November 2024 Healthcare Data Breach Report
There has been a 15.3% month-over-month increase in healthcare data breaches, with 68 data breaches of 500 or more healthcare records reported to the U.S. Department of Health and Human Services’ Office for Civil Rights (OCR) in November. November was the worst month of H2 2024 in terms of reported data breaches, and the 4th worst month of the year; however, data breaches were down 8% from November 2024. November’s healthcare data breaches bring the 2024 total up to 667 data breaches, one short of the total for the year to November 30, 2023. While there was an increase in data breaches there was a reduction in breached records, which were down 36.1% month-over-month to 3,437,256 breached records. In 2024, an average of 16,395,000 records were breached each month; however, that number is skewed by the massive data breach at Change Healthcare which affected an estimated 100 million individuals. The median number of breached records each month in 2024 is 6,496,306 records. As the bar chart below shows, there was a massive decrease in breached records compared to the 31 million...
Illinois Department of Human Services Phishing Attack Impacts 1.1 Million Customers
Earlier this year, an email phishing attack on the Illinois Department of Human Services (IDHS) saw multiple employees tricked into disclosing their credentials. The threat actor was able to access email accounts that contained the public assistance account information of more than 1.1 million customers, including the Social Security numbers of 4,701 customers. According to an IDHS media notice on December 20, 2024, the email accounts were compromised on April 25, 2024. Assisted by the Illinois Department of Innovation and Technology (DoIT), IDHS investigated the incident to determine the extent of the data breach and the individuals who had sensitive data exposed. On May 3, 2024, IDHS determined the incident was a reportable data breach under the Illinois Personal Information Protection Act (PIPA); however, it took several months to analyze the email accounts and associated files. The analysis revealed 1,118,993 customers had public assistance account information compromised, including their name and public assistance account number in combination with some or all of the...
Hackers Obtained the Data of BU Framingham Heart Study Participants
Boston University has notified all Framingham Heart Study participants that hackers have obtained their personal and medical information. Data breaches have also been announced by Rumpke Consolidated Companies, OrthopedicsNY, and IU Health. Boston University – Framingham Heart Study Data Breach Boston University (BU) has recently notified all Framingham Heart Study participants about a September 2024 hacking incident that saw hackers download participants’ personal and medical information. The Framingham Heart Study was founded in 1948 and was devised to determine the causes, characteristics, and common factors that contribute to cardiovascular disease. The Framingham Heart Study is the longest-running multi-generational heart study in the United States and some individuals have been participating for more than 75 years and enrolled their children and grandchildren in the study. All 15,448 participants have been affected by the data breach. The cyberattack occurred on September 8, 2024, and was interrupted by BU officials, although not in time to prevent sensitive data from...
December 23, 2024: Deadline for Compliance with the HIPAA Privacy Rule Reproductive Healthcare Final Rule
In April 2024, the HHS Office for Civil Rights (OCR) published the HIPAA Privacy Rule to Support Reproductive Healthcare Privacy Final Rule. The new rule took effect on June 23, 2024, and the compliance date for all but the Notice of Privacy Practices requirement is December 23, 2024. The Notice of Privacy Practices compliance deadline is February 16, 2026. Why Was the HIPAA Privacy Rule to Support Reproductive Healthcare Privacy Enacted? The new rule was a response to the Supreme Court’s decision in Dobbs v. Jackson Women’s Health Organization in 2022. The decision overturned Roe v. Wade which had guaranteed the constitutional right to abortion since 1973. Following the Supreme Court’s decision, the legality of abortion care was left to individual states to decide. As of December 2024, 13 U.S. states have banned abortions, 6 states have gestational limits of between 6 and 12 weeks, and 4 states have gestational limits between 18 and 22 weeks. Since the Supreme Court’s decision, healthcare providers, patients, and others have expressed concern that their protected health...
Please Take Our 5-Minute Annual HIPAA Survey
HIPAA Compliance for HIPAA Covered Entities The HIPAA Journal Annual Survey measures the level of HIPAA compliance in HIPAA-covered entities. >The survey is completely anonymous – no personal details are required. The survey consists of multiple choice questions and should take around 5 minutes to complete. >The survey results will be freely and publicly shared in The HIPAA Journal editorial and in our weekly newsletter. >The survey is not designed to assess HIPAA compliance for individuals or HIPAA compliance for Business Associates. Start the survey below Please select one answer from each of the multiple-choice options: This survey is now closed.



