August 2025 Healthcare Data Breach Report
There has been a 13.7% month-over-month increase in large healthcare data breaches, with 58 breaches affecting 500 or more individuals reported to the HHS’ Office for Civil Rights in August, slightly lower than the 2025 average of 63.5 large healthcare data breaches per month. Since 2009, the number of reported healthcare data breaches has generally increased each year, although there was a slight reduction in data breaches last year (746 in 2023 vs. 739 in 2024), and that trend appears to be continuing this year. HIPAA-regulated entities have reported 508 large healthcare data breaches in the year to August 31, 2025, compared to 515 large healthcare data breaches over the corresponding period in 2024. For the second consecutive month, the number of individuals affected by healthcare data breaches has fallen. Across the 58 data breaches, the protected health information of 3,789,869 individuals was exposed or impermissibly accessed/disclosed. On average, 5,084,784 individuals have been affected by healthcare data breaches each month this year (median 3,583,200 individuals). The...
HIPAA Training for Individuals
IPAA training for individuals is a practical way to learn how to protect patient information, understand legal responsibilities, and demonstrate knowledge of HIPAA requirements even when training is not provided directly by an employer. What HIPAA Training for Individuals Covers Individual HIPAA training is designed for people who handle or may handle protected health information as part of their work, education, or career development. This includes healthcare professionals, administrative staff, students, contractors, consultants, and anyone preparing for a role in a HIPAA regulated environment. Online training is strongly recommended for individuals because it allows self paced learning, flexible scheduling, and immediate access to completion certificates. Online courses also make it easier to refresh knowledge annually, which aligns with industry best practice. HIPAA Training Course Content A well designed HIPAA training course for individuals focuses on real world understanding rather than legal theory alone. Core topics explain what protected health information is, why it must...
How Often Do You Need HIPAA Training?
The best practice in the healthcare sector is to have HIPAA training at least annually. How often you need HIPAA training can depend on how often there is a material change to HIPAA policies and procedures, how often a risk assessment identifies a need for further training, how often HIPAA training is enforced as a sanction for a HIPAA violation, and how often training is a requirement of a corrective action plan. The frequency of HIPAA training can be subject to a number of factors. These include the frequency of changes to the Privacy Rule, workforce members’ roles and functions, identified risks to the privacy of Protected Health Information (PHI), violations of HIPAA in the workplace, and corrective actions following a breach notification to HHS’ Office for Civil Rights. In addition, covered entities and business associates are required by the Security Rule to implement a security and awareness training program. The frequency of HIPAA security and awareness training is set by each covered entity or business associate. However, the inclusion of the word “program” in...
Microsoft Seizes Sites Used by Popular Phishing Operation to Attack Healthcare Orgs
Microsoft has announced the seizure of hundreds of websites used by a popular phishing-as-a-service (PhaaS) operation that targets Microsoft 365 credentials. The operation’s phishing kits have been used to steal at least 5,000 usernames and passwords, including the Microsoft 365 credentials of at least 20 U.S. healthcare organizations. According to the Microsoft Digital Crimes Unit (DCU), RaccoonO365 is the fastest-growing tool used by cybercriminals to steal Microsoft 365 usernames and passwords. The PhaaS operation provides subscription-based phishing kits, which generate phishing emails mimicking official communications from Microsoft. The emails direct victims to websites that trick victims into disclosing their Microsoft 365 credentials. The phishing kits lower the barrier to conducting phishing campaigns and can be used by even low-skilled individuals to steal credentials. RaccoonO365 has been offering phishing kits to cybercriminals since at least July 2024. Subscribers are able to use the infrastructure to send up to 9,000 phishing emails per day. A 30-day...
Columbia University Health Care to Pay $600,000 to Settle Data Breach Lawsuit
Columbia University Health Care (CUHC) has agreed to pay $600,000 to settle a class action lawsuit over a cybersecurity incident that affected 29,629 current or former patients. The data breach in question occurred between September 11, 2023, and March 7, 2024, when cybercriminals had access to an Internet-accessible platform used by Columbia University Irving Medical Center, the academic medical center of Columbia University, and the largest campus of New York-Presbyterian Hospital. Columbia University and New York-Presbyterian participate in an Organized Health Care Arrangement. The hackers were able to access sensitive healthcare information, including names, medical record numbers, dates of birth, provider names, and a single laboratory test result. Notification letters were mailed to the affected individuals in May 2024. In July 2024, a lawsuit was filed against New York-Presbyterian Columbia University Irving Medical Center by Juanita Huggins, and a second lawsuit was filed in October 2024 by Margaret Nemeth. The defendant, New York-Presbyterian Hospital, was dismissed, and...



