Teamsters Union 25 Health Services & Insurance Plan Hacking Incident Affects 19,000 Members
Teamsters Union 25 Health Services & Insurance Plan, a health and wellness benefits plan for members of Teamsters Union Local 25, a trade union representing truck drivers, warehouse workers, clerical workers, and service and technology employees, identified suspicious activity within its computer network on or around August 1, 2025, potentially indicating unauthorized access. Third-party cybersecurity experts were engaged to investigate the activity and confirmed unauthorized access to the network. Further investigation uncovered evidence that certain data, including Protected Health Information, on the network was accessed and potentially copied without authorization. The data related to members of the Teamsters Union 25 Health Services & Insurance Plan and the Teamsters Union 25 Investment Plan. The review of the affected files was completed on August 18, 2025, and notification letters were mailed to the affected individuals on September 3, 2025. The affected individuals have been offered 12-24 months of complimentary credit monitoring and identity theft protection...
R1 RCM & Dignity Health to Pay $675,000 to Settle Data Breach Lawsuit
A $675,000 settlement has been agreed upon to resolve a class action data breach lawsuit against R1 RCM Inc., a revenue cycle management company, and Dignity Health – St. Rose Dominican Hospital, Rosa de Lima Campus in Henderson, Nevada. The lawsuit stems from a data breach at R1 RCM, which was detected on November 23, 2023. R1 RCM determined that the hacker had exfiltrated sensitive data such as names, contact information, dates of birth, Social Security numbers, service locations, diagnosis information, patient account numbers, and medical record numbers. The data breach was reported to the HHS’ Office for Civil Rights as affecting 16,121 individuals. The lawsuit – Heather Hillbom v. R1 RCM, Inc. and Dignity Health dba Dignity Health – St. Rose Dominican Hospital, Rosa de Lima Campus – was filed in the U.S. District Court for the District of Nevada on April 5, 2024, and alleged that the defendants were negligent by failing to implement reasonable and appropriate safeguards to ensure the confidentiality of patient data. The defendants maintain there was no...
HIPAA Training for Medical Secretaries
HIPAA training for medical secretaries helps organizations maintain HIPAA compliance by preparing staff to protect protected health information (PHI) while managing schedules, records, communications, and coordination tasks that routinely involve patient information. Medical secretaries often serve as the operational link between patients, clinicians, and external parties, which means their daily activities can create privacy and security risk if safeguards are not applied consistently. A comprehensive HIPAA training program supports correct handling of PHI across verbal conversations, paper documents, and electronic systems. Handling PHI in Administrative Workflows Medical secretaries encounter PHI in appointment schedules, registration details, insurance information, referral documentation, clinical correspondence, phone messages, faxes, scanned forms, and electronic health record workflows. PHI can also appear in work queues, task lists, shared drives, spreadsheets, and reporting extracts used to manage operations. HIPAA training should reinforce that identifiers combined with...
Adena Health to Pay $1.73 Million to Settle Pixel Lawsuit
Adena Health System, a nonprofit health system serving patients in south central and southern Ohio, has agreed to pay up to $1.73 million to resolve claims that it unlawfully disclosed patient data to third parties via tracking pixels on its MyChart patient portal. Adena Health is one of many health systems to use tools such as Meta Pixel and Google Analytics code to track users on its website; however, these tools were also implemented on its patient portal, which requires users to log in. Whilst on the website and patient portal, users’ data was collected, which may have included personally identifiable information (PII) and protected health information (PHI). That information was automatically sent to companies such as Meta and Google. A lawsuit was filed over the disclosures, which were alleged to have occurred without the knowledge or consent of the data subjects. Users of the patient portal could book appointments, research medical conditions, learn about treatment options, and communicate with their providers. The lawsuit alleged that health conditions, preferred treatment...
Feds Offer $10 Million Reward for Ransomware Administrator Who Attacked U.S. Healthcare Orgs
The U.S. Department of Justice has charged a Ukrainian serial ransomware criminal who is alleged to have been the administrator of multiple ransomware operations. Volodymyr Viktorovich Tymoshchuk, through online monikers including deadforz, Boba, msfv, and farnetwork, is alleged to have been the administrator of the LockerGaga, MegaCortex, and Nefilim ransomware operations between December 2018 and October 2021. Tymoshchuk, along with his accomplices, conducted or played a key role in ransomware attacks on more than 250 victims in the United States between July 2019 and June 2020 using the LockerGaga and MegaCortex ransomware variants, as well as hundreds of victims worldwide. An international law enforcement operation targeting the LockerGoga and MegaCortex ransomware schemes in September 2022 obtained decryption keys, which were made available to victims via the No More Ransom Project. Many potential victims were able to prevent file encryption after receiving prompt notifications from law enforcement that their networks had been compromised. Under the Nefilim ransomware scheme,...



