July 2025 Healthcare Data Breach Report
U.S. healthcare data breaches are down 34.1% month-over-month, and 44.5% fewer individuals had their healthcare data exposed. HIPAA-regulated entities reported 48 data breaches affecting 500 or more individuals in July, 12 fewer than the monthly average over the past 12 months. July saw the lowest number of reported healthcare data breaches since September 2024, although the monthly total is likely to increase as there is often a delay between an entity reporting a data breach to the HHS’ Office for Civil Rights (OCR) and it being added to the OCR breach portal. For instance, in August 2024, when we compiled the July 2024 healthcare data breach report, there were 43 data breaches, with the total increasing to 49 over the next few months. July’s total is therefore likely to be slightly higher than July 2024, and data breaches are up slightly year-over-year. When we compiled our July 2024 data breach report on July 20, 2024, 435 data breaches affecting 500 or more individuals had been reported to OCR. This year’s total for January 1, 2025, to July 31, 2025, stands at 444 data...
HIPAA Compliance for Organ Procurement and Transplant Coordination Companies
HIPAA compliance for organ procurement and transplant coordination companies means protecting PHI during urgent, multi organization coordination work that involves rapid communication, mobile operations, and strict timelines, while meeting HIPAA Business Associate obligations and maintaining reliable documentation across the full workflow. Why HIPAA Compliance Is High Stakes in Organ Procurement and Coordination Organ procurement and transplant coordination often involve hospitals, labs, transplant centers, transport providers, and on call staff exchanging sensitive information quickly. PHI may move through calls, messages, shared systems, documents, and mobile devices in time critical scenarios. HIPAA compliance requires clear rules for permitted disclosures, minimum necessary sharing, secure communication, and rapid incident escalation when something goes wrong. HIPAA Training for Business Associates Our training includes specific lessons covering the unique HIPAA-challenges faced by staff at Business Associates. View Training The Gold Standard in HIPAA Training by The HIPAA...
DaVita Confirms 2.7 Million Individuals Affected by Ransomware Attack
DaVita, a Denver, CO-based kidney dialysis service provider, has submitted a breach report to the HHS’ Office for Civil Rights confirming the number of individuals affected by its April 12, 2025, ransomware attack. Hackers gained access to its network, exfiltrated sensitive data, and then encrypted files on parts of its network. While the attack caused some temporary operational disruption, DaVita said the critical care it provides to patients continued uninterrupted. DaVita previously confirmed that the ransomware group gained access to a laboratory database containing patient information. The database and other affected parts of the network have been reviewed, and DaVita has now confirmed that the protected health information of 2,689,826 individuals was compromised in the incident. That makes it the third-largest healthcare data breach announced so far this year, behind the cyberattack on Episource that affected 5.5 million individuals, and the website tracking data breach at Blue Shield of California that affected 4.7 million individuals. Notification letters are...
New Texas Law Gives Physicians 3 Days to Communicate Sensitive Test Results to Patients
Texas Governor Greg Abbott has signed a bill into law that provides physicians in the state with a 3-day window to review sensitive medical test results and communicate the findings to patients before they are notified electronically, and the test result is added to their electronic medical record. Senate Bill 922, titled Relating to the disclosure of certain medical information by electronic means, was introduced by Sen. Kelly Hancock (R-North Richland Hills) and Rep. Caroline Fairly (R-Amarillo) in response to calls from physicians in the state to give them time to review sensitive test results and communicate that information to patients. The bill was in response to a provision of the 21st Century Cures Act that required the immediate release of health information to patients’ information portals. Since the spring of 2021, test results have been sent to patients’ information portals immediately. While rapid access to health information has its benefits, there have been many cases where patients have received a cancer diagnosis via their smartphone rather than have the results...
Mount Sinai Health System Settles Web Tracking Lawsuit for $5.3 Million
Mount Sinai Health System, the largest hospital network in New York City, has agreed to a $5.3 million settlement to resolve allegations it violated federal and state laws by sharing the personal health information of website and patient portal users with Facebook without their knowledge or consent. Legal action was taken against Mount Sinai Health over its use of the Facebook Pixel and Conversions Application Programming Interface (CAPI) on its website and MyChart patient portal between October 2020 and October 2023. The tool can collect information about website users and transmit that information to Facebook. Mount Sinai Health has denied any wrongdoing and specifically denies that any medical information from either its website or patient portal was shared with Facebook. The lawsuit – Cooper, et al., v. Mount Sinai Health System, Inc. – was filed in the United States District Court for the Southern District of New York by plaintiffs Ronda Cooper, Coral Fraser, David Gitlin, and Gilbert Manda, who alleged that their personally identifiable health information was being...



