Florida Eye Care Provider Data Breach Affects 153,000 Patients
Retina Group of Florida is the latest eye care provider to report a breach of patient data. The protected health information of almost 153,000 patients was potentially compromised in a November 2024 hacking incident. Retina Group of Florida is a multi-physician, 22-office ophthalmology practice specializing in diseases of the retina. On November 9, 2024, suspicious activity indicative of an intrusion was identified in a portion of its computer network. Immediate action was taken to secure its network and contain the potential threat, and an investigation was launched to determine the nature and scope of the activity. The investigation confirmed unauthorized network access to parts of its network starting on November 6, 2024. Over the four-day intrusion, patient data may have been copied from the network. The review of all exposed files was completed on August 18, 2025, and over the next month, contact information was verified to allow notification letters to be sent. The notification process started on September 16, 2025, and the affected individuals have been offered credit...
23andMe Requests Bankruptcy Judge Approve Revised $50 Million Data Breach Settlement
23andMe has proposed an increased settlement fund to resolve U.S. litigation over its 2023 data breach, adding a further $20 million to the $30 million settlement proposed last year. The $30 million settlement was given preliminary approval by a federal court judge in December. The data breach began in April 2023 and involved unauthorized access to customer accounts for around 5 months as a result of a credential stuffing attack. Approximately 7 million customers were affected, 6.4 million of whom were located in the United States. Customer accounts were compromised because they used the same password as other platforms that had previously been breached. While credential stuffing attacks exploit poor password practices by users of a platform, 23andMe was criticized for having inadequate security, such as not requiring multi-factor authentication to protect accounts. The $30 million settlement was agreed upon and received preliminary approval before 23andMe’s bankruptcy. The company filed for Chapter 11 bankruptcy protection in March 2025 to maximize value through a court-supervised...
GAO: HHS Yet to Implement 82 Cybersecurity and IT Management Recommendations
The U.S. Government Accountability Office has written to Clark Minor, Chief Information Officer (CIO) of the U.S. Department of Health and Human Services, advising him about the current open cybersecurity and IT management recommendations that require his attention. GAO is a non-partisan agency that works for Congress and provides support to ensure it meets its constitutional responsibilities and helps improve the performance and ensure the accountability of the federal government. GAO makes recommendations for improving the government’s performance in IT and related IT management functions, including recommendations for the HHS, yet many of those recommendations have yet to be implemented. In the letter, GAO explained that the HHS currently has 82 open recommendations involving high-risk cybersecurity and IT management issues. GAO made the recommendations over several years, each relating to a GAO High-Risk area: Ensuring the Cybersecurity of the Nation or Improving IT Acquisitions and Management. Out of the 82 recommendations, at least 37 are considered sensitive, and one has...
Alphabet’s Verily Sued by Former Executive Over Alleged HIPAA Breaches
A lawsuit has been filed against Alphabet-owned Verily by a former employee who alleges that the personally identifiable health information of more than 25,000 patients was misused, and the company failed to report the HIPAA breaches, as required by the Health Insurance Portability and Accountability Act (HIPAA). Verily, formerly Google Life Sciences, is a research organization owned by Google’s parent company, Alphabet. The Verily platform drives AI-powered precision health solutions that help pharmaceutical firms bring new therapies to market sooner and health systems and payers improve patient outcomes at a lower cost. The lawsuit alleges that an internal investigation confirmed HIPAA breaches involving HIPAA-protected data obtained from 14 HIPAA-regulated entities. The lawsuit claims patient data was used without authorization, in violation of the HIPAA Privacy Rule. Further, while the investigation uncovered misuses of patient data, Verily failed to disclose the breach, delaying notifications while contract renewals were negotiated with the affected covered entities, in...
Sen. Wyden Urges FTC to Take Action Against Microsoft for “Gross Cybersecurity Negligence”
Senator Ron Wyden (D-OR) has written to Andrew Ferguson, Chair of the Federal Trade Commission (FTC), requesting the FTC investigate Microsoft and hold it responsible for “gross cybersecurity negligence,” which Sen. Wyden believes has contributed to the barrage of ransomware attacks on critical infrastructure entities. In the letter, Sen. Wyden cites figures from a February 2025 report published by the Director of National Intelligence (DNI) indicating more than 5,000 ransomware attacks in 2024, a 15% increase from 2024, and a 103% increase from 2022. Around half of the victims of those attacks are located in the United States. Those attacks have caused enormous harm to healthcare providers, put patient care at risk, and pose a continuing threat to national security. Sen. Wyden believes Microsoft is at fault for many of these attacks because of its de facto monopoly on operating systems, combined with dangerous software engineering decisions that have made the Windows operating system vulnerable to ransomware attacks. Sen. Wyden explained that Microsoft chooses the...



