Sen. Wyden Urges FTC to Take Action Against Microsoft for “Gross Cybersecurity Negligence”
Senator Ron Wyden (D-OR) has written to Andrew Ferguson, Chair of the Federal Trade Commission (FTC), requesting the FTC investigate Microsoft and hold it responsible for “gross cybersecurity negligence,” which Sen. Wyden believes has contributed to the barrage of ransomware attacks on critical infrastructure entities. In the letter, Sen. Wyden cites figures from a February 2025 report published by the Director of National Intelligence (DNI) indicating more than 5,000 ransomware attacks in 2024, a 15% increase from 2024, and a 103% increase from 2022. Around half of the victims of those attacks are located in the United States. Those attacks have caused enormous harm to healthcare providers, put patient care at risk, and pose a continuing threat to national security. Sen. Wyden believes Microsoft is at fault for many of these attacks because of its de facto monopoly on operating systems, combined with dangerous software engineering decisions that have made the Windows operating system vulnerable to ransomware attacks. Sen. Wyden explained that Microsoft chooses the...
$13.75M Settlement Agreed to Resolve WebTPA Class Action Data Breach Litigation
WebTPA Employer Services (WebTPA) and the co-defendants in a consolidated class action lawsuit have agreed to a $13,750,000 settlement to resolve claims relating to an April 2024 cyberattack and data breach. WebTPA is a third-party administrator that provides custom health plans for self-funded employer groups, hospital health plans, and administrative outsourcing services. On April 23, 2023, WebTPA identified suspicious network activity, and the investigation confirmed unauthorized access to its network between April 18, 2023, and April 23, 2023, and potentially exfiltrated sensitive data. The data breach was communicated to its customers on or around March 25, 2024, and individual notification letters were mailed to the affected individuals starting on May 8, 2024, and the HHS’ Office for Civil Rights was informed that the protected health information of 2,518,533 individuals had been exposed and potentially compromised in the incident. WebTPA was named in 13 putative class action lawsuits over the data breach, along with other defendants. Since the lawsuits had overlapping...
HIPAA Training for Organizations
HIPAA training for organisations is the structured process of educating the workforce on how to protect patient information, follow internal policies, meet HIPAA obligations, and reduce the risk of breaches, complaints, and enforcement actions. Online training is usually the best delivery method because it is consistent, scalable, easy to assign by role, and simple to document for audits. Why Organisations Need a Formal HIPAA Training Program A HIPAA training program turns rules into daily habits that staff can apply when handling patient data, speaking with patients and families, using systems, and responding to incidents. It also helps leadership set expectations and show that privacy and security are part of professional performance, not optional extras. When training is delivered consistently and tracked properly, it supports accountability across departments and locations. Training should be planned rather than improvised. Organisations need a defined curriculum, clear assignment rules, onboarding processes for new hires, refreshers for existing staff, and a reliable method...
HIPAA Medical Training
HIPAA medical training is the structured training healthcare organizations use to ensure every workforce member understands how to protect patient privacy, handle PHI and ePHI safely, and follow the policies and procedures that support HIPAA compliance in daily work. What HIPAA Medical Training Covers HIPAA medical training should explain the Privacy Rule, the Security Rule, and the Breach Notification Rule in clear, practical language that connects directly to real workflows. Staff should learn what PHI and ePHI are, how minimum necessary applies in common scenarios, and what to do when something goes wrong. Effective training also sets expectations for professionalism, including conversations in public areas, safe use of email and messaging, and avoiding disclosures through photos or social media. Training should also make reporting simple by explaining how to raise a concern, who to contact, and why early reporting protects patients and the organization. Who Must Receive HIPAA Medical Training All staff must receive HIPAA training because any workforce member can encounter PHI...
California Radiology Provider Announces 13,000-Record Data Breach
Data breaches have been reported by Radiology Associates of San Luis Obispo, North Oaks Health System, The Children’s Center of Hamden, Huron Regional Medical Center, and Franklin Dermatology Group. Pacific Imaging Management (Radiology Associates of San Luis Obispo) Pacific Imaging Management, doing business as Radiology Associates of San Luis Obispo in California, has identified unauthorized access to certain employee email accounts. Suspicious activity was identified within its email environment on March 13, 2025. An investigation was launched, which revealed that certain email accounts were accessed by an unauthorized third party at various times between February 3, 2025, and March 17, 2025. The accounts were reviewed and found to contain the protected health information of 13,158 individuals. The types of data involved vary from individual to individual and are detailed in the individual notification letters that started to be mailed on September 10, 2025. Policies and procedures are being reviewed and enhanced, and the affected individuals have been offered...



