Data Breaches Announced by DermCare Management; Option Care Health; Aetna
Data breaches have recently been announced by DermCare Management in Florida, Option Care Health in New York, and Aetna in Connecticut. DermCare Management Discloses 2025 Hacking Incident DermCare Management, a Florida-based provider of practice management services to dermatology practices in Florida, Texas, California, and Virginia, has identified unauthorized access to its computer systems. Suspicious activity was identified within its computer network on February 26, 2025, and, assisted by third-party digital forensics specialists, DermCare Management determined on March 3, 2025, that there had been unauthorized network access between February 14, 2025, and February 26, 2025. During that time, patient information was either accessed or acquired. DermCare Management engaged data review specialists to determine the individuals affected and the types of data involved. Due to the complexity of the data, it took until March 2, 2026, to identify the individuals affected, the types of data involved, and obtain sufficient information to issue individual notification letters. DermCare...
HIPAA for Solo Practitioners
Most solo practitioners do not begin their careers in solo practice. They typically spend years working in hospitals, group practices, or supervised clinical settings where confidentiality, accurate recordkeeping, and respect for patient rights are treated as core professional obligations. By the time they open their own practice, solo practitioners have already acquired and demonstrated competence in the ethical and legal standards of their profession through formal education, licensing exams, and real‑world clinical experience. What changes in solo practice is not the practitioner’s understanding of these obligations, but the responsibility for operationalizing them. HIPAA provides a federal compliance framework that translates long‑standing professional duties into operational requirements that must be implemented, documented, and maintained. In larger organizations, this work is supported by administrative staff, IT teams, compliance officers, and established workflows. In a solo practice, the practitioner becomes the Privacy Officer, Security Officer, and compliance lead by...
February 2026 Healthcare Data Breach Report
In February 2026, 63 data breaches were reported to the Department of Health and Human Services (HHS) Office for Civil Rights (OCR) that affected 500 or more individuals, a 14.5% increase from January 2026, and 12.5% more than the average number of February data breaches over the past 5 years. Between January 1 and February 28, 2026, 118 data breaches affecting 500 or more individuals have been reported to OCR, involving the protected health information of 9,651,076 individuals. While healthcare data breaches have declined 10.6% year-over-year, the number of individuals affected has increased 44.7%. Across the 63 data breaches reported in February, the protected health information of at least 8,134,378 individuals was exposed or impermissibly disclosed, a 436% month-over-month increase and 38.9% more than the average number of affected individuals over the past 12 months. Biggest Healthcare Data Breaches in February 2026 The high total in February is due to massive data breaches at two HIPAA-regulated entities in February – TriZetto Provider Solutions, a provider of administrative...
Data Breaches Announced by Neinstein Plastic Surgery; Atlantic Brain and Spine
Neinstein Plastic Surgery in New York and Atlantic Brain and Spine in North Carolina have announced security incidents that exposed patient information. Neinstein Plastic Surgery, New York Neinstein Plastic Surgery in New York City has identified unauthorized access to an email account that contained sensitive patient information. Unauthorized activity was identified in the email account on December 2, 2025. The account was secured, and an investigation was initiated to determine the nature and scope of the activity. The investigation confirmed that the account had been accessed by an unauthorized individual between November 12, 2025, and November 20, 2025, and that this was a financially motivated attack rather than an attempt to obtain patient information; however, patient information may have been obtained in the incident. The account was reviewed and on February 20, 2026, Neinstein Plastic Surgery confirmed that emails and documents in the account contained information such as names, contact information, dates of birth, driver’s license or passport numbers, Social Security...
Settlement Agreed to Resolve Class Action Data Breach Litigation Against Concord Orthopaedics
Concord Orthopaedics Professional Association, a New Hampshire-based provider of comprehensive orthopedic and rheumatology care, has settled a consolidated class action lawsuit stemming from a November 2024 cybersecurity incident involving unauthorized access to the personal and protected health information of 72,815 individuals. Concord Orthopaedics detected an intrusion on November 21, 2024. Hackers had gained access to its computer network, where names, dates of birth, Social Security numbers, appointment information, health insurance information, and driver’s license/state identification numbers were stored. The affected individuals started to be notified about the incident on March 25, 2025. The first class action lawsuit was filed by plaintiff Kattie Montambeault on April 1, 2025, in the Merrimack County Superior Court for the State of New Hampshire. A further four class action complaints were filed in response to the data breach, which were consolidated into a single action – Montambeault, et al. v. Concord Orthopaedics Professional Association – in the Superior Court...



