March 1, 2026: Small Healthcare Data Breach HIPAA Reporting Deadline
Healthcare data breaches discovered in calendar year 2025 that affected fewer than 500 individuals must be reported to the HHS’ Office for Civil Rights by March 1, 2026. The HIPAA Breach Notification Rule requires data breaches affecting 500 or more individuals to be reported to OCR within 60 days of the discovery of a data breach. Individuals must also be notified within 60 days, and a notice must be submitted to prominent media outlets where the affected individuals are located if 500 or more individuals are affected in a state or jurisdiction. The breach notification requirements for small breaches are different. The affected individuals must still be notified within 60 days of the discovery of a data breach; however, a media notice is not required. OCR must still be notified about small healthcare data breaches, but HIPAA-regulated entities can delay submitting notifications to OCR. All small healthcare data breaches must be reported to OCR within 60 days of the end of the calendar year when the breach was discovered. Each small data breach must be reported separately via the...
Academic Urology & Urogynecology of Arizona Data Breach Affects 73K Patients
Academic Urology & Urogynecology of Arizona, a division of Palo Verde Hematology and Oncology that serves patients throughout Arizona, has announced a significant data breach, potentially affecting 73,281 current and former patients. Unauthorized access to its computer network was detected on or around May 22, 2025. Steps were taken to secure its network to prevent further unauthorized access, and third-party cybersecurity experts were engaged to conduct a forensic investigation. On January 30, 2026, it was confirmed that there had been unauthorized access to its network between May 18, 2025, and May 22, 2025, during which time, files containing patient data may have been viewed or acquired. The data involved varies from individual to individual and may include some or all of the following: full names, dates of birth, Social Security numbers, account numbers, account types, routing numbers, medical record numbers, mental or physical conditions, diagnoses/diagnosis codes, treatment locations, procedure types, provider names, dates of service, other medical benefits/entitlements,...
Managed Care Advisors / Sedgwick Notify Patients of Ransomware Attack
Managed Care Advisors and Sedgwick Government Solutions recently announced a cybersecurity incident involving unauthorized access to a corporate Secure File Transfer Protocol (SFTP) server that contained personal and protected health information. Files on the server were encrypted with ransomware. Sedgwick Government Solutions, which acquired Managed Care Advisors in 2021, is a Bethesda, MD-based federal government contractor that provides workers’ compensation and managed care solutions. Sedgwick is also the manager of the Nationwide Provider Network for the World Trade Center Health Program. Data breach notices often fail to disclose the exact nature of hacking incidents, which makes it difficult for victims to accurately gauge the level of risk they face. Sedgwick bucked that trend, opting for transparency over the data breach. Sedgwick explained that the incident was detected on December 4, 2025, and it immediately implemented its incident response processes. All connections to the SFTP server were disabled to prevent further unauthorized access, and the encrypted data...
March 2, 2025: Deadline for Electronic Submission of 2025 Workplace Injury and Illness Data
The deadline for submitting electronic workplace injury and illness information to the Occupational Safety and Health Administration (OSHA) is March 2, 2026. Failure to submit timely data can result in a citation or penalty. OSHA maintains a secure website hosting its Injury Tracking Application (ITA), which can be used by certain employers to submit data from their OSHA recordkeeping forms (OSHA Forms 300A, 300, and 301). Covered employers must use the ITA to submit their data ahead of the reporting deadline, which for calendar year 2025 is March 2, 2026. To ensure that data is submitted on time, establishments should use the ITA to submit their data well ahead of the deadline in case of any technical issues. Online submission of workplace injury and illness data is required for establishments if the answer to either of the questions below is yes. Your establishment had 250 or more part-time, full-time, and seasonal employees at any time during calendar year 2025 and is not on the exempt industry list. Your establishment had between 20 and 249 part-time, full-time, and seasonal...
Carespring Health Care Management & LifeBridge Health Settle Class Action Data Breach Lawsuits
Carespring Health Care Management in Ohio and LifeBridge Health in Maryland have agreed to settle class action lawsuits stemming from data breaches. Carespring Health Care Management Carespring Health Care Management has agreed to settle a class action lawsuit stemming from an October 2023 cyberattack and data breach. Hackers gained access to the protected health information of 64,609 individuals, including names, dates of birth, Social Security numbers, financial information, health insurance information, and medical information. The first class action lawsuit over the data breach was filed by plaintiff Phyllis Rise on August 29, 2024. Four related actions were subsequently filed by other affected individuals. The five lawsuits were consolidated – Rice, et al., v. Carespring Health Care Management, LLC – in the Court of Common Pleas for Clermont County, Ohio, as the lawsuits had overlapping claims. The consolidated lawsuit asserted several claims, including negligence/negligence per se, breach of contract, breach of implied contract, breach of fiduciary duty, breach of...



