VectraRx Mail Pharmacy Services Notifies 109K Individuals About Data Breach
Cyberattacks and data breaches have recently been announced by VectraRx Mail Pharmacy Services, St. Andrew’s Resources for Seniors System, Jewish Child Care Association of New York, and the Columbus Division of Fire. VectraRx Mail Pharmacy Services VectraRx Mail Pharmacy Services, a New York-based mail order pharmacy, has suffered a major data breach involving the protected health information of 109,383 individuals. On February 6, 2025, VetraRx disclosed details of the incident, stating that unusual activity was identified in its computer systems on December 13, 2025, and a third-party cybersecurity firm was engaged to investigate the cause of the activity. The investigation confirmed that an unauthorized actor had access to its network and may have viewed or acquired certain data. VetraRx did not disclose in the breach notice when its network was first breached or the duration of the unauthorized access. The review of the exposed data was completed on January 7, 2025, when it was confirmed that the exposed electronic protected health information (ePHI) included names, dates of...
Three Healthcare Providers Notify Patients About 2024 Data Breaches
Data breaches have recently been announced by Consultants in Pain Medicine in Texas, Claris Vision Holdings in Massachusetts, and Precision Orthopedics and Sports Medicine in Maryland. Consultants in Pain Medicine Texas Consultants in Pain Medicine, a San Antonio, Texas-based pain management practice, has recently notified the Texas Attorney General about a security incident that saw unauthorized individuals access its network between June 26, 2024, and July 7, 2024. The forensic investigation confirmed that the attackers had access to patient data and exfiltrated files from the network. The file review concluded on January 17, 2025, and it was confirmed that full names, Social Security numbers, dates of birth, driver’s license numbers or state identification numbers, financial account information, passport numbers, medical information, and/or health insurance policy information had been stolen. Notification letters started to be mailed to the affected individuals on February 14, 2025. Individuals whose Social Security numbers were involved were offered complimentary credit...
Vulnerability Identified in Medixant RadiAnt DICOM Viewer
A vulnerability has been identified in the Medixant RadiAnt DICOM Viewer, a commonly used PACS DICOM viewer for medical images. The vulnerability is tracked as CVE-2025-1001 and is a medium-severity vulnerability with a CVSS v3.1 base score of 5.7 (v4 base score 5.7). The vulnerability affects RadiAnt DICOM Viewer version 2024.02 and is due to the update mechanism failing to verify the update server’s certificate. The vulnerability could be exploited in a machine-in-the-middle (MitM) attack, and successful exploitation could allow an attacker to modify the response from the server and deliver malicious updates to the user. Medixant has addressed the issue and recommends users update their software to version v2025.1 or a later version. If any users are unable to apply the update, steps should be taken to prevent the vulnerability from being exploited. The mitigations involve preventing any updates from being applied to the software. The display of available updates should be disabled via the command reg add “HKCU\Software\RadiAnt Viewer” /t REG_DWORD /v CheckUpdate /d 0...
How Much Does an EMR for a Small Practice Cost?
For a small practice, EMR software cost commonly totals $3,000 to $25,000 in the first year and $2,000 to $15,000 per year after that, driven by per provider subscription fees, implementation work, data migration, interfaces, training time, and optional modules such as billing, ePrescribing, patient texting, and analytics. Small-practice EMR system pricing is shaped less by the sticker price and more by operational scope. A one or two clinician clinic using scheduling, charting, ePrescribing, and a patient portal has a different cost profile than a multi location practice that needs integrated practice management, clearinghouse services, custom templates, extensive reporting, and interfaces to labs, imaging, immunization registries, and health information exchanges. Implementation labor, configuration decisions, and the time staff spend in training and workflow redesign create real costs even when the vendor fee is low. EMR Software Cost Emr software cost usually includes a recurring license and several one-time items that are not visible in a monthly quote. Subscription fees are...
HIPAA Compliance Regulations
HIPAA Compliance Regulations The latest version of the HIPAA compliance regulations were enacted in the Final Omnibus Rule of 2013. They extend the rights of patients under the HIPAA Privacy Rule, now cover business associates, and introduce new administrative, physical and technical safeguards under the HIPAA Security Rule. The HIPAA compliance regulations reflect changes in working practices and technological advances over the past few years. Many more medical professionals are supporting their workflows by using their personal mobile devices. The misuse, theft or loss of mobile devices is estimated to result in thousands of security breaches every year. The latest HIPAA compliance regulations are intended to prevent these breaches. Compliance with the HIPAA Privacy Rule In addition to extending the HIPAA compliance regulations to business associates, other changes to the HIPAA privacy rule introduce new guidelines for the conditions under which Protected Health Information (PHI) should be disclosed to anybody other than the patient. Effectively, only the minimum “individually...



