HIPAA Certification for Business Associates
HIPAA certification for Business Associates is documented evidence that employees have completed training on HIPAA Privacy Rule, HIPAA Security Rule, HIPAA Breach Notification Rule, Business Associate Agreement restrictions, permitted uses and disclosures of protected health information, incident reporting, and practical safeguards that apply when a vendor, contractor, consultant, or service provider handles protected health information for a covered entity. Meaning of HIPAA Certification for Business Associates HIPAA certification for HIPAA Business Associates usually refers to a certificate of completion issued after workforce members complete HIPAA training and pass the required course assessments. For HIPAA Business Associates, certification has a narrower compliance function. It shows that employees received training on HIPAA obligations relevant to their work. It also creates documentation that can be retained with training records, workforce onboarding files, compliance reports, and audit materials. HIPAA Business Associates should treat certification as evidence of...
Home Healthcare Agency Owner Facing Decades in Jail for $1.6M Medicare Fraud Scheme
The owner and operator of a Michigan home health care company has been convicted of five counts of healthcare fraud and four counts of paying illegal healthcare kickbacks and now faces decades in jail. Ruby Scott, 55, of Farmington Hills, Michigan, the owner and operator of Delta Home Health Care LLC, was alleged to have operated a fraud scheme that caused more than $1.6 million in losses to the Medicare program. From 2018 to 2021, Scott was alleged to have fraudulently billed Medicare for home health services using stolen patient records. Scott bribed a discharge nurse at a Detroit hospital to identify Medicare patients and fax their medical records to Delta Home Health Care. Scott developed a kickback relationship with the nurse, paying approximately $300 for each set of patient records that were successfully used to bill Medicare. The discharge nurse was paid more than $130,000 via PayPal, CashApp, cash, and check for providing the records. Scott used confidential diagnostic and personal information to bill Medicare for home healthcare services for the patients, falsely...
Datavant Group to Pay $900,000 to Settle Class Action Data Breach Lawsuit
A settlement has been agreed to resolve a class action lawsuit against Ciox Health, which does business as Datavant Group, an Arizona-based health IT company, over a May 2024 email-related data breach. Suspicious activity was identified within an employee’s email account on May 9, 2024. The forensic investigation confirmed that an unauthorized individual had access to the account between May 8 and May 9, 2024. Access to the account was gained after an employee responded to a phishing email. The breach was reported to the HHS’ Office for Civil Rights as affecting 320,702 individuals. Data potentially compromised in the incident included names, dates of birth, addresses, contact information, Social Security numbers, financial account information, driver’s license numbers, passport numbers, and health information. A lawsuit was filed in response to the data breach – Jackson v. Ciox Health, LLC d/b/a Datavant Group – in the United States District Court for the District of Arizona. The lawsuit alleged that the defendant failed to implement sufficient security measures to protect...
May 2026 Data Breach Round Up: Data Breaches Affect 9 HIPAA-regulated Entities
A round-up of data breaches recently announced by 9 HIPAA-regulated entities: University of Nebraska Medical Center, Singing River Health System, Tampa Bay Dental Implants & Prosthetics, Aligned Orthopedic Partners, South Alabama Regional Planning Commission, Pivot Health, LHC Group, Mays Housecall Home Health, and the World Trade Center Health Program. University of Nebraska Medical Center University of Nebraska Medical Center (UNMC) has discovered that a vulnerability in a third-party software application has been exploited by a threat actor, exposing patient information. UNMC learned about the vulnerability in the REDCap software application in February 2026. REDCap software is used by UNMC to support its research studies and public health activities. When UNMC learned about the vulnerability, the software was taken offline, and an investigation was launched to determine if the vulnerability had already been exploited. Assisted by third-party cybersecurity experts, UNMC determined that the vulnerability had been exploited on September 20, 2023, and access remained possible...
Radiology Associates of Richmond Data Breach Affects 266K Individuals
Radiology Associates of Richmond in Virginia, one of the oldest, continuously operating private radiology practices in the United States, has announced another major data breach. Two years ago, the protected health information of more than 1.4 million individuals was compromised in a cybersecurity incident. A little over one year later, another cybersecurity incident was experienced that exposed the personal and protected health information of more than 266,000 current and former patients. The most recent incident has recently been reported to the Maine Attorney General as involving unauthorized access to the electronic personal and protected health information of 266,183 individuals. The breach notice does not state when the intrusion was detected; only that the forensic investigation determined that the unauthorized access occurred on or around July 25, 2026. The extensive forensic investigation and manual data review concluded on April 6, 2026, when it was confirmed that personal and protected health information was potentially viewed or acquired in the incident. A substitute...



