Cybercriminals Hit Washington Laboratory and New York Pharmacies
Hacking-related data breaches have been reported by Meridian Valley Laboratories in Washington, and College Parkside Pharmacy and College Hometown Pharmacy in New York state. College Parkside Pharmacy & College Hometown Pharmacy Certain patients who received services from College Parkside Pharmacy and/or College Hometown Pharmacy in New York state are being notified about a recent security incident that potentially involved unauthorized access to their protected health information. The pharmacies are operated by Albany College of Pharmacy and Health Sciences, which previously announced the security breach; however, the HHS’ Office for Civil Rights has only recently been notified. The OCR breach portal indicates the incident affected 9,742 individuals who received services from College Hometown Pharmacy and 5,736 individuals who received services from College Parkside Pharmacy. According to the breach notice, unusual activity was identified within its computer network on or around September 14, 2024. External cybersecurity specialists were engaged to assist with the...
Florida Pediatric ENT Specialists Confirm Data Breach Affecting 44,000 Individuals
Pediatric Otolaryngology Head & Neck Surgery Associates has reported a data breach affecting almost 44,000 patients. Anchorage Neighborhood Health Clinic in Alaska is investigating a potential security breach that may have affected up to 10,000 patients, and Valley Mountain Regional Center has exposed data over the Internet. Pediatric Otolaryngology Head & Neck Surgery Associates, Florida Pediatric Otolaryngology Head & Neck Surgery Associates (POHNS) in Florida recently reported a data breach to the HHS Office for Civil Rights affecting 43,446 individuals. POHNS first announced the data breach on April 25, 2025. Unusual activity was identified within its computer network on February 24, 2025. The forensic investigation confirmed unauthorized access between February 19 and February 24, 2025, including access to patients’ protected health information. The file review confirmed that a range of patient data had been exposed, although the information involved varied from individual to individual. Data potentially compromised in the incident included names in combination...
New York Blood Center Enterprises Notifies Individuals Affected by January Ransomware Attack
New York Blood Center Enterprises, the operator of 19 blood donor centers in New York and New Jersey, has notified the Maine Attorney General about its January 2025 ransomware attack and has provided further information on the findings of its investigation. As previously announced and reported below, the attack was detected on January 26, 2025. The forensic investigation confirmed that an unauthorized third party had access to its computer network between January 20 and January 26, 2025, and obtained a copy of a subset of files stored on the network. The files were reviewed, and New York Blood Center Enterprises obtained a preliminary list of individuals whose names and sensitive data were involved on June 30, 2025. The draft list was reviewed, and “an extensive analysis” was conducted to develop a final list of the individuals to notify. The final list was obtained on August 12, 2025. The types of information involved vary from individual to individual and may include names in combination with Social Security numbers, driver’s license numbers, other government...
HIPAA Compliance for Pain Management Clinics
HIPAA compliance for pain management clinics requires implementing controls under the HIPAA Privacy Rule, HIPAA Security Rule, and HIPAA Breach Notification Rule across scheduling, evaluation, treatment planning, procedures, prescribing support, referrals, billing, and records release. HIPAA Compliance in Pain Management Practices Pain management clinics create, receive, maintain, and transmit protected health information through registration, referrals, clinical histories, diagnostic documentation, treatment plans, procedure notes, medication lists, prior authorization records, and revenue cycle activities. Pain management practices frequently exchange protected health information with primary care providers, specialists, imaging providers, laboratories, pharmacies, and payers. Each exchange must be governed as a regulated use or disclosure and supported by documented controls. Pain management services also operate within multidisciplinary care models that involve physical therapy, behavioral health support, and care coordination functions. HIPAA compliance must cover how...
Settlement Agreed to Resolve Weirton Medical Center Data Breach Lawsuit
Weirton Medical Center in West Virginia has agreed to a settlement to resolve class action litigation over a January 2024 ransomware attack that involved the exfiltration of sensitive data from its network. Hackers had access to its computer network between January 14 and January 18, 2024, and used ransomware to encrypt files. Data stolen in the attack included names, dates of birth, Social Security numbers, health insurance information, and treatment information. The affected individuals were notified on March 18, 2024, and the data breach was reported to the HHS Office for Civil Rights as affecting 26,793 individuals. Four class action lawsuits were filed in response to the data breach in the U.S. District Court for the Northern District of West Virginia, naming Trish Yano, Matthew Foltz, Leslie Telek, and Judy Mullins as plaintiffs. The lawsuits were consolidated into a single lawsuit – In re Weirton Medical Center Data Breach Litigation – on June 21, 2024. The lawsuit asserted claims of negligence and negligence per se for failing to protect sensitive data on its...



