Michigan Rural Health System Notifies 140,000 Patients About Hacking Incident
Aspire Rural Health in Michigan is notifying almost 140,000 patients about unauthorized access to its network and the theft of their personal and healthcare data. Aspire Rural Health consists of more than 70 providers and serves patients in rural areas in Huron County, Sanilac County, Tuscola County, and Lapeer County. Aspire detected the intrusion on or around January 6, 2025, and third-party cybersecurity experts were engaged to investigate the incident and determine the nature and scope of the unauthorized activity. The forensic investigation confirmed that an unauthorized third party had access to its network for more than two months from November 4, 2024, to January 6, 2025. According to the substitute data breach notice on the Aspire website, files containing patients’ protected health information were accessed and/or acquired in the incident. Following a manual review of the affected files, Aspire confirmed that a wide range of data types were compromised in the incident. Current and former patients had their first and last names stolen, in combination with one or...
July 2025 Healthcare Data Breach Report
U.S. healthcare data breaches are down 34.1% month-over-month, and 44.5% fewer individuals had their healthcare data exposed. HIPAA-regulated entities reported 48 data breaches affecting 500 or more individuals in July, 12 fewer than the monthly average over the past 12 months. July saw the lowest number of reported healthcare data breaches since September 2024, although the monthly total is likely to increase as there is often a delay between an entity reporting a data breach to the HHS’ Office for Civil Rights (OCR) and it being added to the OCR breach portal. For instance, in August 2024, when we compiled the July 2024 healthcare data breach report, there were 43 data breaches, with the total increasing to 49 over the next few months. July’s total is therefore likely to be slightly higher than July 2024, and data breaches are up slightly year-over-year. When we compiled our July 2024 data breach report on July 20, 2024, 435 data breaches affecting 500 or more individuals had been reported to OCR. This year’s total for January 1, 2025, to July 31, 2025, stands at 444 data...
HIPAA Compliance for Organ Procurement and Transplant Coordination Companies
HIPAA compliance for organ procurement and transplant coordination companies means protecting PHI during urgent, multi organization coordination work that involves rapid communication, mobile operations, and strict timelines, while meeting HIPAA Business Associate obligations and maintaining reliable documentation across the full workflow. Why HIPAA Compliance Is High Stakes in Organ Procurement and Coordination Organ procurement and transplant coordination often involve hospitals, labs, transplant centers, transport providers, and on call staff exchanging sensitive information quickly. PHI may move through calls, messages, shared systems, documents, and mobile devices in time critical scenarios. HIPAA compliance requires clear rules for permitted disclosures, minimum necessary sharing, secure communication, and rapid incident escalation when something goes wrong. HIPAA Training for Business Associates Our training includes specific lessons covering the unique HIPAA-challenges faced by staff at Business Associates. View Training The Gold Standard in HIPAA Training by The HIPAA...
DaVita Confirms 2.7 Million Individuals Affected by Ransomware Attack
DaVita, a Denver, CO-based kidney dialysis service provider, has submitted a breach report to the HHS’ Office for Civil Rights confirming the number of individuals affected by its April 12, 2025, ransomware attack. Hackers gained access to its network, exfiltrated sensitive data, and then encrypted files on parts of its network. While the attack caused some temporary operational disruption, DaVita said the critical care it provides to patients continued uninterrupted. DaVita previously confirmed that the ransomware group gained access to a laboratory database containing patient information. The database and other affected parts of the network have been reviewed, and DaVita has now confirmed that the protected health information of 2,689,826 individuals was compromised in the incident. That makes it the third-largest healthcare data breach announced so far this year, behind the cyberattack on Episource that affected 5.5 million individuals, and the website tracking data breach at Blue Shield of California that affected 4.7 million individuals. Notification letters are...
New Texas Law Gives Physicians 3 Days to Communicate Sensitive Test Results to Patients
Texas Governor Greg Abbott has signed a bill into law that provides physicians in the state with a 3-day window to review sensitive medical test results and communicate the findings to patients before they are notified electronically, and the test result is added to their electronic medical record. Senate Bill 922, titled Relating to the disclosure of certain medical information by electronic means, was introduced by Sen. Kelly Hancock (R-North Richland Hills) and Rep. Caroline Fairly (R-Amarillo) in response to calls from physicians in the state to give them time to review sensitive test results and communicate that information to patients. The bill was in response to a provision of the 21st Century Cures Act that required the immediate release of health information to patients’ information portals. Since the spring of 2021, test results have been sent to patients’ information portals immediately. While rapid access to health information has its benefits, there have been many cases where patients have received a cancer diagnosis via their smartphone rather than have the results...



