Senators Demand Answers from UnitedHealth After Second Massive Data Breach in a Year
Two U.S. senators have written to UnitedHealth Group (UHG) CEO Stephen J. Hemsley demanding answers about cybersecurity and the response to the massive data breach at its subsidiary, Episource, which exposed the personal and protected health information of 5.4 million individuals earlier this year. Episource, which was acquired by UHG-owned Optum in 2023, provides medical coding and risk adjustment services to physicians, health plans, and other healthcare companies. In June 2025, the company announced a hacking incident that involved unauthorized access to its network between January 27, 2025, and February 6, 2025. The hackers stole sensitive information such as names, dates of birth, Social Security numbers, health information, health insurance information, and Medicare/Medicaid numbers. The hacking incident at Episource occurred within a year of a ransomware attack on another UHG subsidiary, Change Healthcare, which resulted in the largest healthcare data breach in U.S. history. Change Healthcare has recently confirmed that 192.7 million individuals were affected and had their...
HIPAA Training for Medical Laboratory Technicians
HIPAA training for medical laboratory technicians supports HIPAA compliance by preparing laboratory personnel to protect protected health information (PHI) while collecting, labeling, testing, reporting, and transmitting laboratory data that can identify a patient and reveal health conditions. Why Laboratory Workflows Create Unique HIPAA Risks Laboratory environments move fast and rely on precision, which means privacy and security issues often arise from routine operational steps rather than intentional behavior. PHI can appear on specimen labels, requisitions, analyzer printouts, pending worklists, quality review reminders, courier logs, instrument interface messages, and laboratory information system screens. Results reporting can involve internal messaging, faxes, portals, and calls to clinical units, and each handoff creates an opportunity for misdirection, over-disclosure, or unauthorized viewing if safeguards are not followed. Laboratory staff also work with information that can be especially sensitive, such as infectious disease testing, toxicology, pregnancy testing,...
Alera Group Notifies 155K Individuals About July 2024 Hacking Incident
Alera Group has notified more than 155,000 individuals about a July 2024 hacking incident. Data breaches have also been announced by The Good Samaritan Health Center of Cobb and Western Montana Clinic. Alera Group Notifies Individuals About July 2024 Hacking Incident Alera Group, Inc., a provider of risk management, insurance, and financial services, has notified 155,567 individuals about the potential theft of some of their protected health information. The incident was first announced on May 21, 2025, and has recently been reported to the HHS’ Office for Civil Rights. Suspicious network activity was detected in August 2024, and the forensic investigation confirmed unauthorized access to its network between July 19, 2024, and August 4, 2024. During that time, sensitive data may have been copied. A file review was initiated to determine the types of data involved and the individuals affected, and that process was completed on April 28, 2025. Alera Group has confirmed that the data related to employees and certain clients, business partners, and providers. That information included...
Hacking Incidents Announced by Two Texas Health Clinics
A drug and alcohol addiction center and an OB/GYN Medical Center in Texas have notified patients about unauthorized access to some of their protected health information. Nova Recovery Center Reports Unauthorized Network Access Nova Recovery LLC (Nova Recovery Center), a drug and alcohol addiction center in Wimberley, Texas, has identified unauthorized access to certain systems hosted on the Nova Recovery network. The intrusion was identified by its IT and Security teams on May 25, 2025. The threat was neutralized, and the breach was investigated to determine if any patient data had been exposed. On June 17, 2025, Nova Recovery confirmed that business records on its network had been accessed, some of which contained patients’ personal information. Data compromised in the incident includes first, middle, and last names, addresses, dates of birth, Social Security numbers, and financial payment information. Individual notification letters have been mailed to the 7,713 affected individuals, and complimentary credit monitoring services have been offered. The third-party consulting firm...
Business Associate Data Breaches Affect Florida Healthcare Providers
PhyNet Dermatology, a business associate of Premier Dermatology Partners, has identified unauthorized access to an email account containing patient information. Baptist Health South Florida has recently confirmed that it was affected by a breach at Oracle Health (Cerner). PhyNet Dermatology – Premier Dermatology Partners PhyNet Dermatology, a provider of managed administrative services to dermatology practices, has announced a breach that has affected one of its affiliates, Boca Raton, FL-based Total Vein & Skin, LLC, which does business as Premier Dermatology Partners. Suspicious activity was identified in an employee’s email account on November 7, 2024. Immediate action was taken to secure the account, and an investigation was launched to determine the nature and scope of the activity. The investigation determined that the breach was more extensive, and further employee email accounts had also been compromised. The review was completed on June 6, 2025, and confirmed that Premier Dermatiology Partners’ data was present in the compromised accounts. The types of...



