340,000 Individuals Affected by Security Breach at St Clair Orthopaedics & Sports Medicine
Data breaches have recently been announced by St Clair Orthopaedics & Sports Medicine in Michigan and Rheumatology Associates of Baltimore in Maryland. St Clair Orthopaedics & Sports Medicine During a recent check of the HHS’ Office for Civil Rights breach portal, a data breach was identified that had not been reported by The HIPAA Journal. St Clair Orthopaedics & Sports Medicine (SCOSM) in St. Clair Shores, Michigan, reported a breach to OCR on January 30, 2025, that involved the protected health information of 340,000 individuals. Suspicious activity was identified within the SCOSM network on November 24, 2024. An investigation was launched to determine the nature and scope of any unauthorized network access, with assistance provided by third-party cybersecurity experts. On December 9, 2024, SCOSM learned that unauthorized individuals had gained access to parts of its network that contained patient data, and once the investigation was completed on December 20, 2024, a comprehensive review was conducted to determine the patients affected and the types of data involved....
Navvis & Company; SSM Health Agree to $6.5 Million Data Breach Settlement
Navvis & Company and SSM Health Care Corporation have agreed to a $6.5 million settlement to resolve all claims related to a 2023 data breach that affected 2.8 million individuals. Navvis & Company is a population health company that partners with health systems, physician enterprises, & health plans to help them with value-based care. SSM Health is a healthcare provider serving patients in Illinois, Missouri, Oklahoma, and Wisconsin. Between July 12, 2023, and July 25, 2023, a cybercriminal group had access to the network of Navvis & Company, exfiltrated sensitive data, and used ransomware to encrypt files. The stolen data included the protected health information of patients and plan members of SSM Health, Arkansas Health Network, Horizon Blue Cross Blue Shield of New Jersey, RWJBH Corporate Services, Hawai’i Medical Service Association, Triple-S Management Corporation, Allina Health, and Florida Medical Clinic. The forensic investigation confirmed that approximately 2.8 million individuals had their data exposed or stolen in the incident, including names, dates...
OCH Regional Medical Center Notifies 51,000 Patients About September 2023 Data Breach
OCH Regional Medical Center in Mississippi is issuing notification letters to more than 51,000 patients about a data breach detected in September 2023. Data breaches have also been announced by Blue Cross and Blue Shield of Montana, and Northwest Radiologists/Mt. Baker Imaging in Washington state. OCH Regional Medical Center OCH Regional Medical Center in Starkville, Mississippi, has recently disclosed a security incident that occurred 19 months ago. A security breach was identified by its security team in September 2023, and immediate action was taken to block the unauthorized access. The forensic investigation confirmed that a threat actor first accessed its systems on September 6, 2023; however, the unauthorized access was not detected and blocked until September 14, 2023. The subsequent file review confirmed that the threat actor gained access to the protected health information of 67,000 patients, including names, Social Security numbers, dates of birth, phone numbers, addresses, diagnoses, disability codes, account numbers, and insurance and payer information. OCH Regional...
OSHA Publishes 2024 Workplace Injury and Illness Data
The U.S. Department of Labor’s Occupational Safety and Health Administration (OSHA) has published the 2024 workplace injury and illness data. The 2024 data was collected from OSHA’s Injury Tracking Application (ITA) and includes data from more than 370,000 OSHA Form 300A Summary of Work-Related Injuries and Illnesses reports. The data has been augmented with partial data from more than 732,000 OSHA Form 300 Logs of Work-Related Injuries and Illnesses and Form 301 Injury and Illness Incident Reports. The remainder of the data is currently being checked to ensure it does not contain any personally identifiable information and will be made public when the review is concluded. With the exception of certain low-risk industries, employers with more than 10 employees are generally required to maintain a record of serious work-related injuries and illnesses. They include any work-related injury or illness that results in loss of consciousness, days away from work, restricted work, or transfer to another job, and any work-related injury or illness that requires medical treatment beyond...
Onsite Mammography Email Breach Affects 357,000 Patients
Data breaches have been announced by Onsite Mammography in Massachusetts, Bell Ambulance in Wisconsin, Kelly & Associates Insurance Group in Maryland, and Cabot Medical Care & Jacksonville Medical Care in Arkansas. Onsite Mammography Onsite Mammography, a Westfield, MA-based provider of medical imaging services to hospitals across the United States, has announced a security incident involving the protected health information of 357,265 individuals. Suspicious activity was identified in an employee’s email account in October 2024. The email account was immediately secured, and a forensic investigation was initiated to determine the nature and scope of the unauthorized activity. Third-party digital forensics experts confirmed that there had been unauthorized access to a single email account for “a brief window of time.” A data analytics vendor was engaged to review the account to determine the individuals affected and the types of information in the account. The review concluded on February 21, 2025, and confirmed that health-related information had been exposed. Additional...



