Nebraska AG’s Lawsuit Against Change Healthcare Survives Motion to Dismiss
A lawsuit filed by Nebraska Attorney General Mike Hilgers over the 2024 Change Healthcare data breach has been allowed to proceed after surviving a motion to dismiss. The lawsuit was filed in Lancaster County District Court in December 2024, naming Change Healthcare, UnitedHealth Group, and Optum as defendants. The lawsuit alleged the defendants violated Nebraska’s consumer protection, data privacy, and security laws. The complaint was filed in the wake of the catastrophic ransomware attack and data breach that affected more than 190 million Americans, including almost 900,000 Nebraskans. The outage following the ransomware attack caused critical payment and claims processing systems to be halted for around two months, resulting in considerable financial hardship for the healthcare providers that relied on Change Healthcare’s clearinghouse services and delaying essential healthcare services for state residents. The lawsuit alleged that the ransomware attack occurred as a result of Change Healthcare’s failure to implement reasonable and appropriate cybersecurity measures and follow...
Data Breaches Announced by Sun Valley Surgery Center & American Associated Pharmacies
Data breaches have recently been identified by Sun Valley Surgery Center in Nevada and American Associated Pharmacies in Alabama. Sun Valley Surgery Center Sun Valley Surgery Center in North Las Vegas, Nevada, has identified unauthorized access to its computer network. Anomalous activity was identified within its information systems on September 3, 2025. The forensic investigation confirmed that an unauthorized third party accessed parts of its network where sensitive patient information was stored. Data potentially compromised in the incident included names, contact information, dates of birth, Social Security numbers, driver’s license/state-issued identification numbers, passport/other government identification numbers, and health information such as health histories, diagnosis/treatment information, explanation of benefits, health insurance information, and/or MRN numbers/patient identification numbers. Sun Valley Surgery Center has implemented additional safeguards and technical security measures to prevent similar incidents in the future. According to the HHS’ Office for...
EHR Vendor Identifies Business Associate Data Breach
Data breaches have recently been announced by the EHR vendor CareTracker (Amazing Charts) and the Wisconsin health system, Marshfield Clinic. CareTracker (Amazing Charts) CareTracker Inc., doing business as Amazing Charts, an electronic health record and practice management platform provider, has been affected by a security incident at one of its vendors. On June 19, 2025, Amazing Charts identified unusual activity within a system managed by a third-party vendor. Immediate action was taken to secure the vendor’s environment, and an investigation was launched to determine the nature and scope of the activity. The investigation confirmed unauthorized access to the service provider’s network between June 15, 2025, and June 19, 2025. Files were then reviewed to determine the individuals affected and the types of data involved. Due to the complexity of the data review, that process has only recently been completed. Data potentially compromised in the incident included names in combination with one or more of the following: diagnoses, treatment information, physician names, medical...
Doctor Alliance Investigating 353 GB Data Theft Claim
Dallas, TX-based Doctor Alliance, a HIPAA business associate that provides document management and billing services to HIPAA-covered entities, is investigating a claim that a hacker exfiltrated 353 GB of data in a November cyberattack. On or around November 7, 2025, a hacker using the moniker Kazu, added a post to an underground hacking forum claiming to have stolen 1.24 million files from Doctor Alliance. The hacker has demanded a $200,000 ransom, payment of which is required to ensure that the stolen data is deleted. The hacker has threatened to sell the data if the ransom is not paid. A 200 MB sample was added to the listing that was analyzed and found to contain what appears to be patient names, addresses, phone numbers, email addresses, medical record numbers, Medicare numbers, diagnoses, treatment information, medications, and provider information. According to the leak site, Doctor Alliance has until November 21, 2025, to pay the ransom. While the sample appears to include patient data, it has yet to be confirmed whether the data came from Doctor Alliance. It is possible...
What is the Best EMR for Small Practices in 2026?
Whether you are starting a new practice or looking to grow your existing business, choosing the right electronic medical record system (EMR) is key to improving revenues and profits. An EMR is more than a system for managing large data records. An EMR is an invaluable tool at the heart of your practice that facilitates many aspects of your practice’s operations, such as scheduling, payments, insurance billing, record requests, patient engagement, telehealth, patient follow-ups, and HIPAA compliance. In addition to ensuring accurate patient records, an EMR is an invaluable tool for aiding decision-making, improving efficiency by streamlining documentation, and eliminating manual administrative tasks that inevitably impact revenue-generating activities and patient care. An EMR can significantly improve the patient experience by streamlining scheduling, providing patients with easy access to their health data to improve engagement, and facilitating communication, helping to improve satisfaction and attract new patients. With an EMR that is the right fit for your practice, you can...



