Almost One-Third of Rural Hospitals Benefiting from Microsoft’s Cybersecurity for Rural Hospitals Program
Earlier this month, Microsoft provided an update on its Cybersecurity for Rural Hospitals Program, an initiative designed to protect access to healthcare for the 46 million Americans living in rural communities by helping rural hospitals improve cybersecurity and resiliency. Patients in rural areas need to travel more than twice as far as residents in urban areas to reach their nearest hospital. If the nearest hospital experiences a ransomware attack that causes disruption to hospital operations, rural residents must travel a further 20 miles for common services and often a further 40 miles for specialized services. Rural hospitals often have low operating margins, high fixed costs relative to their urban counterparts, and have lower reimbursement rates from insurers. Between 2010 and 2017, rural hospitals were closing at a rate of around 1 per month, and there were 136 rural hospital closures in 2020 and 20221 alone. In 2022, 429 rural hospitals were at high financial risk. Due to limited budgets, rural hospitals often lack the resources to implement key cybersecurity...
Numotion Reports Email Data Breach Affects 529,000 Individuals
The wheelchair and mobility equipment provider United Seating and Mobility LLC, which does business as Numotion, has recently confirmed a data breach that involved unauthorized access to the personal and protected health information of 494,326 individuals. According to the substitute breach notice on its website, an unauthorized third party gained access to the email accounts of some of its employees between September 2, 2024, and November 18, 2024, following responses to phishing emails. The total has since been updated to 529,004 individuals. Numotion said it has no reason to believe that the accounts were accessed to obtain personal information, and no evidence has been found to indicate that any information in the accounts has been stolen and misused. The accounts were reviewed to determine the individuals affected and the types of data exposed, and on January 22, 2025, Numotion confirmed that some customer information was involved. The types of information in the accounts varied from individual to individual and may have included names, dates of birth, product information,...
Colorado Eye Clinic Investigating Suspected Ransomware Attack
Data security incidents have been announced by Columbia Eye Clinic in South Carolina, Meigs County Emergency Medical Services in Ohio, Cottrill’s Specialty Pharmacy in New York, and ALN Medical Management in Colorado. Columbia Eye Clinic, South Carolina Columbia Eye Clinic, a medical and surgical ophthalmology practice with four locations in Columbia and Lexington in South Carolina, announced a data security incident on March 14, 2025, involving the exposure of patients’ protected health information. The incident was described as “an information technology network disruption that impacted the clinic’s accessibility to certain electronic systems” – language indicative of a ransomware attack. The incident was detected on January 13, 2025, and the forensic investigation confirmed that an unauthorized actor accessed its network between January 9, 2025, and January 13, 2025, and may have viewed or obtained patient data. The investigation is ongoing, and the e-discovery process has begun to determine the individuals affected and the data exposed. The initial assessment suggests...
Orthodontic Practice Management Software Provider Announces Data Breach
OrthoMinds, an Alpharetta, Georgia-based provider of orthodontic practice management software, has recently announced a November 2024 security incident that potentially resulted in unauthorized access to patients’ protected health information. The forensic investigation confirmed that parts of its network may have been exposed to unauthorized, external third parties between November 17, 2024, and November 27, 2024. The file review confirmed that the information likely compromised in the incident includes names, dates of birth, medical information, health insurance information, payment card information, and Social Security numbers. What is not clear at this stage is how many individuals have been affected. The file review is ongoing, and the breach has been reported to the HHS’ Office for Civil Rights as involving the information of at least 501 individuals. The final total is likely to be substantially higher. OrthoMinds is sending notification letters to the individuals affected on behalf of its affected clients and is offering complimentary credit monitoring services to...
Illinois Business Associate Settles Alleged Risk Analysis Failure for $227,816
Health Fitness Corporation, an Illinois business associate, has agreed to settle an alleged HIPAA risk analysis failure with the HHS’ Office for Civil Rights (OCR). The agreement includes a $227,816 financial penalty, a corrective action plan, and two years of compliance monitoring. One of the most common HIPAA violations identified by OCR in its audits and investigations is the failure to conduct a comprehensive and accurate risk analysis, as required by the administrative safeguards of the HIPAA Security Rule – 45 C.F.R. § 164.308(a)(1)(ii)(A). This implementation specification requires regulated entities to “conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information [ePHI] held by the covered entity or business associate.” Identified risks must then be subjected to a risk management process and be reduced to a reasonable and appropriate level. If a risk analysis is not completed, or if it is not comprehensive and accurate, risks and vulnerabilities to...



