Cyberattack on Sunflower Medical Group Affects 222,000 Patients
Cyberattacks and data breaches have been announced by Sunflower Medical Group, The Center for Digestive Health, NVW Newco, Endless Mountains Health Systems, and the Department of Veterans Affairs Eastern Colorado Health Care System. Sunflower Medical Group, Kansas Sunflower Medical Group, a private multi-specialty medical group with four care centers in Kansas City, Lenexa, and Roeland Park in Kansas, has suffered a data breach involving the personal and protected health information of 220,968 individuals. Suspicious activity was identified within its network on January 7, 2025, with the third-party forensic investigation confirming that an unauthorized actor had access to its network from December 15, 2024, until January 7, 2025. During that time, files were exfiltrated from its network, some of which contained patient data. The file review confirmed that the types of data compromised in the cyberattack included names, addresses, dates of birth, Social Security numbers, driver’s license numbers, medical information, and health insurance information. Sunflower Medical Group is...
HIPAA Compliance for Dermatologists
A number of sources discussing HIPAA compliance for dermatologists suggest all dermatologists are required to comply with HIPAA because they have access to personal health information. This is not correct, and it may be the case that some dermatologists have implemented HIPAA privacy and security safeguards unnecessarily. The Health Insurance Portability and Accountability Act (HIPAA) is an Act passed in 1996 with the primary objectives of increasing individual access to health insurance, enabling individuals to continue health coverage between jobs, and limiting the restrictions health insurance plans can place on individuals with preexisting health conditions. Because achieving these objectives would incur costs for health plans – and because of concerns the costs would be passed on in the form of higher insurance premiums – Congress added measures to HIPAA to lower costs for health insurance companies by reducing the opportunities for insurance fraud and increasing the efficiency of healthcare transactions. These measures led to the publication of the HIPAA Administrative...
CareFirst BCBS Sues Change Healthcare Over February 2024 Ransomware Attack
CareFirst BlueCross BlueShield has filed a lawsuit against Change Healthcare in response to the February 2024 ransomware attack that caused extensive disruption to Change Healthcare’s services. CareFirst BlueCross BlueShield provides health plans to 3.5 million individuals and groups in Maryland and the Washington D.C. metropolitan area and has a 75% share in the Federal Employees Health Benefits Program, which has more than 626,000 members. The CareFirst lawsuit was filed a year to the day after the ransomware attack by the ALPHV/BlackCat ransomware group, which gained access to Change Healthcare’s network using compromised credentials for a Citrix portal that did not have multifactor authentication enabled. The ransomware affiliate exfiltrated a huge amount of data from the network, including the protected health information of an estimated 190 million individuals. The outages of Change Healthcare’s systems lasted for weeks, causing massive disruption to healthcare providers that relied on its clearinghouse services. Unable to bill for services and get paid, many providers...
Rhode Island Human Services Agency Announces 114K-Record Data Breach
Cyberattacks have recently been announced by Community Care Alliance in Rhode Island, Central Texas Pediatric Orthopedics, and Whitman Hospital and Medical Clinics in Washington. At least 204,000 individuals have had their personal and health data exposed. Community Care Alliance A major data breach has been announced by the Woonsocket, Rhode Island-based human services agency Community Care Alliance. A security incident was identified on July 6, 2024, when network disruption was experienced. Third-party cybersecurity experts were engaged to investigate the cause of the activity, and it was confirmed that an unauthorized third party had access to its network from July 1, 2024, to July 5, 2024. While ransomware was not mentioned in the breach notice, it appears to have been an attack by the Rhysida ransomware group, which has added Community Care Alliance to its data leak site. Rhysida claims to have exfiltrated a 2.5 terabyte SQL database in the attack, which included data such as names, contact information, and Social Security numbers. Community Care Alliance conducted a file...
What Does TPO Stand for in HIPAA?
In HIPAA, TPO stands for Treatment, Payment, and Healthcare Operations – activities in which HIPAA covered entities and business associates are generally permitted to use and disclose Protected Health Information without an individual’s consent or authorization. However, there are exceptions, and conditions are attached to certain types of uses and disclosures. One of the purposes of the HIPAA Privacy Rule is to distinguish between which uses and disclosures of Protected Health Information (PHI) are required, which are permitted, and which require the consent or authorization of the subject of the PHI or their personal representative. Generally, required uses and disclosures of PHI are limited to: Disclosures to an individual exercising their HIPAA Rights. Disclosures to HHS agencies (i.e., Office for Civil Rights). Disclosures required by law (i.e., reporting child abuse). Permitted uses and disclosures of PHI include disclosures by whistleblowers, disclosures for public health activities, and disclosures to law enforcement agencies. Covered healthcare providers can also disclose...



