Paubox Research on Email Security Identifies Top Security Risks in 2026
New research from Paubox has highlighted the top email security risks for healthcare organizations in 2026. The greatest risk lies not with novel and increasingly sophisticated threats, but the foundational weaknesses in email security that have existed and been exploited by threat actors for years. The latest data show that cyber threat actors are relying less on vulnerabilities and are focused on compromised credentials for initial access to networks. Email is the leading entry point for cybercriminals and the root cause of many data breaches, especially in healthcare. Cybercriminals are using email to obtain credentials that provide them with the foothold they need for an extensive compromise, including data theft, extortion, and file encryption with ransomware. The extent to which email is used, and the weaknesses in email security that facilitate attacks, have been explored by the leading HIPAA-compliance email firm Paubox in its 2026 Healthcare Email Security Report. Based on data reported to the Department of Health and Human Services (HHS) Office for Civil Rights (OCR), at...
ID Care & CommuniCare Announce Data Breaches
ID Care in New Jersey and Barrio Comprehensive Family Health Care Center (CommuniCare) in Texas have confirmed that patients’ personal and protected health information have been compromised in recent data security incidents. ID Care ID Care, a New Jersey-based network of board-certified infectious disease specialists, has recently disclosed a data security incident that involved unauthorized access to the personal and protected health information of current and former patients. Suspicious activity was identified within certain systems on November 5, 2025. Industry-leading cybersecurity specialists were engaged to investigate the activity and confirmed that an unknown actor gained access to its network and accessed or downloaded files without authorization. ID Care is currently reviewing the affected files, and while that process has not yet been completed, ID Care has confirmed that the affected files contained full names, dates of birth, Social Security numbers, health insurance information, and medical information, including diagnoses, treatment information, and prescription...
Data Breaches Reported by Centerwell & Lakeside Pediatrics & Adolescent Medicine
Centerwell, a provider of senior healthcare services in 30 U.S. states, has experienced a cyberattack and data breach. Lakeside Pediatric & Adolescent Medicine has recently notified individuals affected by an October 2024 data breach. Centerwell Centerwell, a Louisville, Kentucky-based provider of healthcare services to seniors, has recently reported a data breach to the Texas Attorney General that involved unauthorized access to patient information. The scale of the breach is currently unclear, other than the personal and protected health information of 4,618 Texas residents was compromised in the incident. The breach could be substantially larger, as Centerwell provides senior healthcare services in 30 U.S. states. The Texas Attorney General was informed on March 6, 2026, that data compromised in the incident includes names, addresses, dates of birth, and medical information. At the time of writing, the affected individuals have not been informed by mail, and no known threat group has publicly claimed responsibility for the incident. While there is currently no substitute...
HIPAA Compliance for Practice Managers
Practice managers occupy one of the most compliance-exposed positions in a healthcare organization because they are responsible for both the structural integrity of the HIPAA program and the accuracy of its daily execution across every function the practice performs. The HIPAA Privacy Rule, HIPAA Security Rule, and HIPAA Breach Notification Rule impose obligations that run through hiring, onboarding, vendor contracting, patient interactions, IT system management, and incident response, all of which fall within the practice manager’s operational scope. A practice manager who understands these obligations at a working level, rather than relying on policy documents alone, is the single most effective compliance control a small or mid-sized practice has. Building and Maintaining the HIPAA Compliance Program Assigning Compliance Roles The HIPAA Privacy Rule requires every HIPAA Covered Entity to designate a HIPAA Privacy Officer responsible for developing and implementing privacy policies and procedures. The Rule also requires the designation of a point of contact for patients who...
Texas Governor Instructs State Agencies to Audit Chinese Medical Devices
Texas Governor Greg Abbot has ordered all state agencies and state-owned medical facilities to conduct an audit of patient monitoring devices to ensure that they do not have unresolved vulnerabilities that could be exploited to gain access to Texans’ sensitive health information. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) and the United States Food and Drug Administration (FDA) have issued warnings about vulnerabilities in patient monitoring devices manufactured in China. Devices have been found to contain a backdoor that can be used by a remote attacker to gain access to sensitive patient data. There has been a proliferation of Chinese-manufactured medical devices within the U.S. healthcare system. The concern is that these devices have backdoors that can be exploited by state-sponsored hacking groups to obtain the private medical information of Americans. Governor Abbot wants to make sure that the private medical data of Texans cannot be obtained by China. “I will not let Communist China spy on Texans. State-owned medical facilities must ensure there are...



