$13.75M Settlement Agreed to Resolve WebTPA Class Action Data Breach Litigation
WebTPA Employer Services (WebTPA) and the co-defendants in a consolidated class action lawsuit have agreed to a $13,750,000 settlement to resolve claims relating to an April 2024 cyberattack and data breach. WebTPA is a third-party administrator that provides custom health plans for self-funded employer groups, hospital health plans, and administrative outsourcing services. On April 23, 2023, WebTPA identified suspicious network activity, and the investigation confirmed unauthorized access to its network between April 18, 2023, and April 23, 2023, and potentially exfiltrated sensitive data. The data breach was communicated to its customers on or around March 25, 2024, and individual notification letters were mailed to the affected individuals starting on May 8, 2024, and the HHS’ Office for Civil Rights was informed that the protected health information of 2,518,533 individuals had been exposed and potentially compromised in the incident. WebTPA was named in 13 putative class action lawsuits over the data breach, along with other defendants. Since the lawsuits had overlapping...
HIPAA Training for Organizations
HIPAA training for organisations is the structured process of educating the workforce on how to protect patient information, follow internal policies, meet HIPAA obligations, and reduce the risk of breaches, complaints, and enforcement actions. Online training is usually the best delivery method because it is consistent, scalable, easy to assign by role, and simple to document for audits. Why Organisations Need a Formal HIPAA Training Program A HIPAA training program turns rules into daily habits that staff can apply when handling patient data, speaking with patients and families, using systems, and responding to incidents. It also helps leadership set expectations and show that privacy and security are part of professional performance, not optional extras. When training is delivered consistently and tracked properly, it supports accountability across departments and locations. Training should be planned rather than improvised. Organisations need a defined curriculum, clear assignment rules, onboarding processes for new hires, refreshers for existing staff, and a reliable method...
HIPAA Medical Training
HIPAA medical training is the structured training healthcare organizations use to ensure every workforce member understands how to protect patient privacy, handle PHI and ePHI safely, and follow the policies and procedures that support HIPAA compliance in daily work. What HIPAA Medical Training Covers HIPAA medical training should explain the Privacy Rule, the Security Rule, and the Breach Notification Rule in clear, practical language that connects directly to real workflows. Staff should learn what PHI and ePHI are, how minimum necessary applies in common scenarios, and what to do when something goes wrong. Effective training also sets expectations for professionalism, including conversations in public areas, safe use of email and messaging, and avoiding disclosures through photos or social media. Training should also make reporting simple by explaining how to raise a concern, who to contact, and why early reporting protects patients and the organization. Who Must Receive HIPAA Medical Training All staff must receive HIPAA training because any workforce member can encounter PHI...
California Radiology Provider Announces 13,000-Record Data Breach
Data breaches have been reported by Radiology Associates of San Luis Obispo, North Oaks Health System, The Children’s Center of Hamden, Huron Regional Medical Center, and Franklin Dermatology Group. Pacific Imaging Management (Radiology Associates of San Luis Obispo) Pacific Imaging Management, doing business as Radiology Associates of San Luis Obispo in California, has identified unauthorized access to certain employee email accounts. Suspicious activity was identified within its email environment on March 13, 2025. An investigation was launched, which revealed that certain email accounts were accessed by an unauthorized third party at various times between February 3, 2025, and March 17, 2025. The accounts were reviewed and found to contain the protected health information of 13,158 individuals. The types of data involved vary from individual to individual and are detailed in the individual notification letters that started to be mailed on September 10, 2025. Policies and procedures are being reviewed and enhanced, and the affected individuals have been offered...
Teamsters Union 25 Health Services & Insurance Plan Hacking Incident Affects 19,000 Members
Teamsters Union 25 Health Services & Insurance Plan, a health and wellness benefits plan for members of Teamsters Union Local 25, a trade union representing truck drivers, warehouse workers, clerical workers, and service and technology employees, identified suspicious activity within its computer network on or around August 1, 2025, potentially indicating unauthorized access. Third-party cybersecurity experts were engaged to investigate the activity and confirmed unauthorized access to the network. Further investigation uncovered evidence that certain data, including Protected Health Information, on the network was accessed and potentially copied without authorization. The data related to members of the Teamsters Union 25 Health Services & Insurance Plan and the Teamsters Union 25 Investment Plan. The review of the affected files was completed on August 18, 2025, and notification letters were mailed to the affected individuals on September 3, 2025. The affected individuals have been offered 12-24 months of complimentary credit monitoring and identity theft protection...



