Is GroupMe HIPAA Compliant?
GroupMe is not HIPAA compliant and cannot be used to create, collect, store, or transmit Protected Health Information due to its lack of Technical Safeguards. In addition, GroupMe’s owners – Microsoft – will not enter into a Business Associate Agreement with users of the GroupMe service as it is not an “in-scope” service. GroupMe is a free text messaging service that connects friends, family members, student groups, and/or work colleagues via SMS, IM, audio, and video. Available on Windows desktops, via the Internet, and mobile apps, the service allows users to create groups, invite members, host events, and run polls. Users can also search for and apply to join groups that may be of interest to them. GroupMe and Protected Health Information While GroupMe can be used to connect groups of healthcare professionals, it lacks the Technical Safeguards required by the HIPAA Security Rule to protect Protected Health Information from authorized access and disclosures. For example, GroupMe does not allow group moderators to manage access controls, audit logs, or user...
What is HIPAA Compliant Voicemail?
There are three answers to the question what is HIPAA compliant voicemail – the first relating to the systems used to record incoming messages, the second to the greeting recorded on a healthcare provider’s voicemail system, and the third to voicemail messages left on patients’ answerphone machines. For healthcare providers, it is important that all three types of voicemails are HIPAA compliant. What is HIPAA compliance? Who is required to comply with HIPAA? What is a HIPAA compliant voicemail system? What is a HIPAA compliant voicemail greeting? What is a HIPAA compliant voicemail message? Conclusion and HIPAA compliant voicemail FAQs. What is HIPAA Compliance? HIPAA compliance means complying with the applicable Administrative Simplification Regulations of the Health Insurance Portability and Accountability Act (HIPAA). These regulations can be found at 45 CFR Subtitle A Subchapter C and include well-known HIPAA Rules such as the Privacy Rule, the Security Rule, and the Breach Notification Rule. The primary objectives of the Administrative Simplification Rules are to...
Saint Louis University Agrees to $2 Million Settlement to Resolve Data Breach Lawsuit
A settlement has been reached to resolve a class action lawsuit against St. Louis University and SSM Health Saint Louis University Hospital (SSM-SLUH) over a 2023 data breach. Under the terms of the settlement, a fund of $2 million will be created to cover claims, attorneys’ fees, and legal costs and expenses. St. Louis University identified suspicious activity within its email system in March 2023. The investigation confirmed that a cybercriminal group accessed a limited number of employee email accounts after conducting a phishing campaign. The unauthorized access spanned from December 2022 to July 2023, and while there was unauthorized access, no evidence was found to indicate there had been any misuse of the exposed data. The compromised accounts contained the personal information of students, employees, and hospital patients, including names, addresses, telephone numbers, dates of birth, driver’s license numbers, passport numbers, digital signatures, Social Security numbers, health insurance information, and medical information. Up to 93,000 individuals potentially had...
Loretto Hospital Confirms Patient Data Involved in January Hacking Incident
Loretto Hospital in Chicago has confirmed that patient data was exposed in a January hacking incident. Data breaches have also been announced by Family Centers Inc. in Connecticut and Maryhaven in Ohio. Loretto Hospital, Illinois Loretto Hospital in Chicago, Illinois, has warned patients about a recent hacking and data theft incident. It is unclear from the breach notice exactly when the incident was detected; however, the forensic investigation confirmed that there was unauthorized access to its network between January 17 and February 1, 2025, during which time files were copied from its network. Further, Loretto Hospital determined that from the evening of February 2, 2025, through the afternoon of February 4, 2025, patient information was entered into its electronic medical record system that was not saved. Efforts were made to recover that data, but some records may not have been recovered or fully recreated. It is currently unclear how many individuals have been affected as the file review has not yet concluded. In the interim, the breach has been reported to the HHS’ Office...
Central Texas Pediatric Orthopedics Hacking Incident Affects 140,000 Patients
Hacking incidents have been announced by Central Texas Pediatric Orthopedics, Omni Healthcare Financial Holdings in North Carolina, and Community Dental Care in Minnesota. Central Texas Pediatric Orthopedics On March 6, 2025, Central Texas Pediatric Orthopedics notified the Texas Attorney General about a security incident involving unauthorized access to patient data. The breach report indicates that the protected health information of approximately 90,000 Texas residents was involved, and the April 4, 2025, breach report to the HHS’ Office for Civil Rights reveals 140,000 patients in total have been affected. Central Texas Pediatric Orthopedics has uploaded a substitute breach notice to its website that states a security incident was identified on January 25, 2025. Assisted by third-party cybersecurity experts, Central Texas Pediatric Orthopedics determined that an unauthorized third party accessed its network between January 23 and January 26, 2025. On February 4, 2025, it was confirmed that some of the network locations accessed by the threat actor contained patient information...



