to be added for October well into December. Based on data obtained from OCR on December 31, 2025, OCR received 28 reports of data breaches affecting 500 or more individuals in October – the lowest monthly total of the year, the lowest total since the 28 reported data breaches in May 2020, and a 31.7% month-over-month reduction in large healthcare data breaches. While there has been a downward trend in data breaches, the October total is suspiciously low, which could indicate the backlog of data breach reports has yet to be cleared. The...
What is the Purpose of HIPAA?
The purpose of HIPAA was originally to ensure more employees could continue to receive health insurance coverage when they were between jobs and would not be discriminated against for pre-existing conditions. Due to the costs that would be incurred by health plans – and concerns these may be passed on to plan members and employers – Congress added a second Title to the Act to combat fraud and abuse of the healthcare insurance system. Title II also instructed the Secretary for Health and Human Services to adopts standards to simplify the administration of healthcare transactions between healthcare providers and health plans. Because – prior to HIPAA – health plans had developed their own transaction code structures, more than four hundred sets of codes existed. Determining which code applied to which payer, and translating one code to another, often delayed transactions such as eligibility checks, treatment authorizations, and payment remittances. In additional to adopting standards for healthcare transactions, the Secretary was also instructed to develop...
What Does HIPAA Stand For?
The acronym HIPAA stands for Health Insurance Portability and Accountability Act of 1996 – an Act which ultimately led to the development of standards for the privacy and security of Protected Health Information, but which originally had the objective of reforming the health insurance industry. To best fully explain what does HIPAA stand for, it is a necessary to look at the state of the health insurance industry prior to 1996. The industry had grown from a handful of companies offering accident insurance in the 1850s – and employer-sponsored disability insurance from 1911 onwards – into a multi-billion dollar business by the end of the twentieth century. However, prior to 1996, the healthcare insurance industry was governed by a hotchpotch of federal and state legislation. The reason for the hotchpotch of legislation was that, in the early days of healthcare insurance, many commercial for-profit insurance providers were considered to be “unlicensed practitioners of medicine” because they indirectly provided medical services to policy holders. To overcome this...
Business Associate Data Breach Affects 55K Bosch Choice Welfare Benefit Plan Members
A business associate data breach has affected 55,000 members of the Bosch Choice Welfare Benefit Plan, and a data breach has been reported by Leidos QTC Health First Rehabilitation Resources. Bosch Choice Welfare Benefit Plan On October 31, 2025, Bosch Choice Welfare Benefit Plan reported a data breach to the HHS’ Office for Civil Rights (OCR) that affected 55,000 of its members. Bosch Choice Welfare Benefit Plan is a flexible benefits program for Bosch employees in the United States that includes health, dental, vision, life, and disability insurance. While limited details have been made public about the data breach, OCR closed the investigation quickly and has shared information on the incident via its data breach portal. A vendor of one of the health plan’s business associates experienced a cybersecurity incident that involved unauthorized access to systems containing names, Social Security numbers, dates of birth, claims, health insurance information, and diagnoses/conditions. Neither Bosch nor the HHS mentioned the name of the business associate, but the HHS report on...



