What Are HIPAA Laws?
The main objective of HIPAA law is to protect the privacy of an individuals’ health information while at the same time permitting needed information to be disclosed for patient care and other purposes such as billing. This balance helps protect the rights of patients while ensuring smooth operation of the healthcare system. HIPAA compliance laws set the standards for protecting sensitive patient data that healthcare providers, insurance companies, and other covered entities must adhere to. You can use our HIPAA Law Compliance Checklist to check your compliance requirements and avoid HIPAA violations. What follows is an overview of the main components of HIPAA Law: The HIPAA Law Privacy Rule A key component of HIPAA compliance law is the Privacy Rule, which sets out national standards for when protected health information (PHI) may be used and disclosed. PHI refers to any information about health status, provision of health care, or payment for health care that can be linked to a specific individual. This interpretation of PHI is broad and encompasses any part of a...
HIPAA Compliance for Counselors
The responsibility for HIPAA compliance for counselors in the healthcare industry can vary depending on a counselor’s HIPAA status and whether a practice is part of a managed care organization – in which case, the structure of the managed care organization can determine who is responsible for HIPAA compliance. Counselors who qualify as – or who work for – a HIPAA covered entity are required to comply with all applicable standards and implementation specifications of the HIPAA Administrative Simplification Regulations. These not only include the HIPAA Privacy, Security, and Breach Notification Rules, but also the General Provisions in Parts 160 and 164, and the Transactions and Code Sets Rules in Part 162. The responsibility for determining which standards and implementation specifications apply can vary depending on a counselor’s HIPAA status and what services are contracted out. For example, a sole practitioner counselor that subcontracts claims and billing transactions to a business associate is not required to comply with Part 162 – although it is advisable to monitor business...
Ransomware Gangs Attack Sault Ste. Marie Tribe of Chippewa Indians & SimonMed Imaging
SimonMed Imaging and the Sault Ste. Marie Tribe of Chippewa Indians have suffered ransomware attacks, and the San Diego trade union, UFCW Local 135, has reported a breach of the personal data of more than 62,000 individuals. SimonMed Imaging SimonMed Imaging, a radiology practice in Scottsdale, Arizona, was targeted by a ransomware group. A spokesperson for the practice said the attack was identified and interrupted before any files were encrypted. Some systems were temporarily taken offline, which caused a delay to some services; however, the practice remained fully operational throughout. The spokesperson said there was no unauthorized access to any clinical systems. The Medusa ransomware group has claimed responsibility for the attack and added SimonMed Imaging to its data leak site, along with apparent proof of data theft. 45 files were added to the listing, and the group claimed it stole 212 GB of data in the attack and demanded a $1 million ransom payment. Medusa gave SimonMed Imaging until February 21, 2025, to pay the ransom. Medusa claims to have stolen data such as...
Email Account Breaches Reported by Kansas & West Virginia Medical Centers
Heartland Community Health Center in Kansas and Charleston Area Medical Center in West Virginia have identified unauthorized access to employee email accounts that contained patient data. Heartland Community Health Center Heartland Community Health Center in Lawrence, Kansas, identified unauthorized access to an employee’s email account on October 1, 2024. The forensic investigation confirmed that the breach was limited to a single email account and no other systems were affected. The file review confirmed that the email account contained electronic protected health information such as names, addresses, phone numbers, email addresses, Social Security numbers, driver’s license/state ID numbers, dates of birth, medical diagnosis/treatment information, prescription information, dates of service, patient ID numbers, provider names, medical record numbers, Medicare/Medicaid numbers, health insurance information, health insurance claim numbers, health insurance policy numbers, and/or treatment cost information. Heartland Community Health Center added a substitute breach notice to its...
Data Breaches Confirmed by City of McKinney and Innovative Renal Care
Data breaches have recently been announced by the City of McKinney in Texas and Innovative Renal Care in Tennessee. City of McKinney The City of McKinney has recently confirmed that the protected health information of 17,751 individuals was compromised in an October 2024 cyberattack. The security breach was detected on November 14, 2024, with the forensic investigation confirming government systems were first breached on October 31, 2024. City officials did not provide further information on the nature of the attack, such as if ransomware was involved, and no ransomware group appears to have claimed responsibility for the attack. City officials said the unauthorized access was immediately severed and the Federal Bureau of Investigation, Department of Homeland Security, and the Texas Department of Information were contacted and provided assistance. The forensic investigation confirmed on November 16, 2024, that files had been exposed and may have been stolen, and on December 30, 2024, it was confirmed that some of those files contained protected health information. The review of the...



