Ransomware Attack Announced by True Dental Care for Kids and Adults
Data breaches have recently been announced by True Dental Care for Kids and Adults in Pennsylvania, North Hudson Community Action Corporation in New Jersey, and California Correctional Health Care Services. True Dental Care for Kids and Adults, Pennsylvania True Dental Care for Kids and Adults LLC in Pennsylvania has started notifying 17,640 individuals about a recent ransomware attack. A hacker gained access to its network on February 3, 2025, and downloaded ransomware, which was used to encrypt files on its network. The forensic investigation of the incident identified unauthorized access to patient data prior to file encryption. A ransom demand was issued; however, it was not paid, and files were successfully restored from backups. True Dental said it is unaware of any misuse of patient data at the time of issuing the notification. The types of information involved vary from individual to individual and include names, dates of birth, addresses, phone numbers, and patient dental/medical records. True Dental said additional safeguards are being implemented to prevent similar...
HIPAA Compliance Tools
HIPAA compliance tools are used as part of the HIPAA compliance process, for example, forms and notices, and to measure HIPAA compliance, for example, assessment tools or checklists that guide covered entities and business associates through the basics of HIPAA compliance. The HIPAA Journal has a number of free resources that help HIPAA-Covered Entities with their HIPAA compliance. HIPAA Business Associate Agreement Template This downloadable template provides a reference for what should be contained in a HIPAA Business Associate Agreement. Click to Download HIPAA Business Associate Agreement Template (Word document, 18K) HIPAA Release Form Releasing medical records without a HIPAA authorization form is a HIPAA violation. Click here for HIPAA release form (free PDF document – Opens directly in the browser) Two US states have their own forms Click here for California HIPAA release form Click here for Texas HIPAA release form HIPAA Notice of Privacy Practices HHS’ Office for Civil Rights has produced a Notice of Privacy Practices template that is free to download. Instructions...
Is GroupMe HIPAA Compliant?
GroupMe is not HIPAA compliant and cannot be used to create, collect, store, or transmit Protected Health Information due to its lack of Technical Safeguards. In addition, GroupMe’s owners – Microsoft – will not enter into a Business Associate Agreement with users of the GroupMe service as it is not an “in-scope” service. GroupMe is a free text messaging service that connects friends, family members, student groups, and/or work colleagues via SMS, IM, audio, and video. Available on Windows desktops, via the Internet, and mobile apps, the service allows users to create groups, invite members, host events, and run polls. Users can also search for and apply to join groups that may be of interest to them. GroupMe and Protected Health Information While GroupMe can be used to connect groups of healthcare professionals, it lacks the Technical Safeguards required by the HIPAA Security Rule to protect Protected Health Information from authorized access and disclosures. For example, GroupMe does not allow group moderators to manage access controls, audit logs, or user...
What is HIPAA Compliant Voicemail?
There are three answers to the question what is HIPAA compliant voicemail – the first relating to the systems used to record incoming messages, the second to the greeting recorded on a healthcare provider’s voicemail system, and the third to voicemail messages left on patients’ answerphone machines. For healthcare providers, it is important that all three types of voicemails are HIPAA compliant. What is HIPAA compliance? Who is required to comply with HIPAA? What is a HIPAA compliant voicemail system? What is a HIPAA compliant voicemail greeting? What is a HIPAA compliant voicemail message? Conclusion and HIPAA compliant voicemail FAQs. What is HIPAA Compliance? HIPAA compliance means complying with the applicable Administrative Simplification Regulations of the Health Insurance Portability and Accountability Act (HIPAA). These regulations can be found at 45 CFR Subtitle A Subchapter C and include well-known HIPAA Rules such as the Privacy Rule, the Security Rule, and the Breach Notification Rule. The primary objectives of the Administrative Simplification Rules are to...
Saint Louis University Agrees to $2 Million Settlement to Resolve Data Breach Lawsuit
A settlement has been reached to resolve a class action lawsuit against St. Louis University and SSM Health Saint Louis University Hospital (SSM-SLUH) over a 2023 data breach. Under the terms of the settlement, a fund of $2 million will be created to cover claims, attorneys’ fees, and legal costs and expenses. St. Louis University identified suspicious activity within its email system in March 2023. The investigation confirmed that a cybercriminal group accessed a limited number of employee email accounts after conducting a phishing campaign. The unauthorized access spanned from December 2022 to July 2023, and while there was unauthorized access, no evidence was found to indicate there had been any misuse of the exposed data. The compromised accounts contained the personal information of students, employees, and hospital patients, including names, addresses, telephone numbers, dates of birth, driver’s license numbers, passport numbers, digital signatures, Social Security numbers, health insurance information, and medical information. Up to 93,000 individuals potentially had...



