Medusind to Pay $5 Million to Settle Data Breach Litigation
Medusind has agreed to pay $5,000,000 to settle a consolidated class action lawsuit over a 2023 data breach. Medusind is a revenue cycle management and practice management software vendor based in Florida. On or around December 29, 2023, the firm identified unauthorized access to its computer systems and found evidence to suggest that files had been exfiltrated from its network. The file review confirmed that more than 701,000 individuals had protected health information exposed in the incident, including names, contact information, health insurance information, medical histories, driver’s license numbers, passport numbers, and Social Security numbers. Notification letters were mailed to the affected individuals more than a year after the intrusion was detected. Victims of the breach took legal action against Medusind, claiming negligence for failing to implement reasonable and appropriate safeguards to protect individuals’ personal and protected health information. Eight separate complaints were filed in response to the data breach. Since they had overlapping claims, they...
Michigan Critical Access Hospital Suffers Two Hacking Incidents Affecting Almost 78,000 Individuals
Sturgis Hospital, a rural critical access hospital in Michigan, has recently reported two security incidents to the HHS’ Office for Civil Rights, both of which have potentially affected up to 77,771 individuals. The first incident was identified in December 2024 when unauthorized activity was observed in part of its computer network. Third-party cybersecurity experts were engaged to investigate the incident and determine the nature and scope of the unauthorized activity. Unauthorized access was confirmed, the incident was remediated, and the exposed files were reviewed to determine the individuals affected and the types of data involved. The investigation and file review had not concluded when further unauthorized network activity was detected in June 2025. A separate investigation was launched into the second incident, with assistance provided by third-party experts. Based on the two investigations, Sturgis Hospital concluded that there was potentially unauthorized access to patient and employee information and files containing sensitive patient and employee data may have been...
August 2025 Healthcare Data Breach Report
There has been a 13.7% month-over-month increase in large healthcare data breaches, with 58 breaches affecting 500 or more individuals reported to the HHS’ Office for Civil Rights in August, slightly lower than the 2025 average of 63.5 large healthcare data breaches per month. Since 2009, the number of reported healthcare data breaches has generally increased each year, although there was a slight reduction in data breaches last year (746 in 2023 vs. 739 in 2024), and that trend appears to be continuing this year. HIPAA-regulated entities have reported 508 large healthcare data breaches in the year to August 31, 2025, compared to 515 large healthcare data breaches over the corresponding period in 2024. For the second consecutive month, the number of individuals affected by healthcare data breaches has fallen. Across the 58 data breaches, the protected health information of 3,789,869 individuals was exposed or impermissibly accessed/disclosed. On average, 5,084,784 individuals have been affected by healthcare data breaches each month this year (median 3,583,200 individuals). The...
HIPAA Training for Individuals
IPAA training for individuals is a practical way to learn how to protect patient information, understand legal responsibilities, and demonstrate knowledge of HIPAA requirements even when training is not provided directly by an employer. What HIPAA Training for Individuals Covers Individual HIPAA training is designed for people who handle or may handle protected health information as part of their work, education, or career development. This includes healthcare professionals, administrative staff, students, contractors, consultants, and anyone preparing for a role in a HIPAA regulated environment. Online training is strongly recommended for individuals because it allows self paced learning, flexible scheduling, and immediate access to completion certificates. Online courses also make it easier to refresh knowledge annually, which aligns with industry best practice. HIPAA Training Course Content A well designed HIPAA training course for individuals focuses on real world understanding rather than legal theory alone. Core topics explain what protected health information is, why it must...
How Often Do You Need HIPAA Training?
The best practice in the healthcare sector is to have HIPAA training at least annually. How often you need HIPAA training can depend on how often there is a material change to HIPAA policies and procedures, how often a risk assessment identifies a need for further training, how often HIPAA training is enforced as a sanction for a HIPAA violation, and how often training is a requirement of a corrective action plan. The frequency of HIPAA training can be subject to a number of factors. These include the frequency of changes to the Privacy Rule, workforce members’ roles and functions, identified risks to the privacy of Protected Health Information (PHI), violations of HIPAA in the workplace, and corrective actions following a breach notification to HHS’ Office for Civil Rights. In addition, covered entities and business associates are required by the Security Rule to implement a security and awareness training program. The frequency of HIPAA security and awareness training is set by each covered entity or business associate. However, the inclusion of the word “program” in...



