OCR Reminds Regulated Entities of Obligation to Provide Parental Access to Children’s Medical Records
The Department of Health and Human Services (HHS) Office for Civil Rights (OCR) has issued a “Dear Colleague” letter reminding HIPAA-regulated entities of their obligations under the HIPAA Privacy Rule to provide parents with full access to their minor children’s medical records. OCR said it has become aware that there may be instances where the parents of minor children have been denied access to their children’s medical records to the extent required by the HIPAA Privacy Rule. The HIPAA Privacy Rule gives patients rights with respect to their protected health information (PHI). Individuals, or their personal representatives, must be provided with a copy of their medical records and other PHI in a designated record set on request. The same right usually applies to the parents or legal guardians of minor children. “If under applicable law a parent, guardian, or other person acting in loco parentis has authority to act on behalf of an individual who is an unemancipated minor in making decisions related to health care, a covered entity must treat such person as a personal...
Behavioral Health Resources Pays $1.1 Million to Settle Data Breach Lawsuit
Behavioral Health Resources, a behavioral and mental health services provider serving patients in Thurston County, Olympia, in Washington state, has agreed to settle a consolidated class action lawsuit stemming from a data incident identified on November 20, 2024. The forensic investigation confirmed unauthorized access to its technology systems, resulting in the exposure and potential theft of the personal and protected health information of 50,083 current and former patients. The affected individuals were notified about the incident in January 2025. Several class action lawsuits were filed in response to the data breach, the first of which was filed by plaintiff Carol Walker in the Superior Court of Thurston County, Washington. Separate class action complaints were subsequently filed by plaintiffs Rebecca A. Campos, Adam Shotswell, Smukweshun Okena, and Kim Ridgway. The lawsuits were consolidated into a single complaint – Walker et al. v. Behavioral Health Resources. The plaintiffs allege that Behavioral Health Resources failed to implement reasonable and appropriate...
HIPAA Compliance for Hospitals
There is no one-size-fits-all approach HIPAA compliance for hospitals because of the many different types of hospitals, the different types of challenges, and the different types of laws other than HIPAA hospitals have to comply with depending on the nature of their activities. However, HIPAA compliance checklists that account for existing compliance efforts can help hospitals cover the basics of HIPAA compliance. With regards to accounting for existing compliance efforts, most hospitals already comply with HIPAA to some degree due to the measures implemented in order to participate in Medicare. For example, most Medicare-participating hospitals already have: A Notice of Rights which includes the hospital’s grievance procedures Procedures to respond to patients’ requests to access medical records Measures in place to ensure the confidentiality of patient records A system that maintains the availability of records during an emergency Physical safeguards that comply with the Health Care Facilities Code (NFPA 99) To start on the path to HIPAA compliance for hospitals, it...
Kansas City Behavioral Health Center Discloses September 2025 Data Breach
On November 19, 2025, Wyandot Center, a nonprofit community behavioral health center in Kansas City, KS, disclosed a cybersecurity incident that was first detected on or around September 22, 2025. Third-party cybersecurity experts were called in to investigate suspicious network activity and confirmed unauthorized access to its network between September 21 and September 22, 2025. During that time, files containing patients’ protected health information were exposed and may have been accessed or acquired. Over the following six weeks, the exposed files were reviewed. On November 5, 2025, Wyandot Center confirmed that the exposed data included names in combination with one or more of the following: address, date of birth, Social Security number, patient ID, medical record number, health insurance information, service date, diagnosis/condition information, provider name, prescription information, and/or medical history information. Additional security measures have been implemented, and data security policies and procedures are being reviewed. The affected individuals have been...
Patient Data Compromised in Cyberattacks on Sleep Specialists
Two sleep specialists, Persante Health Care in New Jersey and SomnoSleep Consultants in Virginia, have recently disclosed security incidents that exposed patient information. Persante Health Care Patients Informed About January 2025 Cyberattack Persante Health Care, a Mount Laurel Township, NJ-based national provider of sleep and balance center management services to hospitals and physician practices, has announced a security incident that was detected on or around January 28, 2025. Unusual activity was identified within its computer network and, assisted by third-party cybersecurity experts, it was determined that an unauthorized third party accessed its network between January 23 and January 28, 2025. During that time, files containing patient information may have been accessed or acquired. It took more than 8 months to review the affected files to determine whether patient data had been exposed. On October 3, 2025, the data review confirmed that personal and protected health information was involved. The exposed data varied from individual to individual and may have included...



