$2.55M Settlement Agreed to Resolve Octapharma Plasma Data Breach Lawsuit
A settlement has been agreed to resolve litigation against Octapharma Plasma over its April 2024 ransomware attack and data breach. Octapharma Plasma operates more than 190 blood plasma donation centers in 35 states. On or around April 17, 2024, Octapharma detected suspicious activity within its computer systems. The investigation confirmed unauthorized access to parts of its network where sensitive personal information was stored, including names, dates of birth, Social Security numbers, health information, donor eligibility information, financial information, employee data, and business data. On April 26, 2024, shortly after the cyberattack was announced, a class action lawsuit was filed by Bret Woodall against Octapharma. Several other lawsuits were subsequently filed over the data breach, and the lawsuits were consolidated into a single action – Woodall v. Octapharma Plasma Inc. – since they were materially and substantively identical and had overlapping claims. The consolidated lawsuit alleged that Octapharma failed to reasonably secure, monitor, and maintain personal...
Healthcare Compliance Certification
Healthcare compliance certification can mean different things to different people. For individuals, healthcare compliance certification can mean they have completed an Accredited HIPAA Certification course that provides an overview of healthcare regulations in the U.S. For healthcare providers, a certificate of compliance can mean they comply with regulations and standards such as: The Health Insurance Portability and Accountability Act (HIPAA) Medicare Conditions for Participation (including LEIE screening) The Occupational Safety and Health Regulations for Healthcare The Texas Health and Safety Code (as amended by HB 300) The Service Organization Controls 2 (SOC 2) Type 2 There are many more regulations and standards that healthcare providers may be required to comply with depending on their location and the nature of their activities. This article focuses on the above five sets of regulations and standards, and explains what healthcare compliance certification means in the context of each. HIPAA Compliance Certification for Individuals The Health Insurance Portability and...
Data Breaches Announced by Treasure Coast Hospice & Harbor
Treasure Coast Hospice, a palliative care provider in Florida, and Harbor, a mental health and addiction treatment service provider in Ohio, have recently announced security incidents that have exposed patient data. Health & Palliative Services of the Treasure Coast (Treasure Coast Hospice), Florida Health & Palliative Services of the Treasure Coast, Inc. d/b/a Treasure Coast Hospice, a provider of palliative care and hospice services to residents of Martin, St. Lucie, and Okeechobee counties in Florida, has recently notified 13,234 individuals about a September 2024 security incident. On September 25, 2025, Treasure Coast Hospice was made aware of unusual activity within its email environment. A third-party cybersecurity firm was engaged to investigate the activity and confirmed unauthorized access to an email account that contained patient information. The account was reviewed, and on July 15, 2025, the data mining process was completed, and it was confirmed that a range of information had been exposed and may have been accessed or copied. The types of information...
Florida Medication Management Provider Discloses 150K-record Data Breach
Outcomes One, a Florida-based business associate of health plans, has disclosed a phishing incident that has affected almost 150,000 individuals. Emergency Responders Health Center in Idaho has experienced an email breach affecting more than 1,500 individuals. Outcomes One, Inc., Florida Outcomes One, Inc., a Florida-based provider of medication therapy management and medication adherence technology solutions to health plans, is notifying 257,481 individuals about a recent email security incident. An employee identified unusual activity in his Outcomes One email account on July 1, 2025, and reported it to the security team. The email account was immediately secured, and an investigation was launched to determine the cause of the activity. The investigation confirmed that the breach was limited to a single employee email account, which had been accessed by an unauthorized third party following a response to a phishing email. Outcomes One said the attack was identified and remediated within an hour. The account was reviewed and found to contain names in combination with one or more...
SSM Health Agrees to Settle MyChart Patient Portal Tracking Lawsuit
Individuals who used SSM Health’s MyChart patient portal when tracking tools were active are entitled to claim a cash payment and a 12-month membership to a digital privacy and identity protection service to compensate them for having their personal and health data disclosed to third parties such as Meta and Google. The settlement resolves all claims in the lawsuit, Jane Doe v. SSM Health Care Corporation, d/b/a SSM Health, which was filed in the Circuit Court for the City of St. Louis in the State of Missouri on December 5, 2022. The lawsuit alleged that SSM Health added Meta Pixel and other third-party tracking technologies on its MyChart patient portal, which collected and transmitted protected health information to third-party tracking vendors, including their status as patients, their physicians, health conditions, treatments, facilities visited, and other sensitive data, without their knowledge or consent. Tracking tools are used extensively across the internet and track user activity on websites. The data collected by these tools can be used for advertising and marketing...



