Data Breaches Announced by North Atlantic States Carpenters Health Benefits Fund & Millcreek Pediatrics
Data breaches have recently been announced by the North Atlantic States Carpenters Health Benefits Fund in Massachusetts and Millcreek Pediatrics in Delaware. Millcreek Pediatrics, Delaware Millcreek Pediatrics, a Wilmington, Delaware-based pediatric medical practice, has recently reported a data security incident to the HHS Office for Civil Rights involving the protected health information of 14,095 individuals. Unauthorized access to its network was detected on or around February 25, 2025. A leading digital forensics firm was engaged to investigate the activity, which confirmed unauthorized network access between February 17, 2025, and February 25, 2025. On October 27, 2025, the file review confirmed that protected health information had been exposed, including full names, birth dates, medical record numbers, patient identification numbers, driver’s license numbers/state identification numbers, dates of service, claims information, provider information, and clinical/treatment information. A limited number of the affected individuals also had their Social Security numbers exposed....
Davies, McFarland & Carroll; Awakenings Center Data Breaches Impact 72,500 Individuals
Data breaches have been announced by the medical malpractice law firm Davies, McFarland & Carroll, the sex therapy and couples counseling provider Awakenings Center, and the Maryland healthcare provider, Adventist HealthCare. Davies, McFarland & Carroll, Pennsylvania Davies, McFarland & Carroll LLC, a Pittsburgh, PA-based law firm specializing in medical malpractice, has experienced a significant data breach involving unauthorized access to the sensitive information of 54,712 individuals. Davies, McFarland & Carroll is a business associate of HIPAA-covered entities and is provided with access to protected health information to provide its legal services. On or around May 22, 2025, a network intrusion was detected. External cybersecurity experts were engaged to investigate the incident and confirmed that an unauthorized third party had access to its network from May 19, 2025, to May 22, 2025, during which time files containing sensitive data were either viewed or acquired. The forensic investigation and file review concluded on September 25, 2025, when it was...
Data Breaches Announced by Morton Drug Company & Physicians to Children & Adolescents
Data breaches have been announced by Morton Drug Company in Wisconsin, Physicians to Children & Adolescents in Kentucky, and the Center for Urologic Care of Berks County in Pennsylvania. Across the three incidents, the protected health information of more than 50,000 patients was exposed. Morton Drug Company, Wisconsin Morton Drug Company (Morton LTC), a Wisconsin-based pharmacy specializing in long-term care, has recently disclosed a security incident that has affected 40,051 individuals. The incident impacted its IT systems and was detected on or around August 20, 2025. Third-party cybersecurity experts were engaged to investigate, contain, and remediate the incident, and law enforcement was notified. Unauthorized network access was confirmed, and a review was conducted to determine the extent to which sensitive data had been exposed. On or around October 21, 2025, Morton LTC determined that patient data had been exposed and may have been stolen. The types of data involved vary from individual to individual and may include name in combination with address, prescription...
Building a Stronger Compliance Program With Software
Healthcare compliance software is a comprehensive management tool that helps professional compliance officers to effectively oversee compliance efforts across their organization’s facilities, by proactively managing risk, streamlining workflows, improving collaboration, and demonstrating the achievement of compliance objectives to stakeholders. What Are The Benefits Of Healthcare Compliance Software? For a compliance pro, the benefits of compliance software are: 1. Increased Visibility: Compliance software provides real-time visibility into compliance activities across sites, including incident management, allowing the chief compliance officer to monitor progress, track key metrics, and identify areas that require attention, on a per site and per employee basis. This increased visibility and granularity enhances the chief compliance officer’s ability to effectively oversee compliance efforts across the organization. 2. Streamlined Workflows: Compliance software automates many administrative tasks related to compliance management, such as tracking compliance activities,...
Bill Reintroduced to Strengthen Healthcare Cybersecurity
A bipartisan quartet of Senators has reintroduced the Health Care Cybersecurity and Resiliency Act of 2025 in another attempt to bolster privacy and healthcare cybersecurity. The Health Care Cybersecurity and Resiliency Act of 2025 was introduced by Senate Health, Education, Labor, and Pensions (HELP) Committee Chair Bill Cassidy (R-LA), and was co-sponsored by Sens. Mark Warner (D-VA), Maggie Hassan (D-NH), and John Cornyn (R-TX). The bill is the product of a bipartisan healthcare cybersecurity working group established in 2023, and it is largely unchanged from its first iteration, the Health Care Cybersecurity and Resiliency Act of 2024, which was introduced in November 2025 with little time for consideration before Congress adjourned at the start of this year. Cyberattacks on healthcare organizations have steadily increased over the past decade, with a significant uptick in recent years. In each of the past four years, more than 700 data breaches have been reported to the Department of Health and Human Services (HHS) Office for Civil Rights (OCR), with large data breaches now...



