Asheville Eye Associates Hacking Incident Impacts 205K Patients
Asheville Eye Associates has announced a data breach affecting 193,000 patients, Moses-Weitzman Health System has confirmed employee data was compromised in the cyberattack that affected more than 1 million Community Health Center patients, and the Chicago Department of Public Health says patient data was exposed online. Asheville Eye Associates Asheville Eye Associates, an eye care provider serving patients in Western North Carolina, has recently disclosed a security incident involving the personal and protected health information. The breach was initially reported to the HHS’ Office for Civil Rights as affecting 193,306 patients, although the total has now been updated to 204,984 individuals. According to its website breach notice, law enforcement was notified about the cyberattack, and third-party cybersecurity experts were engaged to investigate the security incident and determine the nature and scope of the unauthorized activity. The investigation confirmed that patient data such as names, addresses, health insurance information, and medical treatment information were...
Republican Congressman Introduces Bill Seeking Abolishment of OSHA
Arizona Congressman Rep. Andy Biggs has reintroduced a bill that seeks to abolish the Occupational Safety and Health Administration (OSHA). Biggs views OSHA as part of “the bloated federal government” and believes safety and health issues are better handled by states and private employers. OSHA is a federal agency part of the Department of Labor that was established by the Occupational Safety and Health (OSH) Act, which was signed into law by President Nixon on December 29, 1970. The role of OSHA is to ensure America’s workers have safe and healthful working conditions, free from unlawful retaliation. OSHA sets and enforces workplace safety standards, provides training, and enforces anti-retaliation provisions of the OSH Act. OSHA also works with state programs to improve workplace safety. OSHA recently published data that revealed there were 5,283 workplace fatalities and 1,538,299 injuries and illnesses in 2023. Biggs was elected to Congress for the Fifth District of Arizona in 2016 and currently serves on the House Oversight and Accountability Committee and the House Judiciary...
March 1, 2025: Deadline for Submitting 2024 Data Breach Reports to OCR
The deadline for submitting reports of 2024 data breaches affecting fewer than 500 individuals to the HHS’ Office for Civil Rights (OCR) is March 1, 2025. Late filing of breach reports will put HIPAA-regulated entities at risk of a financial penalty for non-compliance with the HIPAA Breach Notification Rule. The HIPAA Breach Notification Rule requires HIPAA-regulated entities to report data breaches to OCR, issue notifications to the affected individuals, and – for breaches affecting 500 or more residents of a state or jurisdiction – notify prominent media outlets serving that state or jurisdiction. All notifications must be issued without unreasonable delay and no later than 60 days after the date of discovery of a data breach. If there is insufficient contact information for 10 or more individuals, a substitute breach notice must be placed on the home page of the entity’s website for at least 90 days or the notice must be provided to major print or broadcast media where the affected individuals likely reside. HIPAA-regulated entities have greater flexibility regarding...
Cyberattack on River Region Cardiology Affects Up to 500,000 Individuals
Cyberattacks have been reported by River Region Cardiology in Alabama and Delta County Memorial Hospital District in Colorado. Lucent Health Solutions in Tennessee has notified individuals who had their data exposed in an October 2, 2023 phishing attack. Cyberattack on River Region Cardiology Affects Up to 500,000 Individuals River Region Cardiology in Alabama has recently notified approximately half a million current and former patients that some of their protected health information was compromised in a September 2024 security incident. Unauthorized access to its systems was detected on September 16, 2024, with the investigation confirming a hacker accessed the network via the remote connection used by an unnamed vendor. The vendor’s remote connection was severed when the unauthorized access was detected. The review of the exposed files confirmed they contained full names, dates of birth, Social Security numbers, and patients’ sex, height, and weight. The breach was reported to the HHS’ Office for Civil Rights on December 11, 2024, as involving the protected health information of...
Over 1 Million Patients Affected by Community Health Center Data Breach
Community Health Center, a nonprofit healthcare provider in Middletown, Connecticut, has notified more than 1 million individuals about a recent data breach. Unauthorized activity was identified in its computer systems on January 2, 2025, and external cybersecurity experts were engaged to assist with the investigation and determine the nature and scope of the unauthorized activity. The investigation confirmed that a criminal hacker accessed its computer systems and exfiltrated data from its network. Community Health Center did not confirm whether a ransom demand was issued; however, explained that no data was deleted from its network and files were not encrypted, therefore the incident had no impact on daily operations. Community Health Center explained in the notification to the Maine Attorney General that “We believe we stopped the criminal hacker’s access within hours, and there is no current threat to our systems.” The Maine Attorney General breach notice states that the breach first occurred on October 14, 2024. The file review has now been completed and Community Health...



