VITAS Hospice Services Discovers Month-Long Network Intrusion Affecting 319K Patients
VITAS Hospice Services, LLC, the largest for-profit hospice chain in the United States, has notified the California and Texas attorneys general about a data security incident that exposed sensitive patient data. An unauthorized individual compromised an account used by one of its vendors, and through that account was able to access certain Vitas systems. The security breach was identified on October 24, 2025, and the forensic investigation determined that there was unauthorized access to its systems for more than a month between September 21, 2025, and October 27, 2025. During that time, the unauthorized third party was able to view and download the personal information of current and former Vitas patients. Vitas has been working with a third-party cybersecurity firm to investigate the cause of the breach and has taken steps to strengthen vendor oversight and improve its data protection protocols. At the time of issuing notifications to the affected individuals, Vitas was unaware of any misuse of the exposed data; however, as a precaution against identity theft and fraud, the...
Trinity Health; Precision Imaging Centers Settle Class Action Data Breach Lawsuits
Trinity Health in Michigan and Precision Imaging Centers in Florida have agreed to settle class action lawsuits that alleged negligence and violations of state laws in related to breaches of patients’ electronic protected health information. Trinity Health Settles Litigation Stemming from Accellion FTA Data Breach The Livonia, Michigan-based Catholic Health System, Trinity Health Corporation, and co-defendants Valley Surgical Specialists Medical Group, Inc., Daniel Evan Swartz, MD, and Rame Deme Iberdemaj, have agreed to settle class action litigation stemming from a 2021 data breach involving its secure file transfer platform, Accellion FTA. On or around January 29, 2021, Accellion notified Trinity Health that hackers had gained access to the Accellion FTA by exploiting a zero-day vulnerability. Trinity Heath used the Accellion FTA for sending secure email, and determined that the files on the Accellion FTA had likely been downloaded by an unauthorized third party. The files contained names, addresses, email addresses, dates of birth, medical record numbers, lab results,...
AccuCare Home Health Services Pays $20,000 Fine for Employing Excluded Individual
The Department of Health and Human Services Office of Inspector General (HHS-OIG) has agreed to a $20,000 settlement with AccuCare Home Health Services to resolve allegations that the home healthcare provider employed an individual on the HHS-OIG exclusions list and billed services provided by that individual to federally funded healthcare programs. AccuCare Home Health Services is a Mesa, Arizona-based provider of home health care services, specializing in skilled nursing, physical therapy, occupational therapy, speech therapy, and medical social services. According to HHS-OIG, AccuCare Home Health Services was discovered to have employed a home healthcare aide who was not permitted to participate in any federally funded healthcare program, and billed products or services provided by that individual to federal health care programs. The alleged violation was settled with a $20,000 financial penalty. Healthcare organizations must ensure that a check is conducted of the HHS-OIG List of Excluded Individuals and Entities (LEIE) prior to onboarding a new employee. Regular checks must...
Bill Introduced to Repeal Proposed OSHA Heat Standard for Indoor and Outdoor Workplaces
Rep. Mark Messmer (R-IN) has introduced a bill that seeks to repeal safety and health legislation introduced by the Biden administration to protect Americans against heat injury and illness in both indoor and outdoor work settings. Rep. Messmer introduced the Health Workforce Standards Act of 2025 on November 20, 2025, to repeal the Occupational Safety and Health Administration’s (OSHA) Heat Injury and Illness Prevention in Outdoor and Indoor Work Settings proposed rule. The bill is co-sponsored by 23 Republican representatives in 16 U.S. states and is supported by more than two dozen industry organizations. OSHA’s proposed standard applies to most employers in the general industry, construction, maritime, and agriculture sectors where OSHA has jurisdiction, and requires them to implement a plan to evaluate and control heat hazards in the workplace and protect their workers from hazardous heat. Rep. Messmer claims that OSHA’s proposed rule would impose impracticable and unnecessary requirements on residential construction employers, noncompliance with which would attract excessive...
Threat Actors Time Attacks to Coincide with Periods of Reduced Vigilance
Thanksgiving weekend is just a few days away, and while many healthcare employees will be enjoying time off work, it will be a particularly busy time for cybercriminals. Many hacking and ransomware attacks occur over Thanksgiving weekend when staffing levels are lower, and fewer eyes are monitoring for indicators of compromise. The high level of ransomware attacks during holiday periods has recently been confirmed by the cybersecurity firm Semperis, which reports that in the United States, 56% of ransomware attacks occur on a weekend or holiday, and 47% of ransomware attacks on healthcare organizations occur during these times when staffing levels are reduced. “Threat actors continue to take advantage of reduced cybersecurity staffing on holidays and weekends to launch ransomware attacks. Vigilance during these times is more critical than ever because the persistence and patience attackers have can lead to long-lasting business disruptions,” said Chris Inglis, the first U.S. National Cyber Director and Semperis Strategic Advisor. The Semperis 2025 Ransomware Holiday Risk Report is...



