PHI Potentially Stolen in Phishing Attack on Superior Vision Services
Superior Vision Service has announced that protected health information has been compromised in a phishing attack. People Encouraging People has fallen victim to a ransomware attack. Superior Vision Service Superior Vision Services, a vision insurance company and subsidiary of Versant Health, has announced a July 2025 security incident. According to the September 26, 2025, notification letters, Superior Vision learned on July 11, 2025, that an employee had been tricked in a sophisticated phishing attack and disclosed their credentials to the attacker. The employee responded to the phishing email on July 9, 2025, and the threat actor used the employee’s credentials to access their account. On July 11, 2025, the threat actor may have copied emails from the account that contained sensitive customer information. The account was reviewed and found to contain full names, physical addresses, phone numbers, email addresses, dates of birth, genders, Social Security numbers, vision coverage election information, and employment information related to enrollment. Notification letters...
$2.55M Settlement Agreed to Resolve Octapharma Plasma Data Breach Lawsuit
A settlement has been agreed to resolve litigation against Octapharma Plasma over its April 2024 ransomware attack and data breach. Octapharma Plasma operates more than 190 blood plasma donation centers in 35 states. On or around April 17, 2024, Octapharma detected suspicious activity within its computer systems. The investigation confirmed unauthorized access to parts of its network where sensitive personal information was stored, including names, dates of birth, Social Security numbers, health information, donor eligibility information, financial information, employee data, and business data. On April 26, 2024, shortly after the cyberattack was announced, a class action lawsuit was filed by Bret Woodall against Octapharma. Several other lawsuits were subsequently filed over the data breach, and the lawsuits were consolidated into a single action – Woodall v. Octapharma Plasma Inc. – since they were materially and substantively identical and had overlapping claims. The consolidated lawsuit alleged that Octapharma failed to reasonably secure, monitor, and maintain personal...
Healthcare Compliance Certification
Healthcare compliance certification can mean different things to different people. For individuals, healthcare compliance certification can mean they have completed an Accredited HIPAA Certification course that provides an overview of healthcare regulations in the U.S. For healthcare providers, a certificate of compliance can mean they comply with regulations and standards such as: The Health Insurance Portability and Accountability Act (HIPAA) Medicare Conditions for Participation (including LEIE screening) The Occupational Safety and Health Regulations for Healthcare The Texas Health and Safety Code (as amended by HB 300) The Service Organization Controls 2 (SOC 2) Type 2 There are many more regulations and standards that healthcare providers may be required to comply with depending on their location and the nature of their activities. This article focuses on the above five sets of regulations and standards, and explains what healthcare compliance certification means in the context of each. HIPAA Compliance Certification for Individuals The Health Insurance Portability and...
Data Breaches Announced by Treasure Coast Hospice & Harbor
Treasure Coast Hospice, a palliative care provider in Florida, and Harbor, a mental health and addiction treatment service provider in Ohio, have recently announced security incidents that have exposed patient data. Health & Palliative Services of the Treasure Coast (Treasure Coast Hospice), Florida Health & Palliative Services of the Treasure Coast, Inc. d/b/a Treasure Coast Hospice, a provider of palliative care and hospice services to residents of Martin, St. Lucie, and Okeechobee counties in Florida, has recently notified 13,234 individuals about a September 2024 security incident. On September 25, 2025, Treasure Coast Hospice was made aware of unusual activity within its email environment. A third-party cybersecurity firm was engaged to investigate the activity and confirmed unauthorized access to an email account that contained patient information. The account was reviewed, and on July 15, 2025, the data mining process was completed, and it was confirmed that a range of information had been exposed and may have been accessed or copied. The types of information...
Florida Medication Management Provider Discloses 150K-record Data Breach
Outcomes One, a Florida-based business associate of health plans, has disclosed a phishing incident that has affected almost 150,000 individuals. Emergency Responders Health Center in Idaho has experienced an email breach affecting more than 1,500 individuals. Outcomes One, Inc., Florida Outcomes One, Inc., a Florida-based provider of medication therapy management and medication adherence technology solutions to health plans, is notifying 257,481 individuals about a recent email security incident. An employee identified unusual activity in his Outcomes One email account on July 1, 2025, and reported it to the security team. The email account was immediately secured, and an investigation was launched to determine the cause of the activity. The investigation confirmed that the breach was limited to a single employee email account, which had been accessed by an unauthorized third party following a response to a phishing email. Outcomes One said the attack was identified and remediated within an hour. The account was reviewed and found to contain names in combination with one or more...



