HHS-OIG Imposes Penalties on Skilled Nursing Facilities for Employing Excluded Individuals
The U.S. Department of Health and Human Services Office of Inspector General (HHS-OIG) has recently announced enforcement actions against entities alleged to have employed excluded individuals who provided items or services that were billed to federal healthcare programs. On May 29, 2025, HHS-OIG announced a $1,565,374.11 settlement agreement with 19 skilled nursing facilities to resolve allegations that they knew or should have known that they employed individuals who were excluded from federal healthcare programs. Sundance Creek Post Acute, California Escondido Post Acute, California Jurupa Hills Post Acute, California Crystal Cove Care Center, California Redwood Cove Healthcare Center, California Huntington Valley Healthcare Center, California Houston Transitional Care, Texas Napa Post Acute, California Norwood Towers Post Acute, Ohio Sunnyvale Post Acute Center, California Stoney Point Healthcare, California Trellis Centennial, Nevada San Diego Post Acute, California Mirage Post Acute, California Crystal Ridge Care Center, California Aviara Healthcare, California Concord Post...
Cumberland County Hospital Data Breach Affects Almost 37,000 Individuals
While compiling data for last month’s data breach report, the HIPAA Journal identified a data breach that had previously been missed. On June 2, 2025, Cumberland County Hospital Association in Kentucky notified the HHS’ Office for Civil Rights about a hacking-related data breach that affected 36,659 individuals. Cumberland County Hospital detected the hacking incident on April 3, 2025. According to its substitute breach notice, an unauthorized third party had access to its network between February 21, 2025, and April 3, 2025. While its electronic medical record system was not accessed, files on the compromised parts of the network were discovered to include patient information, and some of those files were accessed during the attack. The review of the files confirmed they contained demographic information (name, date of birth, address, phone number(s), email address, race, and ethnicity), along with Social Security numbers, medications, diagnoses, treatment notes, dates of service, medical record numbers, health plan numbers, and claims and billing information. Some employee...
New York Surgery Center Pays $250K to Settle HIPAA Risk Analysis; Breach Notification Violations
Department of Health and Human Services (HHS) Office for Civil Rights (OCR) Director, Paula M. Stannard, has announced OCR’s 18th HIPAA penalty of the year. Syracuse ASC, which does business as Specialty Surgery Center of Central New York, a single-facility ambulatory surgery center in Liverpool, New York, has agreed to settle alleged violations of the HIPAA Security Rule and HIPAA Breach Notification Rule and will pay a $250,000 financial penalty. OCR launched an investigation of Syracuse ASC after receiving a data breach notification report on October 14, 2021, about a hacking incident involving unauthorized access to the protected health information of 24,891 current and former patients. A threat actor had access to its network from March 14, 2021, through March 31, 2021, and potentially obtained names, dates of birth, Social Security numbers, financial information, and clinical treatment information. OCR investigation confirmed that this was a ransomware attack involving PYSA ransomware. OCR’s investigation uncovered no evidence to suggest that Syracuse ASC had ever conducted...
Naper Grove Vision Care Falls Victim to Interlock Ransomware Attack
Naper Grove Vision Care in Naperville, Illinois, has recently announced a cybersecurity incident that was detected on May 24, 2025. Independent cybersecurity experts were engaged to investigate unusual network activity and confirmed that an unauthorized third party accessed its network and exfiltrated files containing patient information. The file review revealed the stolen files contained names, addresses, birth dates, driver’s license numbers, patient numbers, health insurance information, explanation of benefits documents, and medical condition and treatment information. A limited number of patients also had their Social Security numbers stolen. Naper Grove Vision Care has advised the affected patients to monitor their account statements and credit reports closely and report any suspicious activity to law enforcement. There is no mention of complimentary credit monitoring services in the substitute data breach notice. The data breach has been reported to the HHS’ Office for Civil Rights using an interim figure of 501 affected individuals. While ransomware was not mentioned in...
Business Associate Data Breach Affects Duke Regional Hospital Patients
A law firm that provides legal counsel and assistance to Durham County Hospital Corporation in North Carolina has experienced a data breach involving the personal and protected health information of 2,150 individuals. Manning, Fulton & Skinner, P.A. (MFS), identified suspicious activity within its email system on February 6, 2025. An investigation was launched to determine the cause of the activity, and it was confirmed that certain MFS email accounts had been accessed by an unauthorized individual between September 19, 2024, and February 6, 2025. Third-party data review specialists were engaged to review the affected accounts and completed the review on May 14, 2025. Durham County Hospital Corporation was notified about the data breach on May 29, 2025, and provided MFS with the necessary information for mailing notifications on July 14, 2025. The law firm has implemented additional email security measures and has offered the affected individuals 12 months of complimentary credit monitoring and identity theft protection services. The Brien Center for Mental Health and Substance...



