HIPAA Compliance Challenges for Small Medical Practices
All healthcare providers are required to comply with the HIPAA Rules, but there are unique challenges for small medical practices. Large healthcare organizations have greater resources to devote to compliance, and can attract and pay for dedicated compliance professionals, in-house IT and cybersecurity staff, cutting-edge cybersecurity solutions, and staff training programs. Small medical practices typically have limited resources and are forced to make difficult decisions about where to allocate funds due to budget constraints. Investments in the business that boost revenue and profits often take priority over HIPAA compliance and cybersecurity improvements. Small practices often cannot afford to have a dedicated HIPAA Privacy and Security Officer, and compliance duties fall on staff members with many other responsibilities. There may also not be an in-house IT department to oversee security and ensure the information security program is fully compliant with the HIPAA Security Rule. Despite financial constraints, HIPAA compliance and cybersecurity are not optional. The HHS’ Office...
Senators Demand Answers from UnitedHealth After Second Massive Data Breach in a Year
Two U.S. senators have written to UnitedHealth Group (UHG) CEO Stephen J. Hemsley demanding answers about cybersecurity and the response to the massive data breach at its subsidiary, Episource, which exposed the personal and protected health information of 5.4 million individuals earlier this year. Episource, which was acquired by UHG-owned Optum in 2023, provides medical coding and risk adjustment services to physicians, health plans, and other healthcare companies. In June 2025, the company announced a hacking incident that involved unauthorized access to its network between January 27, 2025, and February 6, 2025. The hackers stole sensitive information such as names, dates of birth, Social Security numbers, health information, health insurance information, and Medicare/Medicaid numbers. The hacking incident at Episource occurred within a year of a ransomware attack on another UHG subsidiary, Change Healthcare, which resulted in the largest healthcare data breach in U.S. history. Change Healthcare has recently confirmed that 192.7 million individuals were affected and had their...
HIPAA Training for Medical Laboratory Technicians
HIPAA training for medical laboratory technicians supports HIPAA compliance by preparing laboratory personnel to protect protected health information (PHI) while collecting, labeling, testing, reporting, and transmitting laboratory data that can identify a patient and reveal health conditions. Why Laboratory Workflows Create Unique HIPAA Risks Laboratory environments move fast and rely on precision, which means privacy and security issues often arise from routine operational steps rather than intentional behavior. PHI can appear on specimen labels, requisitions, analyzer printouts, pending worklists, quality review reminders, courier logs, instrument interface messages, and laboratory information system screens. Results reporting can involve internal messaging, faxes, portals, and calls to clinical units, and each handoff creates an opportunity for misdirection, over-disclosure, or unauthorized viewing if safeguards are not followed. Laboratory staff also work with information that can be especially sensitive, such as infectious disease testing, toxicology, pregnancy testing,...
Alera Group Notifies 155K Individuals About July 2024 Hacking Incident
Alera Group has notified more than 155,000 individuals about a July 2024 hacking incident. Data breaches have also been announced by The Good Samaritan Health Center of Cobb and Western Montana Clinic. Alera Group Notifies Individuals About July 2024 Hacking Incident Alera Group, Inc., a provider of risk management, insurance, and financial services, has notified 155,567 individuals about the potential theft of some of their protected health information. The incident was first announced on May 21, 2025, and has recently been reported to the HHS’ Office for Civil Rights. Suspicious network activity was detected in August 2024, and the forensic investigation confirmed unauthorized access to its network between July 19, 2024, and August 4, 2024. During that time, sensitive data may have been copied. A file review was initiated to determine the types of data involved and the individuals affected, and that process was completed on April 28, 2025. Alera Group has confirmed that the data related to employees and certain clients, business partners, and providers. That information included...
Hacking Incidents Announced by Two Texas Health Clinics
A drug and alcohol addiction center and an OB/GYN Medical Center in Texas have notified patients about unauthorized access to some of their protected health information. Nova Recovery Center Reports Unauthorized Network Access Nova Recovery LLC (Nova Recovery Center), a drug and alcohol addiction center in Wimberley, Texas, has identified unauthorized access to certain systems hosted on the Nova Recovery network. The intrusion was identified by its IT and Security teams on May 25, 2025. The threat was neutralized, and the breach was investigated to determine if any patient data had been exposed. On June 17, 2025, Nova Recovery confirmed that business records on its network had been accessed, some of which contained patients’ personal information. Data compromised in the incident includes first, middle, and last names, addresses, dates of birth, Social Security numbers, and financial payment information. Individual notification letters have been mailed to the 7,713 affected individuals, and complimentary credit monitoring services have been offered. The third-party consulting firm...



